Feeds

Deloitte loses hundreds of thousands of pension details

Vodafone, rail union and others

Next gen security for virtualised datacentres

Deloitte has admitted losing a laptop containing thousands of people's pension details, but said the data was encrypted and the machine password-protected, and it had no evidence the data had been misused.

The laptop contained 150,000 railway workers' details as well as details on all UK Vodafone staff with pensions and other unnamed pension funds. The lappy was stolen from a Deloitte staffer's handbag last month. The machine held personal information but not bank details. Deloitte was auditing the pension funds.

A letter sent to Vodafone staff, and seen by The Register, said the details included names, National Insurance numbers, dates of birth, pensionable salary, earnings and contributions.

Pension holders from the rail union got a similar reassuring letter, but Gerry Doherty, general secretary of the Transport Salaried Staff Association, called for an urgent inquiry.

He said: "We are extremely concerned that this personal information affecting well over 100,000 people has gone missing.

"All we have received are bland assurances that everything is going to be all right."

A spokesman for Deloitte said the laptop contained pension fund databases from several clients.

The official Deloitte line is:

A handbag with a Deloitte laptop in it was stolen from a public place in September. The laptop held information which included employee details of individuals from a number of Deloitte's clients. It did not include addresses or bank account information. The theft was immediately reported to the police and relevant clients were notified.

The laptop was protected by a number of security measures, including start up password, operating system user ID/password authentication and encryption.

Deloitte has information security policies which include guidelines for employees to ensure they pay close attention to their laptops when in public places. Nevertheless, and very unfortunately, this theft still occurred.

We believe that the likelihood of unauthorised access to the data held on this laptop is remote due to the opportunistic nature of the theft and the security controls.

Vodafone said: "Vodafone is extremely concerned about the breach in security of our employees’ personal information and we take the matter very seriously.

"Deloitte is a highly reputable firm and also sincerely regrets that this opportunistic theft has happened. We have written to our employees assuring them that we are thoroughly investigating the matter." ®

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New twist as rogue antivirus enters death throes
That's not the website you're looking for
ISIS terror fanatics invade Diaspora after Twitter blockade
Nothing we can do to stop them, says decentralized network
prev story

Whitepapers

A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Maximize storage efficiency across the enterprise
The HP StoreOnce backup solution offers highly flexible, centrally managed, and highly efficient data protection for any enterprise.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.