Feeds

Data watchdogs did not want to see eBay bank server

Watching the watchmen

The man who paid £35 for a server stuffed full of Royal Bank of Scotland and NatWest customer details has been left less than impressed with the reaction of UK data regulators.

Andrew Chapman's story hit the news after he bought a server on eBay which contained over a million customer details including full account details, mothers' maiden names, addresses and even scans of signatures. But neither the Financial Services Authority nor the Information Commissioner's Office contacted Chapman when he went public with what he found inside the machine.

Chapman said he phoned the Information Commissioner Office's head of investigations and offered him the machine. Instead he was told to return it to Graphic Data.

Chapman, an IT manager from Oxford, told the Reg: "I don't really see how either the FSA or ICO can ascertain what happened by relying on Graphic Data. It is a nonsense to ask companies to self-report." He said he was told the ICO had no power to seize equipment - although that clearly would not have been necessary in this case.

The ICO has asked the government for stronger investigatory powers and more powers to punish offenders.

We asked the ICO about this and were told that since it knew what information was on the machine, nothing useful could be learnt from it. The ICO is working with RBS and archiving firm Graphic Data to find out how the machine went astray. ®

More from The Register

next story
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
Apple CEO Tim Cook: TV is TERRIBLE and stuck in the 1970s
The iKing thinks telly is far too fiddly and ugly – basically, iTunes
Huawei ditches new Windows Phone mobe plans, blames poor sales
Giganto mobe firm slams door shut on Microsoft. OH DEAR
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Found inside ISIS terror chap's laptop: CELINE DION tunes
REPORT: Stash of terrorist material found in Syria Dell box
Show us your Five-Eyes SECRETS says Privacy International
Refusal to disclose GCHQ canteen menus and prices triggers Euro Human Rights Court action
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.