By Erika Morphy TechNewsWorld Part of the ECT News Network
12/13/06 11:47 AM PT
A data breach at UCLA has compromised the personal information of as many as 800,000 people associated with the university. The hacked database contained names, Social Security numbers, dates of birth, home addresses and contact information. There are signs that at least some personal information has been obtained by the hacker, acting Chancellor Norman Abrams said.
Some 800,000 people associated with UCLA have been notified that their names and certain personal information were in a database that was compromised by a hacker. The database contained personal information about current and former students, faculty and staff, and some applicants.
There are signs that at least some personal information has been obtained by the hacker, according to acting Chancellor Norman Abrams. The database includes names, Social Security numbers, dates of birth, home addresses and contact information.
Personal Information
"We take our responsibility to safeguard personal information very seriously," Abrams said. "My primary concern is to make sure this does not happen again and to provide to the people whose data is stored in the database important information on how to minimize the risk of potential identity theft and fraud."
According to the university, the hacker gained access using a software program that exploited an undetected flaw in their software.
On Nov. 21, computer security at UCLA noticed an unusually high volume of database queries. The investigation found that access attempts have been made for more than a year, beginning in October 2005. UCLA sent out notices on Dec. 12 to people who might have been affected.
Following the Steps
So far, UCLA appears to be doing everything by the book and, according to accounts, the security flaw appears to be a software problem caused by a third party vendor and not by lax internal processes, Scott Vernick, a partner with Fox Rothschild, said.
That could make all the difference if a person's data was compromised and it led to money theft. "It is conceivable that the university could be held liable if it were demonstrated that it did not take the appropriate safeguards," Vernick told TechNewsWorld.
Such a lawsuit would have a steep uphill climb. For the most part, data breaches have been punished by federal regulators, as consumers have little practical recourse in the legal system. However, as the problem worsens and more high profile thefts occur -- Vernick claimed this is probably the largest one that has occurred in an education facility -- that may change.
There were several bills pending in the last Congress about data security and notification procedures, and consumer advocates will press this issue in the upcoming session.
Federal Regulations
Thus far, more than 40 states have implemented their own notification policies. A federal law could preempt those laws, possibly lowering stringent standards in such states as California.
Meanwhile, companies are taking no chances.
"Sophisticated buyers of software and computer systems are making sure their agreements with vendors have indemnification clauses that would hold the vendor responsible for security breaches," Vernick explained. If UCLA had negotiated such a clause with its software vendor and it were to be sued by an identity theft victim, the software vendor would be the liable party.
Such agreements are becoming more commonplace across all industries, Vernick noted. "For instance, if a company uses one hotel for corporate use, that hotel likely has employee information. So, now what companies are doing when they negotiate the best rate, they are also negotiating indemnification clauses."
Credit Reporting: Where Privacy Really Starts December 11, 2006
Financial institutions and retailers do little to tighten the credit rating agencies' security processes. Why? For the same reason that this group does not want to see any more states enact laws to allow people to freeze their credit. Too-stringent security policies will keep some consumers from -- gasp -- using their credit to run up even more bills.
Related Stories
New Research Center to Combat Identity Theft June 28, 2006
The Center "is a huge step in the right direction," said Ron O'Brien, senior security consultant at Sophos, who applauds the cooperation among the private, public and academic sectors.
Novell, Industry Partners Trumpet Open Source Identity Management June 14, 2006
"The big reason we introduced Bandit and got industry support is it's not going to be solved by one company," Novell Director of Product Marketing of Identity Management Richard Whitehead told LinuxInsider. "The reason for having openness and working with Microsoft, Red Hat, Sun and the others is that we will solve this problem together."
Cautious Optimism for President Bush's ID Theft Executive Order May 13, 2006
"We hope the federal government's leadership role on identity theft doesn't end with this task force," said Bill Conner, president and CEO of Entrust. "While this is a positive step, Congress needs to pass a data breach notification law that assures consumers, clears up the patchwork of state laws and gives organizations the option to protect customer data through encryption."
Related News Alerts
More by Erika Morphy
Windows 7 Flies Off the Shelves November 06, 2009
Early sales figures on Windows 7 boxed software suggest a high level of consumer enthusiasm for the OS. Unit sales were a whopping 234 percent higher than Vista's out of the gate. The revenue haul was not as impressive, as Microsoft offered sharp discounts to spur presales. Also, sales of PCs with Windows 7 preinstalled have been lackluster -- but October is historically a weak month for PC sales.
Southwest Doesn't Fool Around November 06, 2009
Either Southwest Airlines had better deals for my favorite route than its competitors or its superior Web site tools made it easier for me to ferret them out. Either way, kudos to Southwest. In the not-so-hot department were the airline's long list of what passengers weren't allowed to do and its very short list of what Southwest was obliged to do for them. Left me feeling a little chilly.
Commerce Search Puts Google Inside Retailers' Catalogs November 05, 2009
Google has launched a new cloud-based search tool targeting enterprise-level e-commerce operations, just in time for the 2009 holiday selling season. Commerce Search provides a set of features designed to improve the relevance of results for consumers searching a retailer's own product catalog, while boosting cross-selling opportunities.