Skip Links

Network World

  • Social Web 
  • Email 
  • Close

California discloses massive ID theft

By Paul Roberts , IDG News Service , 10/20/2004
  • Share/Email
  • Comment
  • Print

The state of California has warned residents that their personal data may have been stolen from computers at the University of California, Berkeley, after a database used by researchers there was compromised by hackers.

The California Department of Social Services (CDSS) issued a media advisory on Tuesday, saying that the agency was working with the FBI to investigate an intrusion on a computer at Berkeley that contained personal information on around 1.4 million recipients and providers of In Home Supportive Services (IHSS), which provides home-care services to low-income elderly and disabled Californians. Names, addresses, telephone and Social Security numbers, as well as the birth dates for IHSS participants, could have been stolen by the malicious hackers, according to Carlos Ramos, assistant secretary at CDSS.

The state agency gave Berkeley the IHSS data, which was stored on a machine at the university, for research on the CDSS program. If stolen, the information could be used to fake the identity of IHSS recipients.

The compromise occurred on Aug. 1 and was discovered on Aug. 30 by Berkeley IT staff using intrusion detection software, Ramos said.

According to Ramos, investigators know a malicious hacker exploited a vulnerability in "commercially available database software" and compromised the computer, but they don't know if the attack was targeted, speculating that malicious hackers possibly discovered the system by scanning for machines running vulnerable versions of the database software.

While evidence indicates that none of the database's information has been misused, IHSS recipients were encouraged to obtain a credit report and make sure that they were not identity theft victims, the CDSS said in a statement.

A database of personal information on elderly and infirm people would be an attractive target for identity thieves, who may lack the technical sophistication to defend themselves against identity theft, and may even be unaware the IHSS database stored their data, said Jonathan Bingham, president and founder at Intrusic, a Waltham, Mass., company that makes software for spotting suspicious activity on computer networks.

"You take somebody who's elderly and hasn't had experience with computer networks - they're not going to get it," Bingham said.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.