Vulnerabilities / Threats
3/30/2011
12:14 PM
Connect Directly
RSS
E-Mail
50%
50%

BP Loses Laptop With Gulf Claimant Data

The missing computer, containing personally identifiable information on 13,000 people, was password-protected, but not encrypted.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
A BP laptop containing personally identifiable information for approximately 13,000 people is missing. All of the people listed on the computer's hard drive had claimed damages due to the oil spill resulting from the Deepwater Horizon accident.

The laptop, which was lost by a BP employee last month during business-related travel, was password-protected, but not encrypted. A spreadsheet on the laptop -- used for tracking claimants prior to the Gulf Coast Claims Facility being established -- contained people's names, addresses, phone numbers, dates of birth, and social security numbers.

"The lost laptop was immediately reported to law enforcement authorities and BP security, but has not been located despite a thorough search," said Robert Wine, a press officer for BP, via email.

So far, the information appears simply to have been lost, rather than stolen. "There is no evidence that the laptop or data was targeted or that anyone's personal data has in fact been compromised or accessed in any way," he said. "Our security team continues to monitor the situation very closely and we are still in touch with authorities in an attempt to recover the laptop.

"BP takes the protection of personal information very seriously and deeply regrets the loss of the laptop," he said.

BP is sending letters to everyone who's been affected, and offering free credit monitoring services to alert people if their details are used by identity thieves.

According to a 2010 study from the Ponemon Institute, surveyed organizations lost an average of 261 laptops per year, with the lost data on each costing an average of $49,246. The study also found that any given laptop, over a three-year period, has a 5% to 10% chance of being lost or stolen, and only 5% of those missing will ever be recovered.

Hence it's surprising that so few organizations use full-disk encryption to secure laptops against loss or theft, said Paul Ducklin, head of technology in Asia Pacific for Sophos, in a blog post.

"Even if you're the sort of organization which is willing to take risks with your own data -- sales forecasts, trade secrets, and that sort of thing -- you have a clear moral duty not to take risks with data you keep about other people," he said.

"Unfortunately, in those parts of the world where encryption and mandatory disclosure are not enforced by law, many sysdamins are being squeezed by budgetary pressures to do as little as possible about encryption-related security," he said.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-1503
Published: 2014-08-29
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.

CVE-2013-5467
Published: 2014-08-29
Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM)...

CVE-2014-0600
Published: 2014-08-29
FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.

CVE-2014-0888
Published: 2014-08-29
IBM Worklight Foundation 5.x and 6.x before 6.2.0.0, as used in Worklight and Mobile Foundation, allows remote authenticated users to bypass the application-authenticity feature via unspecified vectors.

CVE-2014-0897
Published: 2014-08-29
The Configuration Patterns component in IBM Flex System Manager (FSM) 1.2.0.x, 1.2.1.x, 1.3.0.x, and 1.3.1.x uses a weak algorithm in an encryption step during Chassis Management Module (CMM) account creation, which makes it easier for remote authenticated users to defeat cryptographic protection me...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.