All the latest UK technology news, reviews and analysis

Compaq cockup exposes customer details

by Ian Lynch

20 Nov 2001

Be the first to comment

  • Tweet this

Compaq has blamed "human error" for the mistake that exposed thousands of its Presario customers' email addresses by including them all in the 'to' field of a mass mailout. Some 2,900 email addresses were involved.

Labelled "ridiculous" by security experts, the embarrassing blunder may be investigated by the Information Commission as a breach of the UK's Data Protection Act, even though Compaq insists no other customer data has been exposed.

Eva-Maria Bieda, PR manager at Compaq EMEA, said: "Compaq regrets that every customer who had registered for a Microsoft Windows XP upgrade received an email yesterday [Monday 19 November] where all email addresses were fully visible.

"However, we can ensure that no other sensitive data of the order process is accessible to others. Compaq takes this incident very seriously and is working with its suppliers to ensure the safety of data in the future. We will also follow up with our customers to explain the situation to them."

Terry Scerri, director of Compaq's Access Business Group, EMEA, said the website and subsequent email was not produced in-house and blamed "human error" by one of its suppliers for the rogue mass email.

The firm refused to name the errant supplier or comment on why the email sender was labelled 'Wisdom IT' in the in-box of some recipients.

Jonathan Bamford, assistant commissioner at the Information Commission, told VNU News Net: "We would look into any complaint brought by individuals on the list of recipients who felt their privacy had been breached."

Asked about the Data Protection Act, Scerri said: "I have no comment to make on that. We're still investigating the details with our supplier and our in-house legal team."

Bamford added: "It doesn't matter if Compaq used a contractor, the data is still owned by Compaq so they are the data controller and they are legally liable."

Customers, already furious over being kept waiting for a month for their free upgrade to Windows XP, said they couldn't believe what had happened.

"I give up, what a complete fiasco," said Andrew Cleland, who bought a Compaq Presario 5146EA from PC World early in October.

"It seems ironic that the footer should say 'The contents of this email are confidential to the intended recipient at the email address to which it has been sent. It may not be disclosed or used by anyone other than the addressee nor may it be copied in any way'."

Experts said the matter was a nightmare for Compaq.

"What dreadful PR," said Alex Barnett, chief operating officer at web design firm Bluewave. "It looks like the kind of mistake that involves a manual process or a shoddily-written in-house application. But whatever system they're using, the golden rule is that this can't happen."

"This is now potentially very embarrassing for Compaq," said Neil Barrett, security consultant at Information Risk Management. "There is a clear link between email and the individual, and it is a possible breach of the Data Protection Act."

"This is ridiculous," agreed Mark Read, network security analyst at MIS-CDS. "Leaving aside the security aspect, it is effectively like giving away your customer database, and my immediate concern is whether there is a spammer on the list. That's a valuable chunk of information."

Read also pointed out that many of the intended recipients of the email may not learn of the blunder until Compaq contacts them to apologise.

"Customers using business email addresses may have had the message blocked at the corporate firewall because of the sheer number of names in the header," he said.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Senior SAS Developer - SAS,Macros

My client, a leading telecoms firm listed in the Sunday...

C# ASP.NET Developer - Gaming Sector - London - To £55k

ASP.NET C#, .Net 3.5, .Net 4.0 MVC developer to join...

Linux Systems Engineer

Linux Systems Administrator - £45k - London A Linux...

Unix Systems Administrator - Finance

Unix systems administrator required to work for leading...

To send to more than one email address, simply separate each address with a comma.