ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security management Toolkit

Halifax theft exposes customer mortgage data

Will Sturgeon silicon.com

Published: 27 Mar 2007 14:52 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

UK high street bank Halifax has admitted stolen documents from one of its employees contained data on 13,000 mortgage customers.

The documents were in a briefcase stolen from the locked car of an employee last week and the bank yesterday started writing to affected customers, after first reporting the breach to the Financial Services Authority (FSA) and the police.

Around 1,800 of the 13,000 customer records exposed by the theft included name, address, mortgage account number and account balance. The remainder included name, mortgage account number and approval status.

According to a spokesman for Halifax: "It would be almost impossible for any fraud to be committed with the information on the printout."

However, the bank, part of the HBOS Group, has promised: "No customer will be left out of pocket in the very unlikely event of fraudulent activity on their account following this unfortunate theft."

The theft further highlights the risk of taking data outside the organisation — whether in a digital or hard-copy format. In this instance the employee was intending to use the data during meetings with mortgage intermediaries.

Proponents of encryption have argued any sensitive data should travel in an encrypted format from point to point and a spokesman for encryption experts PGP said he found the decision to cart around printouts of 13,000 customer records — protected by "nothing more than a briefcase lock" — a strange one.

He said: "When people set up a security policy there are many steps to it and one of them will be the physical aspect in terms of what form you carry data in. Nowadays with the ability to manage this information much more easily on removable media with encryption whether that is on a USB or a hard drive or whatever makes sense, why would you take this as a hard copy?"

Shane O'Riordan, general manager of group communications at Halifax, said lessons have been learned, adding: "We are reviewing our procedures as a matter of urgency."

However, the PGP spokesman said Halifax should be praised for "doing the decent thing and notifying people" — despite no requirement on UK companies to do so.

Earlier this year the Nationwide building society was fined nearly £1m by the FSA after the theft of a laptop exposed customer data.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
8 out of 8 people found this useful


Full Talkback thread

1 comment

  1. Taking responsibility welshtroll

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Helpdesk Analyst (Active Directory tools,Reuters,Bloomberg) BANKING

Leading Investment Bank is looking to hire a Senior 1st line Helpdesk Support Analyst to join its vibrant team. This role will be ideal for ...

2 x Bulge Bracket Investment Banking, Commodities Business Analysts

The successful candidates will be experienced Business Analysts with strong track records in requirements gathering, writing functional ...

SAS Senior Portfolio Anlayst - SAS - Gloucester 35K - 40K

Permanent Job description: Leading financial institution and well-known retail bank are recruiting for a role to support the management of their 90bn ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec