29 Aug 2008
The Bank of New York Mellon (BNY Mellon) has admitted that the number of its customers hit by a data breach was much larger than previously stated.
The bank informed customers in May that 4.5 million customer account details, including names, addresses, dates of birth and Social Security numbers, had been compromised after two sets of tape backups went missing from a third-party courier.
However, it has now increased that figure to 12.5 million, possibly making this the biggest data breach of the year.
“It is simply outrageous that this mountain of information was not better protected, and it is equally outrageous that we are hearing about a possible six million additional individuals and businesses six months later,” said the Connecticut governor Jodi Rell.
“We fear a substantial number Connecticut residents are among this latest group. Had the hundreds of thousands of Connecticut residents affected been notified immediately that their data had been compromised, they could have taken steps to protect themselves.”
She added that she was considering levying financial penalties over the breach and instructing it to make financial restitution to customers. Her consumer protection commissioner Jerry Farrell Jr is investigating the case.
"Nothing in the data we were given in May and June by BNY Mellon indicated in any way that these additional six million individuals and businesses were involved," said Farrell.
“This certainly raises serious additional questions about how secure personal identifying data is at BNY Mellon and widens the scope of our investigation.”
Bank of New York Mellon is the world's largest custodial bank and one of the 10 largest asset managers. It is notifying customers about the breach, but says there is no evidence that the data has been abused.
The bank has set up a web page to keep people informed and is offering two years of free credit monitoring, $25,000 worth of identity theft insurance, reimbursement for the cost of one placement and one removal of a credit freeze for each of the three national credit reporting bureaus to customers affected.
Latest stories from Finance
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Low Latency Network Engineer, Senior Network Engineer...
SQL DBA - (North London) North London , £45k - 50k...
Business Architect – (North London) £65,000 – 75,000k...
Graduate Software Engineer - Javascript OR Android...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
let's calm down
For months I have posted a question on my blog: Has there ever been a documented example of identity theft committed as the result of lost backup tapes? So far, no one has shown me an example. and Best Western, it is easy to blow apparent data breaches out of proportion. --Ben
Posted by: Benjamin Wright 29 Aug 2008