Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Shell warns employees of suspected data loss

Tom Espiner ZDNet.co.uk

Published: 08 Oct 2008 18:18 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Oil company Shell has dismissed one of a third-party contractor's workers, under suspicion of misusing employee data.

The employee was engaged in database work, and was removed from US Shell premises when the company learned that the employee could have misappropriated four of its employees' social-security numbers, in order to file fraudulent unemployment claims.

Shell also terminated its contract with the third-party vendor following the suspected incident. The company said it had no information as to whether any credit-card fraud had been perpetrated as a result of the breach, or whether any other employee personal data had been compromised.

The oil giant is "continuing to work with the Texas Workforce Commission and Harris County law enforcement to investigate this matter", Shell said in an employee notification of the incident.

Read this

Feature
Special report: The top five internal security threats

What should an employer watch out for?

Read more +

Security analyst Andy Buss, from the firm Canalys, said it was difficult to prevent trusted employees from misusing data, whether they are internal or third-party.

"There's nothing you can do to get rid of all the bad apples," said Buss. "You'll never get around this problem, even with strict digital-rights management. For external [workers], you need to consider why they need access."

Buss said that, to mitigate the threat, companies should put in data-loss prevention or intrusion-detection capabilities to monitor the flow of information over networks. He added that companies looking to mitigate the threat of employees using removable storage devices, such as USB sticks, could physically glue ports, or put a policy in place so only corporate-issued, encrypted sticks could be used.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters