Identity, Security, Payments, Biometrics, Smart Cards and Authentication News
CBORD: Securing buildings, transactions, and the bottom line. www.cbord.com

UI: No evidence personal information taken in UBS computer breach

Thursday, June 2, 2005

After one of its computers containing 30,000 active credit card and student/employee ID numbers was improperly accessed from outside its network, the University of Iowa is alerting its book store customers of the breach so they can take appropriate measures, even though there has been no evidence that any personal information was accessed.


Although there is no evidence that any personal customer information was taken, the University of Iowa is alerting current and past University Book Store customers that a computer containing credit card numbers and student/employee ID numbers was improperly accessed from outside the UI network last month. As a precaution, the university wants potentially affected customers to know about the breach so they can make an informed decision on whether to take steps to protect themselves against the risk of identity theft and/or unauthorized credit card use.

The breach occurred on May 18 and was discovered later the same day. Upon discovering the breach, the University Book Store shut down and isolated the computer system, which may have contained up to 30,000 active credit card numbers. It should be noted that no other UI departments that accept credit card and/or ID charges are impacted.

An internal investigation by UI information technology authorities and by UI Police is under way, and the FBI has been notified.

According to Steve Fleagle, UI chief information officer, two independent firms have been retained by the UI to analyze the incident and determine the possible degree of exposure of personally identifiable customer information and also to determine what can be done to prevent similar occurrences in the future. The companies are VeriSign, a nationally recognized computer security firm, and The Starken Group of Cedar Rapids. Also, Visa and MasterCard have prescribed incident response checklists for such breaches, which are being closely followed in this case.

“The confidentiality of the bookstore customers’ private financial information is one of our highest priorities,” said David Grady, UI assistant vice president for student services, who supervises the book store. “Since this incident, we have been working closely with UI Information Technology Security Office and our consultants to understand how this breach occurred and to determine what steps we can take to avert a recurrence.”

Since the records in the tampered system did not contain complete addresses of the credit card holders, the university cannot notify customers individually. Grady has announced that the UI has established an information website for anyone with questions about the incident www.uiowa.edu/~ournews/bookstore/index.html.

Information on placing a precautionary fraud alert on credit files is included on the website. [end] 

Personal information of 9,000 current and prospective students was inadvertently posted online by Valencia College in Orlando. The school has apologized for the mistake.

The information included the students’ names, addresses, dates of birth and student ID numbers but not their Social Security numbers or financial information.

read more »

A server error on the University of Tampa computer system led to the accidental release of student data containing Social Security and student ID numbers and birth dates. The information for thousands of students was accessible on Google, according to the university.

read more »

Social Security numbers and credit card information of 2,818 users of a University of Maine computer server may have fallen into the hands of hackers, according to university officials.

read more »

Gemalto announced it has been appointed by Oman Information Technology Authority (ITA) as prime contractor to secure the country’s eGovernment services. The full solution encompasses strong authentication and digital signature using the eID card, as well as mobile authentication using a mobile handset.

read more »

Stratfor, a publisher of global intelligence and analysis, announced that CSID, a provider of global, enterprise-level identity protection and fraud detection technologies, has been retained to assist Stratfor customers whose financial information may have been compromised by recent cyber attacks.

read more »

If you want to use a credit or debit card at College of Brockport dining halls, forget it. Until the end of the school term, it’s mostly cash only due to a security breach which affected hundreds of credit and debit cards from students, staff and faculty.

read more »