• Home
  • Et Cetera

Infosecurity.US

Sunshine State Loses Quarter Million Social Security Numbers

By Marc Handelman on December 3rd, 2008

National ID Watch has revealed a State of Florida Agency has managed to lose a quarter million IDs and their attendant US Social Security Numbers. Evidence now implicates the State of Florida Agency for Workforce Innovation (AWI), in, what we believe, was a completely avoidable snafu. Apparently, the Agency published the personal employment information and more than 250,000 social security numbers online for at least 30 days (maybe longer).  The information posted on the Agency’s web site included social security numbers of at least 50 minors. More information from the National ID Watch posting can be examined after the page jump.

From  National ID Watch: “The Florida Agency for Workforce Innovation (AWI, or Florida Jobs– floridajobs.org) posted employment information and more than a quarter million social security numbers online for at least one month, and perhaps longer.  The information included social security numbers of at least fifty children.

Individuals who participated in the Florida Jobs One-Stop Program since 2002 may be at risk, and should go to National ID Watch (http://www.nationalidwatch.org/) to find out whether they were affected.

In the course of developing a new employment website, AWI posted several thousand Excel and text files containing millions of employment records. These records contained:

  • Between 255,917 and 259,193 Names and Social Security Numbers.
  • 51 breached social security numbers belonged to children

Although some of the files have been on the server for more than six years, AWI officials insist that the server was only connected to the internet for about a month. Whether social security numbers were online for a month or six years, they had no passwords, were not encrypted, and were not behind a firewall. Anyone with an internet connection could access the names and social security numbers.

The Liberty Coalition asked AWI the following questions:

  1. Why did the Agency for Workforce Innovation store sensitive Excel files on a server at all?
  2. Why was this website left open to the public for more than a month, undetected by AWI’s IT department?
  3. Why were the files on the server not behind a firewall, password protected or encrypted?
  4. How many other servers store sensitive personal information, and how many of those are available to the public right now?
  5. How many AWI employees have access to clients’ social security numbers, and do they all need access?
  6. How do you plan to train employees to appropriately handle sensitive personal information?
  7. Do you have a regular schedule of scanning your internal networks and external servers for personal information? If so, why was this breach not discovered?
  8. Does the Agency for Workforce Innovation intend to pay for identity theft protection services for the victims of this breach?
  9. Will the Agency notify victims by mail?

In response to these questions, an official answered in part, “The Agency takes these matters very seriously, and the security of our customers’ confidential information is a number one priority. Although this was an isolated incident which was quickly discovered and corrected, we are examining the details of this issue very closely, and based on our findings, will implement any necessary system modifications and will take appropriate action in accordance with applicable law.” The agency has or will take the following steps:

  • The Agency for Workforce Innovation quickly removed access to the sensitive information within hours of becoming aware of the breach.
  • The Agency quickly coordinated with search engines to remove cached versions of the documents from the internet.
  • The Agency will attempt to notify the victims of this breach by mail.
  • The Agency has hired a third party to assess network vulnerability.
  • The Agency is working with the Florida Department of Law Enforcement and the Office of the Attorney General.
  • The Agency pledges to learn from its mistakes.

The Liberty Coalition commends the agency for these responsible steps, but also notes the following:

  • AWI has not offered to protect victims with identity theft protection services.
  • AWI relied on public search engines and a member of the public 800 miles away to discover the breach.
  • The Agency should destroy the information, not just restrict access.
  • We don’t know how many other AWI servers are currently exposing personal information.
  • We question the need for AWI to collect minors’ social security numbers.
  • AWI has not indicated how many employees have access to clients’ social security numbers, and whether these employees require access to fulfil their job descriptions.
  • AWI does not appear to regularly scans its networks for sensitive personal information.

The Agency for Workforce Innovation has taken the files offline, though it’s too early to tell whether the Florida Jobs breach has resulted in identity theft.

About NationalIDWatch.org

National ID Watch is a search engine for personal information breaches.  Sponsored by the Washington, DC non-profit Liberty Coalition (http://www.libertycoalition.net), NationalIDWatch.org provides more than a million free personalized Identity Exposure Reports™ as a public service.
Each Identity Exposure Report (IXR) documents what types of personal information were exposed (such as Social Security Numbers, Birth Dates, Addresses, etc.), without revealing them. Each IXR also details the situation surrounding each exposure, and contact information of those responsible for the breach. Armed with this information, victims can further investigate, take action, or correct harm.

  • Equifax’s new age-verification tool cumbersome, limited
  • Court Eyes Illegal Aliens And ID Theft
Reblog this post [with Zemanta]

Categories: Blatant Stupidity, Data Security, Features, Infosecurity, Web Security, What Were They Thinking
Tags: Blatant Stupidity, Cybercrime, Dataloss, Features, Florida, ID Theft, Liberty Coalition

Comments are closed.

« VLC Exploit In The Wild XKCD: Sleet »
  • Latest
  • Random
  • Bookmarks
  • Archives
  • Oracle Patches Critical WebLogic Flaw
  • Lisa Benson: Beanstalk
  • USB Electronic Key Impressioner – Open Sesame
  • Sherffius: Bacterial-Laden
  • Firefox Malware Extensions Discovered
  • Holbert: Trillion Dollar Stuck Pedal
  • But Wait, There’s More – 13 Critical Security Patches Queued For Microsoft’s PatchTuesday
  • Thach Bui: Monumental Upgrades
  • New, Critical Internet Explorer Vulnerability – Nearly All Versions Affected
  • Lisa Benson: Health Care Reform R.I.P.
  • Benson: Ode to Haiti
  • XKCD: Piano
  • White House Set To Reel-In Cybersecurity Role?
  • Breen: H1N1
  • Weekend Off!
  • Adobe Announces Potential Vulnerabilities in PageMaker
  • Apple Releases MAC OS X Leopard Wireless Network, App Updates
  • Wondermark: Stymied Studies
  • Blackberry Security Advisory Released
  • XKCD
  • Apple
  • BSD
  • Closson
  • Darknet
  • Debian
  • Finnigan
  • ha.ckers
  • Hoff
  • Insecure
  • Krebs
  • Layer8
  • MSRC
  • Network Security Blog
  • NSA SEL
  • openSUSE
  • RedHat
  • SANS
  • Schneier
  • Security Eunoia
  • Securosis
  • Shimel
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
Subscribe

Featured Blog - Blogs.com SANS Security Reading Room KnotOriginal: fine art to hang on your body and walls Member - Security Bloggers Network

Dilbert

Sponsored Links

KnotOriginal

Featured Video

RSS Cryptography

  • Microscope-wielding boffins crack cordless phone crypto 2010/02/08
  • Making packet processing more efficient with network-optimized multicore designs: Part 2 2010/02/08
  • New Attack on Threefish 2010/02/07
  • So I deleted it without reading it. 2010/02/06
  • Kaspersky: Google hack takes spotlight from Russia 2010/02/05
  • IP Cores, Inc. Announces an Update of its Elliptic Curve Crypto Accelerator 2010/02/05
  • SMIC, SSHIC deliver smart card IC using 0.162 m EEPROM 2010/02/04
  • Revere Security Appoints Co-Inventor of Public-Key Cryptography... 2010/02/03
  • Data defenders: Researchers try to ward off increasingly sophisticated cyber attacks 2010/02/02
  • IP Cores Selects Phoenix Technologies for Israel 2010/02/02

RSS Security Bloggers Network

  • My Blackhat DC Paper, Slides, and Video are available 2010/02/08 IBM Internet Security Systems Frequency X Blog
  • Is Your BlackBerry Spying On You? 2010/02/08 spinman
  • The 800-lb Dragon’s APTitude 2010/02/08 Bill Wildprett
  • Wrapping insecure web apps with Apache 2010/02/08 Asmodian X
  • Oracle Patches Critical WebLogic Flaw 2010/02/08 Marc Handelman
  • Lisa Benson: Beanstalk 2010/02/08 Marc Handelman
  • Week 5 in Review 2010/02/08 glenn
  • Google Street View Car Gets GPSed by F.A.T. Pranksters 2010/02/08 Devin McDonald

RSS SANS ISC

  • Oracle has an unscheduled security alert and patch for CVE-2010-0073. The issue affects WebLogic Server and is remotely exploitable. Details and patch are here http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0073.html, (Tue, Feb 9th) 2010/02/09
  • When is a 0day not a 0day? Samba symlink bad default config, (Tue, Feb 9th) 2010/02/09
  • When is a 0day not a 0day? Fake OpenSSh exploit, again. , (Mon, Feb 8th) 2010/02/08
  • Mandiant Mtrends Report, (Sun, Feb 7th) 2010/02/07
  • LANDesk Management Gateway Vulnerability, (Sat, Feb 6th) 2010/02/06
  • tweaked ISC layout. Please submit screen shot and browser details if things don't look right., (Sat, Feb 6th) 2010/02/06
  • Oracle WebLogic Server Security Alert, (Sat, Feb 6th) 2010/02/06
  • New version of Andreas Schuster's Evtx Parser released http://computer.forensikblog.de/en/2010/02/evtx_parser_1_0_2.html, (Sat, Feb 6th) 2010/02/06
  • Memory Analysis - time to move beyond XP, (Fri, Feb 5th) 2010/02/06

RSS Oracle

  • Oracle to Acquire AmberPoint 2010/02/09
  • Bookmarkable page with parameters 2010/02/09
  • 32-bit to 64-bit database migration tips: OLAP upgrade 2010/02/08
  • ADF Coding Ninja 2010/02/08
  • Case Study: Swedish Rail Operator SJ Increases Revenue and Customer Satisfaction Using CRM 2010/02/08
  • Random Things: Volume #13 2010/02/08
  • v-Commerce? 2010/02/08

RSS MySQL

  • A deep look at MySQL 5.5 partitioning enhancements 2009/12/24
  • Sun "Tech Days" Conference World Tour Kicks Off in Brazil 2009/12/07
  • Tino Rachui: Using MySQL Cluster in Sun's Virtual Desktop Infrastructure 2009/11/10
  • MySQL Database Analytics with InfiniDB from Calpont – Part 2 2009/10/28
  • MySQL Database Analytics with InfiniDB from Calpont – Part 1 2009/10/27
  • What's New in the MySQL Enterprise Fall 2009 Release? - Interview with Mark Matthews and Andy Bang 2009/09/08
  • Introducing the MySQL Librarian 2009/07/14

RSS Linux

  • Oracle Drops Sun's Commitment To Accessibility - Slashdot 2010/02/09
  • LinuxCon Puts Out Call for Papers Ahead of Summer Event - OStatic (blog) 2010/02/09
  • How To Reverse Engineer A Motherboard BIOS - Benchmark Reviews 2010/02/09
  • Oracle Patches Dangerous WebLogic Server Flaw - eWeek 2010/02/09
  • Unix ENGINEER - TRADING - SYDNEY CBD! - Australian Techworld 2010/02/09

RSS MAC OSX

  • Anti-DRM Protest Against The iPad Grows 2010/02/08 Eli Milchman
  • Amazon to Hike Ebook Pricing as iPad Ships 2010/02/08 Ed Sutherland
  • Daily Deals: iPhone Acces. Bundle, External Superdrive, App Store Freebies 2010/02/08 Ed Sutherland
  • Mock Up Your iPad Ideas With IA’s Omnigraffle Template 2010/02/08 Giles Turnbull
  • The inevitable DIY iPad papercraft mockup 2010/02/08 John Brownlee
  • Apple to app devs: don’t use Core Location “primarily” for advertising 2010/02/08 John Brownlee
  • Report: Carriers to Subsidized iPads for 2-Year 3G Contracts 2010/02/08 Ed Sutherland

RSS Microsoft

  • February 2010 Bulletin Release Advance Notification 2010/02/04 MSRCTEAM
  • Security Advisory 980088 Released 2010/02/03 MSRCTEAM
  • January 2010 Out-of-Band Security Bulletin Webcast 2010/01/22 MSRCTEAM
  • Bulletin MS10-002 Released 2010/01/21 MSRCTEAM
  • Security Advisory 979682 Released 2010/01/21 MSRCTEAM
  • Advance Notification for Out-of-Band Bulletin Release 2010/01/20 MSRCTEAM
  • Security Advisory 979352 – Going out of Band 2010/01/19 MSRCTEAM

RSS Network

  • Europe lagging behind on fibre broadband adoption 2010/02/08
  • LG NAS N4B1 review 2010/02/08
  • VoIP patent under review by Patent Office 2010/02/08
  • YouTube now supports IPv6 2010/02/08
  • Where do web giants stand on IPv6? 2010/02/05
  • Intel details vPro for Core i5, i7 processors 2010/02/05
  • Microsoft IE still popular, researcher says 2010/02/05

Daily Posts

February 2010
S M T W T F S
« Jan    
 123456
78910111213
14151617181920
21222324252627
28  
Creative Commons License
The Infosecurity.US Blog is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

Find the best blogs at Blogs.com.

Creative Commons Attribution-Share Alike 3.0 U.S. License ©2010 Infosecurity.US

Subscribe