Shostack + Friends Blog Archive

 

Breach Roundup

  • Expedia/Ernst & Young, 250,000 CC, Lost Laptop. Ed Hasbrouck has a great analysis of Expedia’s privacy policy at “Expedia auditors lose laptop with customer credit card numbers.”
  • Japanese Telco KDDI, 4million names, address, phone numbers, mechanism unknown. “KDDI Suffers Massive Data Leak.” [link to http://www2.csoonline.com/blog_view.html?CID=22007 no longer works]

    Why is a Japanese telco owning up? New expectations.
  • AIG (American Insurance Group), 930,000 SSNs+Medical data, stolen computer. “Stolen computer server sparks ID theft fears,” (MSNBC via Dataloss.)
  • Union Pacific Railroad, 30,000 SSNs, stolen computer. News and analysis in “Data-loss disclosure falls short.” David Lazurus did some sleuthing to get us numbers.