21 Nov 2007
The head of HM Revenue and Customs (HMRC) has resigned after it was revealed in parliament that the personal details of 25 million Britons had been "lost in the post".
Chancellor of the Exchequer Alistair Darling said in a statement that two CDs with the details of 25 million families had been sent to the National Audit Office by courier firm TNT but failed to arrive.
The material was apparently put in the post by a junior employee at the HMRC office in Washington, Tyne & Wear.
The disks, which were password protected but not encrypted, contained names, addresses, dates of birth, child benefit numbers, National Insurance numbers and bank or building society account details.
Paul Gray, chairman of HMRC, has already resigned and opposition MPs are calling on Darling to do likewise.
"The lost bank account numbers, names and addresses represents a gold mine for thieves and is much more valuable than credit card numbers or taxpayer ID numbers," said Avivah Litan, vice president at Gartner Research.
"Bank account numbers sell for the highest price on the black market, between $30 and $400, which is significantly more than the 50 cents to $5 that criminals pay for credit cards.
"If evidence emerges that the data fell into criminal hands, the UK banks may be forced to close the 15 million accounts and issue new ones at an enormous cost to them and a major inconvenience for their customers."
This is the third in a series of data breaches at HMRC. The organisation lost the details of a number of high net worth individuals in October, and banking details for 15,000 savers went missing earlier this month when a laptop was stolen.
"Another week and another high profile data breach for the government," said Joseph Hoban, vice president at data protection firm GuardianEdge.
"This is not the first time that public data has been compromised and, if lacklustre security continues to rule, it certainly will not be the last.
"It is time that tougher security measures were taken to protect our most confidential files. Securing two disks with only a password is not sufficient."
Darling has described the incident as "extremely regrettable" but has resisted calls for his resignation.
The loss has also sparked renewed calls for a data breach law that would force the government and companies to inform people if their data had been put at risk.
"California introduced data breach notification legislation some time ago, which compels businesses to inform customers if their personal data may have been compromised," said Richard Turner, vice president of sales at security firm RSA.
"The introduction of similar legislation would not only be a significant step in combating fraud, but constitutes a basic human entitlement.
"Public awareness of security breaches would serve to focus organisations on ensuring that confidential information is adequately protected, and enable the public to take appropriate safeguards in the event of a compromise."
Latest stories from Public Sector
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
/ Corporate Account Manager / Management Consultant...
Prince 2 Project Management Professional, Client Facing...
Solution Architect / Technical Project Manager / Corporate...
Solution Architect / Technical Project Manager / Corporate...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Better data protection
Human error will always be a factor, but if the discs and usbs are encrypted properly to begin with then the general public can rest their minds that their data will be safe even in the event of loss or stolen cds and usbs.
Posted by: Louisa 28 Jan 2009
HMRC Database
The latest claim in defence is that it would have been too expensive to select only the data that NAO required. Having dealt with databases for 30+ years I find this utterly absurd. All databases have a query language (often SQL) which make selection possible and often easy and certainly cheap. It is also possible to design the database that certain fields are only accessible by authorised persons. That this was not done shown incompetence at a management level. Using password protection is also a sign of senior management failure. PGP (Pretty good pricacy) costs nothing but is vastly more secure than passwords and there are better encryption methods. Having been in the Civil Service I know that Administrators who pull the strings pride themselves on culture not competence. To know how a database actually works would to them be a sign of failure. This leads to the results we have seen.
Posted by: misceng 22 Nov 2007