On mySimon: Victoria's Secret Vanilla Orchid
BNET Business Network:
BNET
TechRepublic
ZDNet

April 8th, 2008

HSBC loses data on 370,000 customers; violates security standards

Posted by Michael Krigsman @ 1:39 pm

Categories: CIO issues, End-user impact, IT issues, Project failures, Security and privacy, Uncategorized

Tags: Bank, Security, Disc, Security Standard, HSBC, Financial Services, Michael Krigsman

HSBC loses data on 370,000 customers; violates security standards

HSBC, the UK’s largest bank, lost an unencrypted data disc containing the names and insurance information of 370,000 customers. HSBC sent the disc via unregistered postal mail because its usual method of secure electronic data transmission “wasn’t working.”

Network World reports the bank’s response:

“The data, which was password-protected, includes names, life insurance cover levels, dates of birth and whether or not a customer smokes. There is nothing else that could in any way compromise a customer and there is no reason to suppose that the disc has fallen into the wrong hands,” the bank said in a statement.

“We don’t normally send information on hard copy, but usually send electronically through this secure network. But the system wasn’t working the day this information needed to be sent to the reinsurer.”

THE PROJECT FAILURES ANALYSIS

According to Forbes, HSBC is the world’s largest company, meaning it has the resources needed to properly secure customer data. As an axiom, unencrypted confidential data should never be sent through the mail.

The situation is particularly disturbing in light of a similar, and extremely well-publicized, incident at the UK Revenue & Customs (HMRC). In that case, 25 million names were lost when discs were also sent through the mail.

HSBC has demonstrated complete lack of regard for handling secure, confidential, and private customer data. I urge the Information Commissioner’s Office (ICO) to take swift and appropriate action against HSBC.

Michael KrigsmanMichael Krigsman is CEO of Asuret, Inc., a software and consulting company dedicated to reducing software implementation failures. Click here to discuss this post with him on Twitter. See his full profile and disclosure of his industry affiliations.

Email Michael Krigsman

Subscribe to IT Project Failures via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 20 Talkback(s)
RE: HSBC loses data on 370,000 customers; violates security standards
I'm a customer and was never informed! (Read the rest)
Posted by: FDERIGGE@... Posted on: 04/13/08 You are currently: a Guest | | Terms of Use
HSBC Has A Lot To Learn  Kromaethius | 04/08/08
Sending it over an ssh tunnel is too dangerous  fr0thy2 | 04/08/08
More likely  Larry the Security Guy | 04/09/08
RE: HSBC loses data on 370,000 customers; violates security standards  dahowlett@...ZDNet Moderator | 04/08/08
How can losing 370,000 customers data ...  fr0thy2 | 04/08/08
HSBC acknowledged responsibility  mkrigsman@...ZDNet Moderator | 04/08/08
Not quite right  dahowlett@...ZDNet Moderator | 04/08/08
Headline should read: HSBC loses 370,000 customers  DigitalFrog | 04/10/08
I encrypt data on 200 people  croberts | 04/08/08
RE: HSBC loses data on 370,000 customers; violates security standards  PracticalRiskManagement | 04/08/08
Great post!  mkrigsman@...ZDNet Moderator | 04/09/08
RE: HSBC loses data on 370,000 customers; violates security standards  Surfcr8zy | 04/09/08
Any loss in not acceptable  dave@... | 04/09/08
RE: HSBC loses data on 370,000 customers; violates security standards  royalef | 04/09/08
It's very simple and inexpensive to provide protection.  joe.smetona@... | 04/09/08
Message has been deleted.  pablo Dante | 04/09/08
What it's going on in the brain of HSBC people...  MV_z | 04/10/08
Not suprised at all, they have much to learn...  UWILLPAY | 04/10/08
RE: HSBC loses data on 370,000 customers; violates security standards  etweimer | 04/11/08
RE: HSBC loses data on 370,000 customers; violates security standards  FDERIGGE@... | 04/13/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here