Advertisement
Promo

Security threats Toolkit

Lost Standard Life CD was unencrypted

Tom Espiner ZDNet.co.uk

Published: 06 Nov 2007 12:03 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A lost compact disc containing the personal pension details of 15,000 people was not encrypted.

The CD was lost in transit between HM Revenue and Customs Service and financial services company Standard Life, and was unencrypted, HMRC revealed on Monday.

"HMRC take the security of customer information very seriously. The data, which contained the records of around 15,000 people, was lost in transit by HMRC's external courier," said an HMRC statement. "Customers have been written to and precautionary measures have been put in place to check customers' records for any fraudulent activity. We have also reviewed our arrangements and introduced safeguards to prevent this happening in future."

One form of pension payment is an Age Related Rebate (ARR). Funds are paid into the accounts of individuals' pension providers by HMRC electronically, depending on the level of the National Insurance contributions people have made. The pension details of the individuals are then sent separately to pension providers, to enable their records to be updated.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

In this instance 15,000 pension details of customers of Standard Life were sent to the pension provider by HMRC via an unnamed third-party courier, at the end of September. However, the courier lost the disc, which was not encrypted, an HMRC spokesperson told ZDNet.co.uk.

"HMRC very much regrets that this has happened and are committed to working with the institutions to ensure that those customers affected receive the advice and support they require," said the HMRC statement. "We have asked customers to remain vigilant and have set up a number of dedicated HMRC telephone hotlines."

The data contained on the disk included the surnames and initials of the individuals, as well as their National Insurance numbers, dates of birth and pension plan numbers. That the disc was not encrypted means the details can be read more easily.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
22 out of 25 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Bletchley Park calls for operators for...

The home of World War II codebreaking has called for engineers to operate an electro-mechanical machine developed by mathematician Alan Turing. The Turing Bombe was a brute-force... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters