Shostack + Friends Blog Archive

 

Breach Roundup: "We’re From The Government" Edition

baxter-overflow.jpg

  • State of Colorado, 150,000 voter records, “missing.” “Records for 150,000 Colo. voters missing,” [link to http://news.yahoo.com/s/ap/20060611/ap_on_re_us/voter_records_missing no longer works] via Dataloss.
  • State of Oregon, 2,200 tax records, ex-employee getting trojan’d by a porn site. “State says taxpayer files may have been compromised.” [link to http://www.kgw.com/sharedcontent/APStories/stories/D8I7JI4G0.html no longer works] AP via dataloss.
  • Minnesota State Auditor, numbers about unknown number of state and local employee, stolen laptops. “3 laptops apparently stolen from state auditor’s office,” [link to http://www.startribune.com/462/story/490333.html no longer works] Minneapolis Star Tribune. Would the auditor pass you with that lack of controls? (Via Dataloss.)
  • Medicare/Humana, 17,000 SSNs+medical records (?), web access to computers. “Medicare chastises Humana.” [link to http://www.courier-journal.com/apps/pbcs.dll/article?AID=/20060603/BUSINESS/606030358/1003 no longer works]
  • US Department of Energy, 1,500 contractor SSN+background data, uber-hacker, “DOE computers hacked; info on 1,500 taken.” [link to http://seattlepi.nwsource.com/national/1153AP_DOE_File_Theft.html no longer works]
  • US Department of Energy, 4,000 Hanford Nuclear site employees, employee. “Hanford workers warned about security breach,” Seattle PI.

    DOE! a breach! another breach!
    Clay [link to http://www.doe.gov/organization/clay_sell.htm no longer works], a deputy secretary!
    Me! I’m glad, I don’t work there!
    Pah! Another broken policy
    So! What are they gonna do?
    La! (la la: we’re not listening)
    Choicepoint, will do it for them wholesale!

Baxter State Park phot by Jenpilot.