Original URL: http://www.theregister.co.uk/2008/04/07/hsbc_disc_loss/
HSBC has admitted that it has misplaced 370,000 customer details, which were put in the post a month ago on an unencrypted disc.
The envelope has not arrived at its intended destination - a reinsurance firm.
A spokesman for HSBC told the Reg: "We have sent a disc to our reinsurers which they never received. The disc was not encrypted but was password-protected. Our normal method is to use electronic transfer but on the day this happened the system was down so it was sent by disc instead." The disc was sent using ordinary Royal Mail services.
Nick Lowe, regional director for Northern Europe at security firm Check Point said: “The disc was apparently password-protected, but this can be overcome fairly easily by an IT-literate person.
“In this sector, where information is highly sensitive, always-on strong encryption of data is the minimum protection that should be applied to laptops, discs and USB storage devices."
The customer files did not contain account information or addresses but life insurance details, dates of birth and smoking habits.
HSBC has told the Financial Services Authority what happened. The FSA fined Nationwide £980,000 for breaching customer privacy last year by losing a laptop containing customer information. ®
Phone insurance firm reveals Sharia rules policy (10 April 2008)
http://www.theregister.co.uk/2008/04/10/sharia_rules/
Civil liberties groups challenge Data Retention Directive in ECJ (10 April 2008)
http://www.theregister.co.uk/2008/04/10/data_retention_directive_challenge/
HSBC e-payments system limps back online (9 April 2008)
http://www.theregister.co.uk/2008/04/09/hsbc_e_payments_restored/
HSBC e-payments system goes titsup (again) (8 April 2008)
http://www.theregister.co.uk/2008/04/08/hsbc_e_payments_problems/
BT and Phorm secretly tracked 18,000 customers in 2006 (1 April 2008)
http://www.theregister.co.uk/2008/04/01/bt_phorm_2006_trial/
MoD loses 11,000 ID cards (12 March 2008)
http://www.theregister.co.uk/2008/03/12/mod_loses_id_cards/
HMRC data debacle used to bait phishing lure (22 February 2008)
http://www.theregister.co.uk/2008/02/22/hmrc_phishing_attack/
MoD coughs to laptop triple whammy (22 January 2008)
http://www.theregister.co.uk/2008/01/22/mod_gives_away_data/
Clarkson's 'steal my ID' stunt backfires (7 January 2008)
http://www.theregister.co.uk/2008/01/07/clarkson_bank_prank_backfires/
MPs call for stronger data protection laws (3 January 2008)
http://www.theregister.co.uk/2008/01/03/mps_call_for_stronger_information_law/
Information security breaches quadrupled in 2007 (2 January 2008)
http://www.theregister.co.uk/2008/01/02/data_breaches_skyrocket/
© Copyright 2008