Advertisement
Promo

Security threats Toolkit

Amex, RBS, Natwest customer details sold on eBay

Tom Espiner ZDNet.co.uk

Published: 26 Aug 2008 13:28 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Over one million American Express, RBS and Natwest customers' details have been sold on eBay.

The details were stored on a server, bought for just over £35 by Andrew Chapman, an IT manager from Oxford, last week. Chapman told ZDNet.co.uk on Tuesday that the server, a network attached storage (NAS) box, contained unencrypted backups of CDs.

"A professional organisation holding this kind of data should have tested the disks to make sure [the information] was destroyed," said Chapman.

The computer had been used by data-archiving firm Graphic Data to store the details on behalf of RBS, of which Natwest is a subsidiary. Details included names, addresses, bank account numbers, telephone numbers and customer signatures.

RBS said on Tuesday that it was in the process of investigating the incident.

"Graphic Data has confirmed to us that one of their machines appears to have been inappropriately sold on via a third party," RBS said in a statement. "As a result, historical data relating to credit-card applications from some of our customers and data from other banks were not removed. We take this issue extremely seriously and are working to resolve this regrettable loss with Graphic Data as a matter of urgency."

Graphic Data, a subsidiary of Sala International, said it had not planned to dispose of the server, and was investigating how it had appeared on eBay.

ZDNet.co.uk blogs

Blog
Torvalds abandons KDE for Gnome

Ticked off at the latest revamp of KDE, Linux progenitor Linus Torvalds has switched to Gnome...

Read more +

"The IT equipment that appeared on eBay was not planned to be disposed [of] by the company and investigations are still ongoing to find out how this equipment was removed from one of Graphic Data's secure locations," the company said in the statement. "We take customer privacy and data security very seriously. This incident is extremely regrettable and we're taking every possible step to retrieve the data and ensure this is an isolated incident."

The Information Commissioner's Office (ICO) said it would be investigating the breach. "It is essential that companies have appropriate procedures in place to ensure that personal records are kept secure at all times, the ICO said in a statement. "If companies are disposing of computer equipment they must take the necessary steps to ensure that any personal information stored on the hard drive is rendered unrecoverable. We are now investigating this potential data breach and will be seeking an urgent explanation from Graphic Data to establish what has gone wrong and the steps that are being taken to prevent a similar incident occurring."

Neither eBay nor American Express had responded to a request for comment at the time of writing.

This data breach follows the compromise of details of 84,000 prisoners in the UK by a Home Office sub-contractor last week.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
40 out of 43 people found this useful


Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Bletchley Park calls for operators for...

The home of World War II codebreaking has called for engineers to operate an electro-mechanical machine developed by mathematician Alan Turing. The Turing Bombe was a brute-force... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters