Chronology of Data Breaches
Security Breaches 2005-Present

Posted Date: April 20, 2005
Updated Date: July 30, 2010

Save or Print PDF of Entire Breach List including introduction.Save or Print PDF of Entire Breach List(* Including introduction.) Filter breach list before saving or printing PDF.Save or Print PDF (* Select filters.)
    If you do not have access to PDF, print Chronology in landscape view.

Skip the introductory text and go directly to the listing of data breaches below.

What does the Chronology of Data Breaches contain?

The data breaches noted below have been reported because the personal information compromised includes data elements useful to identity thieves, such as Social Security numbers, account numbers, and driver's license numbers. Some breaches that do NOT expose such sensitive information have been included in order to underscore the variety and frequency of data breaches. However, we have not included the number of records involved in such breaches in the total because we want this compilation to reflect breaches that expose individuals to identity theft as well as breaches that qualify for disclosure under state laws. The breaches posted below include only those reported in the United States. They do not include incidents in other countries.

What does the Total Number indicate?

The running total we maintain at the end of the Chronology represents the approximate number of *records* that have been compromised due to security breaches, not necessarily the number of *individuals* affected. Some individuals may be the victims of more than one breach, which would affect the totals.

In reality, the number given below should be much larger. For many of the breaches listed, the number of records is unknown. Further, this list is not a comprehensive compilation of all breach data (see below).

Is the Chronology of Data Breaches a complete listing of all breaches?

No, it is not a complete listing of breaches. The list is a useful indication of the types of breaches that occur, the categories of entities that experience breaches, and the size of such breaches. But the list is not a comprehensive listing. Most of the information is derived from the Open Security Foundation list-serve (see below) which is in turn derived from verifiable media stories, government web sites/pages, or blog posts with information pertinent to the breach in question. Many breaches (particularly smaller ones) may not be reported. If a breached entity has failed to notify its customers or a government agency of a breach, then it is unlikely that the breach will be reported anywhere. If you are aware of a breach that is not included in our list, below, feel free to contact us here: http://www.privacyrights.org/about_us.htm.

Are there state-specific breach listings?

Some states have state laws that require breaches to be reported to a centralized data base. These states include Maine, Maryland, New York, New Hampshire, North Carolina, Vermont and Virginia (Virginia’s notification law only applies to electronic breaches affecting more than 1,000 residents).  However, a number of other states have some level of notification that has been made publicly available, primarily through Freedom of Information requests. These states include California, Colorado, Florida, Illinois, Massachusetts, Michigan, Nebraska, Hawaii and Wisconsin. For details, see the Open Security Foundation Datalossdb website: http://datalossdb.org/primary_sources

How often is the Chronology updated?

We usually update this list twice each week.

Where do you obtain information about the data breaches that are reported on this Web page?

Most of the breaches summarized below on this page have been obtained from the Open Security Foundation list-serve.  As of January 2010, we have expanded our sources to also include Databreaches.net, PHI Privacy and NAID.

  • The Open Security Foundation's DataLossDB.org (www.datalossdb.org) offers a free e-mail list-serve on the latest breaches.
    To subscribe to DataLoss, send a message to: dataloss-subscribe@datalossdb.org
  • The DataLossDB.org page includes a search engine and news articles for the breaches listed below, and also provides an open source database of its data breach records. It is a flat comma-separated value file that can be imported into a database or spreadsheet program for your own data analysis. Visit http://datalossdb.org/download.
  • Beginning in January 2010, we have expanded the sources of our breaches.  We now include the following sources:
    •  Databreaches.net (www.databreaches.net) is a spinoff from www.PogoWasRight.org and compiles a wide range of breach reports since January 2009.
    • Personal Health Information Privacy (www.phiprivacy.net/), affiliated with Databreaches.net, is a database that compiles only medical data breaches.
    • National Associaion for Information Destruction, Inc (www.naidonline.org) provides monthly newsletters that include a number of data breaches largely due to improper document destruction.

What should I do if my personal information has been compromised in a data breach?

For tips on what to do if your personal information has been exposed due to a security breach, read our guide at http://www.privacyrights.org/fs/fs17b-SecurityBreach.htm.

Are there resources for businesses and other organizations on how to avoid having sensitive data breached?

Learn about security and privacy protection practices for your workplace.

What should I do if my business or organization experiences a security breach?

The following resources guide businesses who have experienced a security breach through the notification process and in working with law enforcement.

Do states have laws that require those entities that experience a data breach to notify those affected?

Yes. The catalyst for reporting data breaches to the affected individuals has been the California law that requires notice of security breaches. It is the first of its kind in the nation, implemented July 2003.

More than 40 of states have since passed laws requiring that individuals be notified of security breaches. For a list of states enacting security breach and freeze laws, visit these Web sites:

Which states have laws that require breached organizations to report breaches and submit notice letters to a central clearinghouse?

The state of Massachusetts requires that breached entities report data breaches to the Massachusetts Office of Consumer Affairs and Business Regulation.

The Open Security Foundation and Chris Walsh have compiled breach notice letters from the states that require breached entities to submit such letters to a central repository. These states are: Maryland, New Hampshire, New York, North Carolina, and Vermont. To view these letters, visit http://datalossdb.org/primary_sources.

Has anyone analyzed this and other data breach listings in order to compile statistics and arrive at other observations? Have any analyses of security breach laws been published?

Are there other resources with additional information about security breaches?


Click or unclick the boxes then select go.


Select features, then click GO.

Breach Total
494,643,593 RECORDS BREACHED
(Please see explanation about this total.)
from 1,645 DATA BREACHES made public since 2005
Filter breach list before saving or printing PDF.Save or Print PDF (* Select filters.) Save or Print PDF of Entire Breach List including introduction.Save or Print PDF of Entire Breach List (* Including introduction.)
If you do not have access to PDF, print Chronology in landscape view.
Date Made Publicsort icon Name Entity Type
July 30, 2010 FIrst Advantage Tax Consulting Services (TCS)
Indianapolis, Indiana
BSF PORT

32,842

A laptop that contained personal information was lost or stolen during an airport layover.  The Social Security numbers of people who were employed by companies that used TCS for tax help were on the laptop. The laptop did have a password and after it was lost its access to TCS's network was blocked.

 
Information Source:
Databreaches.net
records from this breach used in our total: 32,842

July 29, 2010 University of Virginia
Charlottesville, Virginia
EDU PORT

Unknown

A transient was ordered to spend time in a men's diversion program after pleading guilty to stealing credit cards and electronics. One of the laptops he stole was a University-owned laptop. The man served 12 months in jail before being sentenced and slept in his car and in the University library during the time of the thefts.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

July 29, 2010 DebtStoppers USA, Robert J. Semrad and Associates
Chicago, Illinois
BSF PHYS

hundreds of documents (At least 100)

 

Documents from the Joilet office were involved

A tipster led to the discovery of hundreds of personal and financial documents in a trash bin outside the attorney's office. The documents included Social Security numbers, names, addresses, driver's license numbers, and signed debit card authorizations from clients.

 
Information Source:
Databreaches.net
records from this breach used in our total: 100

July 29, 2010 Rowland Equipment Co.
Smithfield, Virginia
BSR INSD

Over 30 customers

Linda Rowland pleaded guilty to wire fraud and identity theft. She used customer names and information to falsify loan agreements for over 10 years.

 
Information Source:
Databreaches.net
records from this breach used in our total: 30

July 28, 2010 Wendy's
Tukwila, Washington
BSR INSD

At least 135 accounts

A dishonest employee used a skimmer between September 14, 2009 and July 21, 2010 to commit identity theft and make fraudulent charges to customer credit accounts.

 
Information Source:
Databreaches.net
records from this breach used in our total: 135

July 28, 2010 Time Warner Cable
New York, New York
BSR INSD

Unknown

A former employee was convicted of installing spyware on three company computers. The employee intended to capture the passwords of users who had access to a customer database and a billing system.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

July 27, 2010 Rite Aid Corporation
Camp Hill, Pennsylvania
BSR PHYS

Unknown

Etters, PA is also mentioned as Rite Aid's headquarters

Rite Aid paid one million dollars to settle HIPAA privacy violations. Rite Aid also agreed to update corporate policies and procedures so that patient medical information would be properly disposed, employees would be properly trained in disposal of patient information, and employees would be held accountable if they did not dispose of patient information properly.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

July 27, 2010 Office of Attorney David Naworski
San Antonio, Texas
BSO PHYS

75

Attorney Naworski left legal files in a public dumpster. Naworski thought it was appropriate to dispose of the files in this way since the accounts were old and closed. The documents contained names, addresses, bank account information, Social Security numbers, driver's license numbers, and dates of birth.

 
Information Source:
Databreaches.net
records from this breach used in our total: 75

July 27, 2010 Cooper University Hospital
Camden,
MED PORT

Unknown

A flash drive with the personal information of graduate medical residents and fellows was reported missing on July 23rd.  The personal information included Social Security numbers, addresses, and phone numbers.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

July 27, 2010 Citigroup Inc.
New York, New York
BSR DISC

117,600 users with app (No incidents reported)

Citigroup's mobile banking application for Apple's iphone has a security flaw that saves user account numbers, bill payments and security access codes into a hidden file on the iphone and the user's computer.  An upgrade that will fix the problem is available.

 
Information Source:
Media
records from this breach used in our total: 0

July 26, 2010 United States Post Office Batesburg-Leesville
Batesburg-Leesville, South Carolina
GOV PHYS

Two employees reported

Improperly reusing office paper led to the mailing out of names and Social Security numbers of two post office employees. Two women reported receiving the personal information, which was probably from a timecard, on the back of a post office receipt.

 
Information Source:
Databreaches.net
records from this breach used in our total: 2

July 26, 2010 Natchez Police Department
Natchez, Mississippi
GOV INSD

Unknown

A police officer with the Natchez department fraudulently used and encouraged others to use stolen credit and debit cards.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

July 24, 2010 University of Texas Arlington
Arlington, Texas
EDU HACK

27,000 (2,048 SSNs reported)

Student records dating from 2000 to June 21, 2010 were compromised on a University file server on four separate occasions within the last two years.  The server contained student health center prescription records.

 
Information Source:
Databreaches.net
records from this breach used in our total: 2,048

July 23, 2010 Thomas Jefferson University Hospitals
Philadelphia, Pennsylvania
EDU PORT

Approximately 21,000

A password-protected laptop was stolen from the office of an employee on June 14th.  The computer should not have contained protected health information, but did.  It also contained patient name, birth date, gender, ethnicity, diagnosis, Social Security number, insurance information, and hospital account number.

 
Information Source:
Databreaches.net
records from this breach used in our total: 21,000

July 23, 2010 University of California San Francisco (UCSF) Medical Center
San Francisco, California
EDU INSD

Possibly hundreds

A former employee used the Social Security numbers of his colleagues to obtain vouchers for Amazon.com purchases. He secretly used the Social Security numbers to create hundreds of accounts and complete 382 online surveys in exchange for $100 online vouchers.

 
Information Source:
Databreaches.net
records from this breach used in our total: 100

July 22, 2010 The Loft and Comedy Club
Columbus, Georgia
BSR DISC

60 customers

Names, addresses, phone numbers, and credit card information from customers of The Loft and Comedy Club were discovered through a Google search. Customer data from 2004 to 2008 was posted. The Loft fixed the problem and is working on having the site removed.

 
Information Source:
Databreaches.net
records from this breach used in our total: 60

July 22, 2010 Colorado Department of Health Care Policy and Financing
Denver, Colorado
GOV PORT

105,470 (0 SSNs and financial information reported)

A hard drive containing personal information for clients enrolled in state-provided health insurance was stolen from the Colorado Office of Information Technology. The information included names, state ID number and the name of the client's program. The Agency is certain that contact information, financial information and Social Security numbers were not involved.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

July 22, 2010 Arizona Federal Credit Union
Phoenix, Arizona
BSF INSD

At least 4

A former employee is accused of using bank member information to run credit checks on victims and apply for credit in their names. The former employee was fired and arrested on identity theft charges.

 
Information Source:
Databreaches.net
records from this breach used in our total: 4

July 22, 2010 Iowa Department of Agriculture and Land Stewardship
Des Moines, Iowa
GOV PORT

3,404

A laptop containing personal information from Iowa residents was stolen from a locked state vehicle. The computer was encryption protected and contained names, addresses, phone numbers and Social Security numbers. Iowa residents who participate in the Iowa Horse and Dog Breeding Program were notified.

 
Information Source:
Databreaches.net
records from this breach used in our total: 3,404

July 21, 2010 Lincoln National Life Insurance
Radnor, Pennsylvania
BSF PHYS

26,840

A vendor printed a user name and password for agents and authorized brokers in a brochure.  The brochure was also posted on an agent's public website.  The login information enable access to a website containing medical records and other personal information form individuals seeking life insurance.  Applicant name, Social Security number, address, policy number, driver's license number and credit information is also on the website. 

 
Information Source:
Databreaches.net
records from this breach used in our total: 26,840

July 20, 2010 Long Island Consultation Center (LICC)
Rego Park, New York
MED PORT

800 (0 reports of SSNs or financial information)

A computer device containing doctor reports was reported missing from a secured area at LICC on May 24th. Names, dates of birth, diagnostic information and treatment information of some patients may have been included on the device.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

July 20, 2010 South Shore Hospital
South Weymouth, Massachusetts
MED PORT

800,000 (unknown number of SSNs and financial information)

Computer files containing personal, health and financial information of volunteers, patients, vendors, business partners and employees from January 1996 through January 2010 may have been lost by a professional data management company. Depending on the person's association with the hospital, the information exposed could be full name, address, phone number, date of birth, Social Security number, driver's license number, medical record number, patient number, bank account information, credit card number, diagnoses and treatment.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

July 20, 2010 Maryland Department of Human Resources
Baltimore, Maryland
GOV INSD

3,000 clients

An employee posted Social Security numbers and other personal information of around 3,000 clients on an outside website. The organization provides food stamps and other benefits and aid to clients. The employee was placed on administrative leave.

 
Information Source:
Databreaches.net
records from this breach used in our total: 3,000

July 19, 2010 LV Financial Services
Orlando, Florida
BSF PHYS

Unknown

Dozens of boxes of files from medical offices that hired LV to collect unpaid bills were found in an Orlando public dumpster. The files contained names, addresses, Social Security numbers, driver's license copies and credit reports. The collection agency went out of business in 2005 and the location of the files prior to this incident is unknown.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

July 16, 2010 United Healthcare (UnitedHealthcare), Deere and Company
Minneapolis, Minnesota
MED PHYS

1,097 (no SSNs or financial information reported)

Deere and Company is headquartered in Moline, Illinois

United Healthcare notified members of a Deere and Company employee benefits plan of a mistake that led to claims summary statements being sent to the wrong addresses. Dates of services, categories of service, cost of service, and physician names were included.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

July 16, 2010 Buena Vista University
Storm Lake, Iowa
EDU HACK

93,000

Someone gained unauthorized access to a BVU database. The database contained records of names, Social Security numbers, and driver's license numbers of BVU applicants, current and former students, parents, current and former faculty and staff, alumni and donors. These records go back as far as 1987.

 
Information Source:
Databreaches.net
records from this breach used in our total: 93,000

July 16, 2010 Connecticut Department of Labor
Bridgeport, Connecticut
GOV PORT

5,000

A highly encrypted laptop was stolen from the office of the Connecticut Department of Labor. The laptop contained confidential information about unemployment insurance claims, wage discrepancy complaints and some Bridgeport area employers.

 
Information Source:
Databreaches.net
records from this breach used in our total: 5,000

July 15, 2010 Office of Dr. Thomas K. Lee
Barstow, California
MED PHYS

Hundreds of records

An anonymous tipster called the Sheriff's Department and reported unattended boxes of personal records outside the dental office. The boxes contained patient records from the early 1990's to the present. These records had personal information such as Social Security numbers, names, birth dates, credit card numbers, and addresses. The Sheriff's Department destroyed the records and warned patients of dentists Lee, Sang H. Yoon and Patricia Patterson.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

July 15, 2010 Prince William County Intellectual Disabilities Case Management
Woodbridge, Virginia
GOV PORT

669

On June 18th or 19th, a government-issued Blackberry was stolen from an employee's car. The Blackberry had personal information on patients enrolled in the program. The County notified residents that their Social Security numbers, names, addresses, dates of birth, phone numbers, and Medicaid numbers may have been accessed.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 669

July 15, 2010 Utah Department of Workforce Services
Salt Lake City, Utah
GOV INSD

1,300 (Unknown number of SSNs)

A leak that allowed anti-immigration activists to post and circulate the names, Social Security numbers, medical information, addresses, workplaces, and phone numbers of alleged illegal immigrants in Utah has been linked to Utah's Department of Workforce Services. A large number of employees had access to this information.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

July 15, 2010 Nix Check Cashing
Manhattan Beach, California
BSF STAT

Unknown (over one hundred from New Hampshire)

The May 17th theft of a computer resulted in the exposure of customer names, addresses, phone numbers, Social Security numbers and driver's license numbers. Affected customers were notified on June 30th.

 
Information Source:
Databreaches.net
records from this breach used in our total: 100

July 15, 2010 NBTY
Bohemia, New York
BSR DISC

Unknown

An email containing current and former employees' and plan participants' personal information was sent to the wrong recipient on June 15th. The information in the email included names, dates of birth, and Social Security numbers.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

July 15, 2010 Alcoa Global Mobility Group
New York, New York
BSO DISC

Unknown

An electronic folder containing personal information on current and former expatriates and others who received assistance from Alcoa's Global Mobility Group was shared as a public folder within its network.  The personal information included names, dates of birth, family members' names and dates of birth, salary compensation, Social Security numbers, and some people's medical information.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

July 14, 2010 SunBridge Healthcare
Albuquerque, New Mexico
MED PORT

3,830

Residents of Arizona, Colorado, Montana, California, New Mexico, Oklahoma, Idaho, Washington, Wyoming and Utah affected

A laptop containing Social Security numbers, medical record numbers, dates of service, health insurance numbers and names was stolen in May. The laptop was password-protected.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 3,830

July 14, 2010 Oregon State University
Corvallis, Oregon
EDU HACK

34,000 current and former employees (unknown number of SSNs)

A University computer containing personal information of current and former employees was found to be infected by a virus. Employee records from 1999 to 2005 contained Social Security numbers.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

July 14, 2010 Carle Clinic Association
Urbana, Illinois
MED PHYS

Approximately 1,300 (no SSNs or financial information reported)

An impostor posing as a representative of the organization's recycling service removed several barrels of purged x-ray films and film jackets. The health information included patient names, dates of birth, gender, clinic medical numbers, internal accession numbers, site locations, physician or provider names, and internal provider numbers.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

July 14, 2010 Blue Island Radiology
Blue Island, Illinois
MED PORT

2,000 (number and type of financial account numbers and SSNs unknown)

A backup data tape and compact disc containing protected health information were never received. Individuals demographic, financial and clinical information were on the CD.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

July 14, 2010 Blue Cross Blue Shield Association
Chicago, Illinois
MED PHYS

Approximately 15,000 (0 SSNs and financial information reported)

An error in the quarterly address update process resulted in the mailing of protected health information to incorrect addresses. The information in the letters included demographic information, explanation of benefits, clinical information, and diagnoses. The returned mail was collected and the organization verified whether or not it had been delivered.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

July 14, 2010 VHS Genesis Lab
Berwyn, Illinois
MED PHYS

Over 500 (0 SSNs and financial information involved)

A month's worth of client invoices went missing. It does not appear that they were mailed. The invoices contained health information such as names, dates of birth, and medical testing information.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

July 14, 2010 University of Pittsburgh Student Health Services
Pittsburgh, Pennsylvania
EDU INSD

8,000 (Not included because no specific type of financial information stated)

An employee dishonestly took documents containing names and financial information. The employee was fired.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

July 14, 2010 Tomah Memorial Hospital
Tomah, Wisconsin
MED INSD

600

A nurse used patient names and account numbers to illegally obtain narcotics. The nurse was fired.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

July 13, 2010 Carolina Center for Development and Rehabilitation
Charlotte, North Carolina
MED PHYS

Approximately 900

After a doctor left office cleaning to his sons, they mistakenly threw out hundreds of medical records. The medical records were left in a public recycling bin and included medical histories, pictures of patients and Social Security numbers.

 
Information Source:
NAID
records from this breach used in our total: 900

July 12, 2010 Connecticut Department of Education, State Teachers' Retirement Board
Hartford, Connecticut
GOV PORT

Unknown

An encrypted flash drive containing 2007-2008 member annual statement data has been lost or stolen. It is unlikely that outside parties could read the pension and employment credit.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

July 10, 2010 Ohio Department of Developmental Disabilities
Columbus, Ohio
MED DISC

200

Within a two week period personal information of 200 people using the Department's services was accidentally posted online. The Social Security numbers, names, addresses, medical records, and treatment information were only available for viewing through the state computer network.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 200

July 10, 2010 Village of Big Bend
Big Bend, Wisconsin
BSO PORT

Unknown

A laptop containing payroll information for the village's employees was stolen from the car of the village's payroll provider in Milwaukee. Police have not recovered the laptop. The provider reported the theft and sent letters to employees to inform them their personal information was not secure. The provider recommended that employees contact a credit bureau that would place a 90-day alert on their information to prevent identity theft. 

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

July 10, 2010 Cisco Live 2010
Las Vagas, Nevada
BSO HACK

Unknown

Someone hacked the list of attendees for the recent Cisco Live 2010 users' conference, a security breach that led Cisco to notify the customers as well as a broader group who have dealings with the company. A vendor told Cisco that someone had made "an unexpected attempt to access attendee information through ciscolive2010.com," the event Web site. That lead to the general notification that Cisco sent to attendees and others who had been invited but did not attend. According to Cisco, details about less than 20% of those on the list were compromised. The breach was closed quickly, "but not before some conference listings were accessed." The compromised information consisted of Cisco Live badge numbers, names, titles, company addresses and e-mail addresses. "No other information was available or accessed," according to the warning Cisco Live's event team sent via e-mail.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

July 9, 2010 Emily Morgan Hotel
San Antonio, Texas
BSO PHYS

17,000 hotel guests

Identity thieves obtained stacks of credit card receipts from one of the hotel's storage rooms in 2006.  Hundreds of thousands of dollars in fraudulent charges were then made in three different states.  Investigators first became aware of a large identity theft issue in the area during the beginning of 2009.

 
Information Source:
Databreaches.net
records from this breach used in our total: 17,000

July 8, 2010 Waukesha County
Big Bend, Wisconsin
GOV PORT

Unknown

A laptop was stolen from a payroll services provider of the county. It is unknown what types of Big Bend employee payroll information were contained on the laptop.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

July 7, 2010 University of Hawaii
Honolulu, Hawaii
EDU STAT

53,000

53,000 people may have had their personal information exposed after a breach to the University of Hawaii computer system was discovered. The university released statement  that more than 40,000 Social Security numbers and 200 credit card numbers were part of the exposed information that was housed on a computer server used by the Manoa campus parking office.

 
Information Source:
Dataloss DB
records from this breach used in our total: 53,000

July 7, 2010 Massachusetts Secretary of State, Securities Division
Boston, Massachusetts
GOV PORT

139,000

The Massachusetts Secretary of State's office accidentally released confidential personal information earlier this year on 139,000 investment advisers registered with the state. The data, including the advisers' Social Security numbers, were on a CD-ROM sent to IA Week, an investment industry publication that had requested public information from the Securities Division. Secretary of State IA Week had asked for a list of registered investment companies. The Securities Division responded by sending a list of individual investment professionals. In addition to their names and Social Security numbers, this list included their dates and locations of birth, height, weight, hair color, and eye color.

 
Information Source:
Dataloss DB
records from this breach used in our total: 139,000

July 6, 2010 Massachusetts Secretary of State Office
Boston, Massachusetts
GOV PHYS

139,000 investment advisers

In an attempt to release public information from the Securities Division, the Massachusetts Secretary of State's office released the Social Security and driver's license information of 139,000 investment advisers registered with the state. The information was sent on a CD-ROM sent to IA Week, an investment industry publication.

 
Information Source:
Databreaches.net
records from this breach used in our total: 139,000

July 6, 2010 University of Florida
Gainesville, Florida
EDU PHYS

2,047

Social Security numbers or Medicaid identification numbers were shared with a telephone survey company and included on address labels sent out to request research participation.  The letters were sent through the U.S. Postal Service on May 24th and the issue was discovered on June 6th. 

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 2,047

July 6, 2010 DentaQuest
Chicago, Illinois
MED DISC

76,000

In a statement datelined out of Nashville, DentaQuest reported the laptop theft occurred March 20 in Chicago and was informed of the incident April. DentaQuest reported the laptop contained a database which held the personal information of approximately 76,000 clients. The contractor advised most of the data is not considered sensitive, but the device did contain the first names, last names and Social Security Numbers of about 21,000 individuals. Some 10,500 are Tennessee residents.

 
Information Source:
Dataloss DB
records from this breach used in our total: 76,000

July 4, 2010 AMR Corporation
Fort Worth, Texas
BSO PORT

79,000

American Airlines parent company said Friday the personal information of about 79,000 retirees, former and current employees has been compromised after a hard drive was stolen from its Fort Worth headquarters. No customer data was affected. The data was held by the company's pension department.  The drive contained images of microfilm files, which included names, addresses, dates of birth, Social Security numbers and a "limited amount" of bank account information. Some health insurance information may have also been included -- mostly enrollment forms, but also details about coverage, treatment, and other administrative information. The data spans a period from 1960 to 1995. AMR also believes some of the employee files also contained information on beneficiaries, dependents and other employees from 1960 to 1995.

 
Information Source:
Dataloss DB
records from this breach used in our total: 79,000

July 4, 2010 Beautiful Brands International
West Lafayette, Indiana
BSR HACK

Unknown

Computer hackers have infiltrated the credit card processing system.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

July 2, 2010 AMR Corporation
Fort Worth, Texas
BSO STAT

79,000

Retirees, current, and former employees who participated in AMR's pension plan may have had their names, Social Security numbers, addresses, dates of birth, and other personal information stolen by the theft of a hard drive containing microfilm files. Employees and beneficiaries of employees who were enrolled between 1960 and 1995 are at risk.

 
Information Source:
Databreaches.net
records from this breach used in our total: 79,000

July 2, 2010 Cornerstone
Nashville, Tennessee
NGO PHYS

1,537 clients

According to Cornerstone: "During the weekend of April 30th, 2010, flood waters broke windows of our administrative office for School-Based Services... As a result of the unprecedented flooding that occurred, some clinical record information, along with name, Centerstone ID#, Social Security number, and date of birth, may have been removed from the building by flood waters."

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 1,537

July 1, 2010 NYU Langone Medical Center Hospital for Joint Diseases
New York, New York
MED PORT

2,563 (no SSNs or financial information reported)

An unencrypted portable USB was lost or stolen sometime around May 12th. It contained patient names, medical record numbers, sex, age, procedure, attending physician, time of arrival in recovery room and time of discharge from recovery room.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

June 30, 2010 Lincoln Medical and Mental Health Center
Bronx, New York
MED PORT

130,495 patient

Multiple CDs containing patient personal information were lost in transit by FedEx. Information included dates of birth, driver's license numbers, descriptions of medical procedures, addresses, and Social Security numbers. Siemens Medical Solutions USA, the Hospital's billing contractor, shipped the CDs around March 16th. They were never received.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 130,495

June 29, 2010 University of Oklahoma
Norman, Colorado
EDU HACK

Unknown

The university's Information Technology department noticed unusual Internet activity on a laptop computer associated with its network. It determined the computer belonged to an employee and was infected with a virus known as Zeus or Z-Bod. The employee's laptop had access to computer files that contain student names and Social Security numbers.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

June 29, 2010 University of Maine
Orono, Maine
EDU HACK

4,585

Hackers compromised the personal information of 4,585 students who received services from the school's counseling center. The center provides students with support and mental health services. The information on the servers included names, Social Security numbers and clinical information on every student who sought counseling services from the center between August 8, 2002 and June 21 of this year.

 
Information Source:
Dataloss DB
records from this breach used in our total: 4,585

June 29, 2010 Destination Hotels & Resorts
Englewood, Colorado
BSO HACK

700 customers

Hackers have broken into the payment processing system of Destination Hotels & Resorts, a high-end chain best known for its resort hotels in destinations such as Vail, Colorado; Lake Tahoe, California; and Maui, Hawaii. Destination has uncovered a malicious software program inserted into its credit card processing system from a remote source. Destination Hotels is in the process of notifying victims but will not say how many people have had their credit card numbers stolen. The attackers appear to have hit only point-of-sale processing systems, where credit cards are swiped for purchases. Personal information such as guests' home addresses was not compromised.

UPDATE (7/2/2010): Around 700 customers were affected nationwide by the hack; including dozens of customers of the Driskill Hotel of Austin, Texas.

 
Information Source:
Dataloss DB
records from this breach used in our total: 700

June 29, 2010 Cal State San Bernardino (CSSB)
San Bernardino, California
EDU DISC

36 students

Information such as names and Social Security numbers was exposed to the public through a web server. The students affected were on the class roster for a computer science and engineering course. The files were discovered and removed on June 10th.

 
Information Source:
Databreaches.net
records from this breach used in our total: 36

June 29, 2010 Sparta Board of Education
Sparta Township, New Jersey
GOV DISC

At least 200

Several vendor Social Security numbers and tax identification numbers were accidentally sent out via email to a local activist requesting information on Sparta Board of Education vendors. 

UPDATE (7/8/10): The activist mentioned is Jesse Wolosky and he has not returned the information because "they could get lost in cyberspace or go to the wrong inbox."  Wolosky also claims that state agencies are looking into the matter.  The number of Social Security numbers is still unknown since Wolosky claims 600-800 and the district claims 200-300.

 
Information Source:
Databreaches.net
records from this breach used in our total: 200

June 29, 2010 Brooklyn Tech High School
Brooklyn, New York
EDU HACK

2,416; 103 Social Security numbers

Hackers accessed PSAT information from the school and posted the names, home addresses, citizenship status, and Social Security numbers of students. The information was discovered on the school's website.

 
Information Source:
Databreaches.net
records from this breach used in our total: 103

June 29, 2010 Merrimack Mortgage
Greer, South Carolina
BSF PHYS

Unknown

Personal documents from Merrimack Mortgage were found in an unsecured public dumpster. The documents were not shredded and contained Social Security numbers, credit scores, bank information, and other personal information.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

June 29, 2010 A Woman's Place
Ketchikan, Alaska
MED DISC

Around 400 (0 SSNs reported)

An ACLU lawsuit claims that police acted inappropriately during a raid of A Woman's Place clinic. The lawsuit claims that police not only confiscated medical records, but read them and revealed sensitive medical information about patients to outside parties.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

June 29, 2010 Ridgefield High School
Ridgefield, Connecticut
EDU HACK

Unknown (the students of a few teachers)

Two students were arrested for hacking into their school's computer system. Their goal appears to be changing their own grades; but they had access to the grades and personal information of other students.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

June 28, 2010 Children's Hospital of Orange County
Orange, California
MED PHYS

Unknown

The Hospital is checking its database for accuracy after discovering that patient files have been faxed to the wrong location at least twice. Patient records were faxed to an auto shop in 2009, and the wrong doctor on a separate occasion.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

June 28, 2010 Eastern Connecticut Health Network Pension Plan
Manchester, Connecticut
BSF PHYS

3,178

Mercer, the firm's consulting group, provided a subcontractor with a file containing Pension Plan participant addresses and Social Security numbers. The Social Security numbers were exposed on the mailing label.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 3,178

June 26, 2010 Federal Aviation Administration
Washington, District Of Columbia
GOV DISC

3,000,000 airmen and airwomen

An investigation into the Federal Aviation Administration found that the medical and personal information of airmen and airwomen is at risk.  Names, addresses, Social Security numbers, mental and physical health certification information and other personal information is vulnerable to unauthorized access from former staff and could be accessed through the installation of malicious codes.  The computer system was hacked in 2009.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 3,000,000

June 25, 2010 University Hospital
Augusta, Georgia
MED PORT

13,000 patient records

Two backup tapes containing personal information have gone missing. The hospital does not suspect theft and does believe that there is a very low probability that the personal information on the tapes can be misused. However, credit monitoring services are being offered to those who were affected. The hospital gave up looking for the tapes on May 7th and began notifying patients in late June. 

Per phone interview with University Hospital, Social Security number were involved but they are unaware of any financial data involved in this breach.

 
Information Source:
Dataloss DB
records from this breach used in our total: 13,000

June 23, 2010 Anthem Blue Cross, WellPoint
Pasadena, California
BSF DISC

470,000

More than 200,000 Anthem Blue Cross customers this week received letters informing them that their personal information might have been accessed during a security breach of the company's website. Only customers who had pending insurance applications in the system are being contacted because information was viewed through an on-line tool that allows users to track the status of their application. Social Security and credit card numbers were potentially viewed.  Anthem Blue Cross merged with WellPoint in 2004.

UPDATE (6/29/10): Around 470,000 customers in 10 states were notified of the breach.  The original story states that only applicants were affected, but existing customers also received notification of a possible breach of their information.

UPDATE (7/12/10): 20,000 Louisville, Kentucky residents received notification that a security mistake online resulted in the exposure of their Social Security numbers and financial information.  It is unclear whether these residents are included in the original 470,000 customers.  Only customers who were self insured were affected. WellPoint is claiming that this and other recent breaches were committed by an attorney or attorneys attempting to gain information for a lawsuit against WellPoint.

 
Information Source:
Dataloss DB
records from this breach used in our total: 470,000

June 23, 2010 Florida International University
Miami, Florida
EDU DISC

19,495

Florida International University is in the process of sending notification letters to 19 407 students and 88 faculty members after the university’s IT Security Office discovered personal data may have been exposed over the internet via a database’s external search function. An announcement posted on the FIU website lists the personal data as GPAs, test scores, and Social Security numbers that were stored on the College of Education’s E-Folio software app. This database kept track of student data related to state mastery standards, grade tracking, assignments, and Social Security numbers for both students and faculty.

 
Information Source:
Dataloss DB
records from this breach used in our total: 19,495

June 22, 2010 Oregon National Guard
Portland, Oregon
GOV PORT

Over 3,500

A laptop belonging to an Oregon National Guard member was stolen and the military is contacting service members who might be affected by the theft. According to the Oregon National Guard, the laptop was stolen from a vehicle. The Guard member had been using the laptop to conduct work from home. Although this laptop is password protected, there is still potential for exposure of individual personal information.

 

UPDATE (7/1/10): The 3,500 National Guard members who were affected have been notified.

 
Information Source:
Dataloss DB
records from this breach used in our total: 3,500

June 21, 2010 TeleTech, Sony Electronics
Englewood, Colorado
BSR UNKN

Unknown

Customers who placed orders through Sony Style Telesales Department between May 23rd and June 3rd 2010 may have had their credit card information illegitimately copied and sent to parties outside of the TeleTech network. TeleTech is a third party service provider of Sony.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

June 20, 2010 Mercy Willard Hospital
Willard, Ohio
MED INSD

Unknown

A former employee kept patient photographs, videos, memos, schedules, and forms. Some of the documents included patient Social Security numbers and other personal information. The employee is also being accused of voyeurism and possession of child pornography; though this is unrelated to these findings.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

June 18, 2010 St. Francis Federal Credit Union
Tulsa, Oklahoma
BSF PORT

8,400

Saint Francis Federal Credit Union has notified 8,400 customers that a backup tape containing customer information was lost.  SFFCU believes the tape was accidentally destroyed and that no member information has been misused as a result of the loss.

 
Information Source:
Databreaches.net
records from this breach used in our total: 8,400

June 18, 2010 University of Nevada
Reno, Nevada
EDU STAT

7,526 patients

Some patient information from the University Health System may have been accessed after the theft of computer equipment at the Reno office on June 11th. Patient names, Social Security numbers, patient account numbers, medical information, birth dates and addresses may have been viewed.

 
Information Source:
Databreaches.net
records from this breach used in our total: 7,526

June 18, 2010 Family Care Center
Clinton, Washington
MED PORT

8,000 (0 SSNs reported)

Operations in Clinton, Freeland, and Oak Harbor

A thief or thieves entered the physical therapy office on June 12th.  Cash, other items, and a laptop containing encrypted patient information such as names and account numbers were stolen.  It appears that a door was left unlocked.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

June 18, 2010 Ebony Medical Equipment and Supplies, Inc.
Tyler, Texas
MED INSD

Unknown

The owner used patient medical information to fraudulently obtain over $70,000 from Medicare and Medicaid.  The owner is also charged with buying patient information.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

June 17, 2010 Ocean Lakes High School
Virgina Beach, Virginia
EDU HACK

Over 11,388 students - calculated from the Virginia Beach City County Public Schools page of publicschoolreview.com

Schools that may have been accessed: Advanced Technology Center, Corporate Landing Middle School, Creeds Elementary School, Fairfield Elementary School, Indian Lakes Elementary School, Kellam High School, Kingston Elementary School, Landstown Middle School, Linkhorn Park Elementary School, Lynnhaven Middle School, New Castle Elementary School, Ocean Lakes Elementary School, Ocean Lakes High School, Red Mill Elementary School, Renaissance Academy, Rosemont Elementary School, Salem Elementary School, Technical & Career Education Center, Thalia Elementary School, Three Oaks Elementary School, Windsor Oaks Elementary School

Because of an incorrect security setting, an Ocean Lakes High School student was able to access a temporary file on a server that contained the names, addresses and Social Security numbers of students at 22 schools. The breach was discovered when the student tried to print some of the information in the school library. In addition to names, addresses and Social Security numbers, the student files also contain parent names, phone numbers, class schedules, birth dates and student ID numbers.

 
Information Source:
Dataloss DB
records from this breach used in our total: 11,388

June 17, 2010 Quantum Corporation
Bellevue, Washington
BSR PORT

At least 4

Laptops were stolen on June 13th. One of the laptops was password protected and contained sensitive employee information such as Social Security numbers, addresses, and names.

 
Information Source:
Databreaches.net
records from this breach used in our total: 4

June 16, 2010 AT&T
Dallas, Texas
BSR DISC

Unknown

AT&T customers who were using their own usernames and passwords to log into their accounts reported being sent to the accounts of other AT&T customers.  The account information did not include Social Security numbers or credit card informaiton.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

June 14, 2010 Frankling County Treasurer's Office
Columbus, Ohio
GOV DISC

0

Although it has a newer and better protected website for paying property taxes, the Franklin County Treasurer's Office continues to allow taxpayers to use an older URL which was recently discovered to be vulnerable to hackers.  This may expose taxpayer credit card and checking account numbers. 

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

June 13, 2010 Butler County Department of Job and Family Services
Middle, Ohio
GOV PHYS

10,600

The Agency learned in 2008 that confidential records were being left in public dumpsters without being shredded.  Documents from Medicaid, Food Stamps, Ohio Works First, and child care programs included information such as Social Security number, name, address, phone number and pay stub.  The agency failed to notify those who were affected.

 
Information Source:
Databreaches.net
records from this breach used in our total: 10,600

June 12, 2010 J.P. Morgan Chase
Hackettstown, New Jersey
BSF INSD

12

A Chase bank teller sold twelve customer account profiles to outside parties between 2008 and 2009. These customer accounts were then fraudulently charged over $60,000. The former employee and the outside parties were all caught.

 
Information Source:
Databreaches.net
records from this breach used in our total: 12

June 12, 2010 Middle Township Municipal Hall
Middle Township, New Jersey
GOV PHYS

Unknown

Personal information from Municipal Hall was found in a public dumpster. The information was not shredded and included police reports, Social Security numbers, home addresses, telephone numbers, names, and tax records. The improper disposal of information continued after the first dumpster discovery.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

June 11, 2010 Payless Shoe Store
Bellmore, New York
BSR INSD

11

An employee used a skimming device to obtain customer credit card information. He made fraudulent purchases totaling nearly $11,000 and was charged with grand larceny, possession of a forged device, and identity theft.

 
Information Source:
Databreaches.net
records from this breach used in our total: 11

June 10, 2010 Durham County Government
Durham, North Carolina
GOV PHYS

8,700 employees

A group of people obtained a list of Durham employees which included Social Security numbers, birth dates, and employment information.  They then used their personal information to commit credit card fraud and identity theft.  Police report that more than 200 employees were victims.

 
Information Source:
Databreaches.net
records from this breach used in our total: 8,700

June 10, 2010 City of Springfield
Springfield, Illinois
GOV DISC

Unknown

The city of Springfield put documents online that contained sensitive information such as Social Security numbers, driver’s license numbers, home and work telephone numbers, bank account numbers and the name of someone who called the state anonymously to report suspected child abuse. The documents were posted on the city’s website in response to Freedom of Information Act requests as part of an initiative to make public information available to anyone with a computer. But personal information such as home phone numbers, Social Security numbers and driver’s license numbers are exempt from disclosure under state law.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

June 9, 2010 Apple Inc.
Cupertino, California
BSR HACK

Unknown

A security breach has exposed iPad owners including dozens of CEOs, military officials, and top politicians. They—and every other buyer of the cellular-enabled tablet—could be vulnerable to spam marketing and malicious hacking. The breach exposed the most exclusive email list on the planet, a collection of early-adopter iPad 3G subscribers that includes thousands of A-listers in finance, politics and media, from New York Times Co. CEO Janet Robinson to Diane Sawyer of ABC News to film mogul Harvey Weinstein to Mayor Michael Bloomberg. It even appears that White House Chief of Staff Rahm Emanuel's information was compromised. It doesn't stop there. According to the data we were given by the web security group that exploited vulnerabilities on the AT&T network, we believe 114,000 user accounts have been compromised, although it's possible that confidential information about every iPad 3G owner in the U.S. has been exposed.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

June 9, 2010 TennCare, New Mexico Human Services Department
Chicago, Illinois
MED PORT

76,000 9,600 from New Mexico; over 10,000 from Tennessee

This theft affects people in Tennessee and New Mexico.

An employee from a subcontractor company called West Monroe Partners was robbed of a laptop containing information for a Medicaid billing company named DentaQuest. DentaQuest was responsible for dental benefits of the New Mexico Human Services Department and TennCare. Around 21,000 people had their full names and Social Security numbers on the stolen laptop. Approximately 55,000 others had some form of personal information on the laptop.

 
Information Source:
Databreaches.net
records from this breach used in our total: 21,000

June 9, 2010 Office of Dr. David Brown
St. John, Missouri
MED DISC

Unknown

Patient files were found outside the office of Dr. David Brown. Dr. Brown admitted to failing to shred the old papers and claimed that he ran out of space for the files.

 
Information Source:
NAID
records from this breach used in our total: 0

June 8, 2010 Bank of America
Sun City, Florida
BSF INSD

Uknown

An employee in one of Bank of America's customer call centers has admitted he stole sensitive account information and tried to sell it for cash. The man met with two individuals whom he later learned were undercover FBI agents and offered to sell them names, dates of birth, telephonic passwords, and other details for Bank of America customers, according to court records. He was looking for accomplices who knew how to milk the accounts by establishing phony credit cards in the customers' names or through other means.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

June 8, 2010 Tri-City Medical Center
Oceanside, California
MED INSD

Unknown

Employees shared patient information on Facebook. Differing reports leave it unclear if these employees were nurses, and whether or not they were fired.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

June 8, 2010 Los Angeles County Department of Public Social Services
Los Angeles, California
GOV INSD

155

A dishonest employee used welfare beneficiary information to file for two million dollars worth of tax refunds. The employee was caught and charged with 11 counts of identity theft and 11 counts of making false claims to the United States.

 
Information Source:
Databreaches.net
records from this breach used in our total: 155

June 7, 2010 Wal-Mart, Sam's Club
Bentonville, Arkansas
BSR HACK

117

Sam's Club and Wal-Mart stores in Connecticut, New Jersey, Massachusetts, Rhode Island, New Hampshire, New York, Pennsylvania, Maryland, Delaware, and Puerto Rico

During a credit card fraud scheme, a man obtained and misused customer information.  His scheme involved using customer information to impersonate customers and open new lines of store credit in their names.  Total loses amounted to $781,571.80.

 
Information Source:
Databreaches.net
records from this breach used in our total: 117

June 7, 2010 New York City Department of Education
New York City, New York
EDU HACK

Unknown

The New York City’s Special Commissioner Office revealed a hacker stole more than $640,000 from the Department of Education’s petty cash account at JP Morgan Chase and distributed the codes to others to use to pay for student loans, gas bills and other purchases. The hacker allowed individuals to pay personal bills through EFTs and, in turn, he was given cash. The scam was discovered when an unidentified woman informed Chase someone was trying to pay bills using the account.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

June 7, 2010 Nursing Visioned Medical Services
Nashville, Tennessee
MED PHYS

At least 2,000

Thousands of patient records, surgery information, Social Security numbers and bank information were found dumped behind Nashville Center Point Church of the Nazarene. The documents came from the now defunct and bankrupt Nursing Visioned Medical Services group. Maryland-based Impulse Monitoring, Inc. bought the assets to NVMS last year when they filed bankruptcy. They said they are not responsible for the patient information because the services NVMS provided were one-time services. The old owners had shredded a bunch of old documents and the more recent ones had been passed on to the company (Impulse) that bought NVMS back in January. It is unclear where the documents came from.

 
Information Source:
Dataloss DB
records from this breach used in our total: 2,000

June 6, 2010 Offices of Doctors J. and M. Vyas
Chino Hills, California
MED PHYS

600 patient files (0 reports of SSNs or financial information)

Confidential medical files were found in a dumpster near the medical office of the two doctors. The doctors were in the process of moving to a new location.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

June 5, 2010 National Highway Traffic Safety Administration (NHTSA)
Washington, District Of Columbia
GOV DISC

Unknown

A limited search of NHTSA's public complaint database uncovered Social Security numbers, names, birth dates, addresses, VINs, and drivers' license numbers. Public access to the database of 792,000 complaint cases was temporarily ended.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

June 5, 2010 Marco's Restaurant
Indianapolis, Indiana
BSR HACK

500

The encrypted Internet connection of a restaurant was breached by hackers outside of the organization. Customer credit and debit card information was lost and fraudulently used.

 
Information Source:
Databreaches.net
records from this breach used in our total: 500

June 4, 2010 Digital River Inc.
Eden Prairie, Minnesota
BSF HACK

200,000

A massive data theft from the e-commerce company Digital River Inc. has led investigators to hackers in India and a 19-year-old in New York who allegedly tried to sell the information to a Colorado marketing firm for half a million dollars. The Eden Prairie company obtained a secret court order last month to block Eric Porat of Brooklyn from selling, destroying, altering or distributing purloined data on nearly 200,000 individuals. Digital River suspects that the information was stolen by hackers in New Delhi, India, possibly with help from a contractor working for Digital River.

 
Information Source:
Dataloss DB
records from this breach used in our total: 200,000

June 3, 2010 Penn State
University Park, Pennsylvania
EDU DISC

15,806, 25,000 more later discovered

The Pennsylvania State University sent data breach notification letters to 15 806 individuals who at one time had their personal information, including Social Security numbers, stored in a university database. Penn State issued a press release statement on Wednesday informing the university community that a computer in its Outreach Market Research and Data office was found to be actively communicating with a botnet CNC. According to the statement, the database used by the office had previously contained Social Security numbers on individuals. The university, which discontinued use of SSNs for identification purposes in 2005, nevertheless found that an archived copy of the information went undetected in the computer’s cache.

UPDATE (6/8/2010): An additional 25,000 individuals may have been affected.

 
Information Source:
Dataloss DB
records from this breach used in our total: 40,806

June 3, 2010 Safe Harbor Med
Santa Cruz, California
MED PORT

Unknown

Burglars stole client records, a suitcase and two bags of cookies from a medicinal marijuana referral office. Burglars also stole a computer hard drive that contained a client database, including Social Security numbers, ID numbers and other sensitive information. The burglars apparently cut power to the building — so the alarm didn't go off — and shattered a window to get into the office.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

June 2, 2010 Avalon Center
Cheektowaga, New York
MED DISC

Unknown

Sensitive medical information was dumped outside of a DMV office. The medical information came from a eating disorder clinic that had recently closed. Patient information such as medical treatment and Social Security number was exposed. It is unknown how the information ended up in the dumpster.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

June 2, 2010 Rainbow Hospice and Palliative Care
Park Ridge, Illinois
MED PORT

Unknown

http://www.rainbowhospice.org/protection/

According to their website: "On April 12, 2010, one of our laptop computers, which contained personal information, was stolen during a patient visit.  The laptop had security measures in place, but there is a very small chance that protected information such as name, address, date of birth, Social Security number, insurance information, medications, treatment, and diagnoses may have been inappropriately accessed."

 

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

June 2, 2010 Roanoke City Public Schools
Roanoke, Virginia
EDU PORT

2000

Personal information of more than 2,000 Roanoke City Public Schools employees may be at risk. School officials said the hard drives of eight computers were not removed before the units were sold as surplus. "We believe that we have recovered all of the hard drives," said Superintendent Rita Bishop. The drives contained the names, school locations and Social Security numbers of the division's employees as of November 2006. The division will be setting up a hotline for employees to call with questions and concerns. Free credit monitoring service will be offered to affected employees.

 
Information Source:
Dataloss DB
records from this breach used in our total: 2,000

June 2, 2010 University of Louisville
Louisville, Kentucky
EDU DISC

709

A University of Louisville database of 708 names that included Social Security numbers and dialysis details was available on the Internet without password protection for nearly a year and a half. The Web site was disabled on May 17 when the university discovered the flaw. University officials said in a statement that accessing the database would not have been easy, and no direct links to the database were discovered. The information was available so long because the U of L doctor who set up the Web site thought the information was protected by a password and other precautions. U of L was finally notified when someone outside the university sent an e-mail about open access to the information. The Web site was shut down an hour later.

 
Information Source:
Dataloss DB
records from this breach used in our total: 709

June 1, 2010 Brew HaHa!
Wilmington, Delaware
BSR HACK

Over 30

Outdated and improperly managed software caused customer debit and credit cards to be exposed to fraudulent charges.  Between 20 and 30 customers of one bank had fraudulent charges from overseas added to their statements.  It is not known how many other customers were affected.

 
Information Source:
Databreaches.net
records from this breach used in our total: 30

May 28, 2010 Aetna
South Windsor, Connecticut
BSO PHYS

Around 5,000 from New Jersey and Pennsylvania (no specific numbers of SSNs or financial documents reported)

A cabinet full of documents with sensitive information was found sitting on the side of the road. A woman made the discovery about a month ago and gave the documents to investigators with Aetna Insurance Co. The woman said she saw a bureau on the side of the road in front of Admiral Storage in South Windsor with a sign that said "free." She brought it home and discovered the documents. There were eight bags of nothing but Social Security numbers, names, and death benefits. Information also included patient records and medications. Aetna responded by saying, "Aetna is committed to protecting the privacy of our members and we take this situation seriously. We have policies for properly safeguarding our members’ information, and we are investigating how this incident occurred, but it appears to be human error. The woman contacted us via e-mail on the evening of May 5, and we immediately responded the next morning. She has consistently declined to give us her name or phone number, or to make arrangements to allow us to retrieve the documents at a place convenient for her, or to return them to us. As of today, we now have the files, and will go through each of them to determine the contents and whether any member information has been breached. If it has been, we will notify those members and take steps to mitigate any potential harm." The woman attempted to arrange the hand-off, however, a short time after she got off the phone with the company, three men from Aetna showed up at her workplace, unannounced, and asked for the documents immediately. The woman said, "But when they sent the three guys to my work yesterday, it was an intimidation tactic and I didn't appreciate it. So that told me what I was going to do. That they were going to try and hide it." Aetna said someone from the company made a "serious human error," and it will now go through the files to make sure no sensitive information was lost. What's more troubling, the woman said, is that the bureau wasn't the only piece of furniture offered for free that day. "Out of the pieces that were up for grabs, whose to say that I've got the only piece that was full of Aetna papers." The woman has also contacted the state to investigate the situation. Aetna has clients across the country.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

May 28, 2010 Cincinnati Children's Hospital Medical Center
Cincinnati, Ohio
MED PORT

61,000 (0 SSNs and financial information reported)

A laptop containing the names, medical record numbers, and medical services provided of patients was stolen from an employee's car while it was parked at his or her home. As a precaution, no additional laptops will be allowed outside the hospital unless they are encrypted.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

May 28, 2010 Interior National Business Center
Denver, Colorado
GOV PORT

7,500 (0 SSNs reported)

A disc containing employee information was lost or stolen.  The Interior Department reported that it was encrypted and password-protected personally identifiable federal employee information.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

May 26, 2010 Inovis
Alpharetta, Georgia
BSO PORT

Unknown

On May 4th a laptop containing employee information was stolen from an employee of GXS who was helping with their merger. A letter notified an unknown number of Inovis employees that their addresses, Social Security numbers, names and salary information were on the laptop.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

May 26, 2010 Children's Hospital and Research Center at Oakland
Oakland, California
MED PHYS

1000 (0 SSNs reported)

http://www.childrenshospitaloakland.org/EnhancedPatientPrivacyProtection...

Approximately 1,000 patients were mailed information about themselves and other patients. According to the Hospital's website "equipment designed to generate, fold and stuff documents for mailing was programmed to fold and stuff two pages rather than one. This programming error caused guarantor billing statements prepared on May 25 and May 26 to be collated and mailed incorrectly."

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

May 25, 2010 Loma Linda University Medical Center
Loma Linda, California
MED PHYS

500

(877) 558-6208

A thief has stolen personal information regarding more than 500 surgical patients of Loma Linda University Medical Center, according to hospital officials. A desktop computer containing the information disappeared April 5 from the department of surgery's administrative office on Campus Street. The missing information includes each patient's name, medical record number, diagnosis, surgery date, and the type of procedure.

 
Information Source:
Dataloss DB
records from this breach used in our total: 500

May 25, 2010 AT&T/Ferrell Communication
Jacksonville, Florida
BSO DISC

Unknown

A woman got quite a surprise when she looked in her recycle bin. Someone had dumped hundreds of files of people's personal information. The manila folders that were found contained personal information of AT&T cell phone customers, including credit card numbers, driver's licenses and Social Security numbers. It appears the information was collected by another company called Ferrell Communication, which was located in a strip mall. It's no longer there, and the phone number listed isn't valid. The information is contracts for AT&T wireless service customers dating back to 1999 or 2000. The information is old, but could still be valid.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

May 25, 2010 City of Charlotte
Charlotte, North Carolina
GOV PHYS

5,220

(888) 435-6031

The city of Charlotte says the personal information of 5,220 current and former city employees and elected officials has been lost. The loss affects individuals who received health insurance from the city in early 2002. Two DVDs containing the Social Security numbers of the affected individuals failed to arrive at the offices of Towers Watson & Co., the city’s benefits consulting firm, in Atlanta. The discs also contained prescription-drug information for five individuals.

 
Information Source:
Dataloss DB
records from this breach used in our total: 5,220

May 25, 2010 Local Coffee
San Antonio, Texas
BSR HACK

Unknown

Hackers may have gained access to credit and debit card information by exploiting Aloha software weaknesses. After a purchase at Local Coffee, a customer's debit card was canceled. This prompted Local Coffee to temporarily stop using Aloha.  Another San Antonio eating establishment, Aldaco, also encountered hacking problems while using Aloha software.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

May 25, 2010 Lincoln Financial Group
Radnor, Pennsylvania
BSF DISC

1,286 (0 SSNs reported)

In 2002, 2008, and 2010 records of correspondence between agents and clients were misplaced. Technical errors caused the names, addresses, policies or contract numbers, account values, trade and transaction activities, and dates of birth of the clients to be accessible.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

May 25, 2010 Wells Fargo
San Francisco, California
BSF INSD

1,023

A former stock broker left the firm with the personal information of 1,023 clients. Names, addresses, Social Security numbers and brokerage account numbers were taken.

 
Information Source:
Databreaches.net
records from this breach used in our total: 1,023

May 25, 2010 Wells Fargo
San Francisco, California
BSF INSD

At least 5

A former Wells Fargo employee inappropriately held the personal information of clients. Law enforcement found documents containing names, dates of birth, Social Security numbers and mortgage loan account numbers when acting on a search warrant for the home of a former Wells Fargo team member.

 
Information Source:
Databreaches.net
records from this breach used in our total: 5

May 24, 2010 Cheesecake Factory
Washington, District Of Columbia
BSR INSD

Unknown

Three servers from the Cheesecake Factory at 5345 Wisconsin Avenue were charged with using skimming devices to make over $117,000 in fraudulent charges to customer credit card accounts.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

May 24, 2010 Lake Ridge Middle School
Woodbridge, Virginia
EDU PORT

Over 1,200 (0 SSNs reported)

A USB drive containing student names, identification numbers, phone numbers, and medical information was stolen from the unlocked car of a school administrator at the employee's home.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

May 22, 2010 Staff Jennings Boats
Portland, Oregon
BSR DISC

Unknown, at least two cases of SSN

Sales documents dating back 20 years were found in a dumpster. The personal financial information of customers included Social Security numbers and information on purchases. Staff Jennings went out of business in April of 2010.

 
Information Source:
Databreaches.net
records from this breach used in our total: 2

May 21, 2010 Aldaco's Mexican Cuisine
San Antonio, Texas
BSR HACK

Unknown

Aldaco's Mexican Cuisine at Stone Oak had a data security breach.  Customers were notified of fraudulent charges; some were from places outside of the U.S. Aldaco urged customers who had used their credit cards at the restaurant to cancel them.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

May 21, 2010 Tufts University
Medford, Massachusetts
EDU HACK

"Thousands" of alumni records, at least 2,000

Campus computers with former student files were exposed to a virus.  Alumni may have had their Social Security numbers and other information exposed.

 
Information Source:
Databreaches.net
records from this breach used in our total: 2,000

May 20, 2010 Rockbridge Area Community Services
Lexington, Virginia
MED STAT

500

On March 3rd, at least one computer and one laptop containing personal information were stolen. Information such as names and Social Security numbers may have been compromised.

 
Information Source:
Databreaches.net
records from this breach used in our total: 500

May 20, 2010 Strong Memorial Hospital
Rochester, New York
MED DISC

Around 1250 (0 SSNs and credit cards involved)

Around half of all patient medical bills were sent to the wrong address. The billing statements included patient names, name and address of the person responsible for paying the bill, description of services received and the dates of services, dollar amount owed, health insurance plan and subscriber number.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

May 18, 2010 The Vine Tavern and Eatery
Tempe, Arizona
BSR PHYS

Unknown, "thousands of pages of sensitive information"

Personal documents including applicant names, Social Security numbers, and dates of birth were found in a dumpster. Customer checks with banking information and credit card receipts were also found.

 
Information Source:
NAID
records from this breach used in our total: 0

May 18, 2010 Capitol One
McLean, Virginia
BSF UNKN

Unknown

A fraud ring may have accessed customer information. The information included names, addresses, Social Security numbers, and other personal information. It is not known how the information was obtained or how many customers were affected. The information may have been accessed sometime between December of 2009 and February of 2010.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

May 17, 2010 Edward Waters College
Jacksonville, Florida
EDU DISC

At least 210

Staff and prospective student names, Social Security numbers, driver's license numbers, and addresses were accessible to the public through a Google or Yahoo! search.  The cause was a  mistake in setting up software.

 
Information Source:
Databreaches.net
records from this breach used in our total: 210

May 17, 2010 Silicon Valley Eyecare Optometry and Contact Lenses
Santa Clara, California
MED STAT

40,000

A computer and a plasma TV were stolen from the office on Friday April 2nd, 2010. The computer server contained patient names, addresses, phone numbers, email addresses, birth dates, family member names, medical insurance information, medical records, and in some cases, Social Security numbers.  The data were password protected.

 
Information Source:
Databreaches.net
records from this breach used in our total: 40,000

May 15, 2010 Los Angeles Firemen's Credit Union
Los Angeles, California
BSF DISC

Unknown

An extremely small percentage” of member files were “not properly moved” when the CU relocated from an old location. The data that could have been compromised included members names, addresses, phone numbers, account numbers, Social Security numbers and other identifiers. The CU sought to reassure members that it did not believe any of their information had been compromised and that the CU had “state of the art protocols” available to validate member identifies. The CU also arranged for CU members who chose to do so to be able to enroll in a credit monitoring service for the next two years at no cost to them.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

May 15, 2010 Mellow Mushroom
Warner Robins, Georgia
BSR HACK

2,000

Customers of the Mellow Mushroom eatery had their credit and debit card information hacked sometime around March 11th. Customers of other merchants have been affected, but a hack of Mellow Mushroom's processor is believed to be the source.

 
Information Source:
Databreaches.net
records from this breach used in our total: 2,000

May 14, 2010 Department of Veterans Affairs
Washington, District Of Columbia
GOV PORT

616

The Department of Veterans Affairs has suffered another possible breach of private data as a thief recently stole an unencrypted laptop that had held the Social Security numbers and other information of 616 veterans. Theft of the laptop was owned by a contractor and not the VA.

 
Information Source:
Dataloss DB
records from this breach used in our total: 616

May 14, 2010 Principal Financial Group
Des Moines, Iowa
BSF HACK

Unknown, at least two from New Hampshire

An unauthorized person using a valid employer password and user name accessed group contract number, member name, Social Security number, age and employment status of certain individuals with a connection to Principal Life Insurance.

 
Information Source:
Databreaches.net
records from this breach used in our total: 2

May 13, 2010 Army Reserve/Serco Inc.
Morrow, Georgia
GOV PORT

207,000

A laptop containing the names, address and Social Security numbers of more than 207,000 Army reservists has been stolen from a government contractor in Georgia. A CD-Rom containing the personal identifiable information was in one of three laptops stolen from the Morrow, Ga., offices of Serco Inc., a government contractor based in Reston, Va. The other laptops did not contain sensitive personal information. Serco had a contract with the U.S. Army's Family and Morale, Welfare and Recreation Division, so some of the pilfered information also could belong to reservists' family members.

 
Information Source:
Dataloss DB
records from this breach used in our total: 207,000

May 11, 2010 New Mexico Medicaid
Santa Fe, New Mexico
GOV PORT

9,500

(877) 453-8424

A employee of a subcontractor for the company that processes claims and provides dental benefits for the State’s Medicaid program, filed a stolen car report for a vehicle whose trunk contained an ”unencrypted” laptop loaded with patient information. The patient information in the laptop included name, health plan identification number, which in some cases is the individual’s Social Security number, and a provider identification number but not the name of the provider. The agency sent out a message today saying that it was in the process of notifying 9,500 New Mexicans who use its Medicaid Salud plan of a possible security breach.

 
Information Source:
Dataloss DB
records from this breach used in our total: 9,500

May 10, 2010 Monarch High School, Plantation High School
Coconut Creek, Florida
EDU INSD

6 from Plantation and Monarch, 7 victims total

A former teacher of Monarch High School received six months of house arrest for opening or attempting to open 17 credit cards in other people's names.

 
Information Source:
Databreaches.net
records from this breach used in our total: 7

May 7, 2010 FHG Finance
Pleasant Hill, California
BSF DISC

300

The financial and personal details of about 300 property loan applicants were compromised when confidential documents were mistakenly tossed into an outdoor waste bin. The documents, which contained bank account and Social Security numbers, were found by employees at a neighboring store, who alerted FHG. The company padlocked the trash bin until the documents could be shredded.

 
Information Source:
Dataloss DB
records from this breach used in our total: 300

May 7, 2010 Fast Cash
Knoxville, Tennessee
BSF PHYS

Unknown

Hundreds, maybe thousands, of documents with personal information were dumped behind a shopping center. The documents scattered around a dumpster behind the business listing Social Security numbers, names, addresses, bank account numbers and signatures.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

May 7, 2010 Bureau of Engraving and Printing
Washington, District Of Columbia
BSF HACK

Unknown

Hackers have caused the Bureau of Engraving and Printing (BEP), a part of the US Department of the Treasury, to shut down a number of websites. The BEP confirmed to IT PRO that the hosting company it uses experienced an intrusion and as a result of the breach numerous websites were affected, including non-BEP sites. Those URLs are: bep.gov; bep.treas.gov; moneyfactory.gov and moneyfactory.com. BEP has since suspended the website. The chief research officer at IT security company AVG, indicated that the BEP websites had a line of code injected into them. Upon accessing the US Treasury website (treas.gov, bep.gov, or moneyfactory.gov), the iframe silently redirects victims through statistic servers and exploit packs which will carry the victim onto the second stage of the attack. The exploit kit determined that Java was the “best method” for infecting his test machine. Once infected, users' web browsers will start directing them to ads and “other nasty things” like rogueware.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

May 4, 2010 Millennium Medical Management Resources
Westmont, Illinois
MED PORT

180,111

Health records belonging to patients were stolen in a break-in. The records were on a portable hard drive and stolen from the Westmont office of Millennium Medical Management Resources. Millenium believes the hard drive contained personally identifiable information about EHP patients including name, address, phone, date of birth, and Social Security number.  In some cases other information such as diagnosis, procedure (and/or codes), medical record number, account number, drivers license number and health insurance info. It was NOT encrypted.

 
Information Source:
Dataloss DB
records from this breach used in our total: 180,111

April 30, 2010 Our Lady of Peace
Louisville, Kentucky
MED PHYS

24,600

A flash drive containing personal information on 24,600 patients is missing from Our Lady of Peace psychiatric hospital. The drive contained the following information on patients admitted since 2002: patient names, room numbers, insurance company names and admission and discharge dates. It didn’t include diagnoses or treatments, Social Security numbers, dates of birth, telephone numbers or addresses for these patients. The drive also included the following information on patients assessed since 2009 but never admitted: name, date of assessment, date of birth and the time they left the hospital. For these patients, the information on the drive didn’t include diagnoses or treatments, Social Security numbers, telephone numbers, addresses or insurance information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 24,600

April 30, 2010 North Country Health Services
Bemidji, Minnesota
MED HACK

349

The online bill payment website was hacked. The credit card and debit card account information of customers who paid online was exposed.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 349

April 29, 2010 St. Jude Heritage Medical Group
Orange, California
MED PHYS

20,000

(800) 627-8106

20,000 patients may have had their personal information stolen after a break-in at the St. Jude Heritage Healthcare Clinical Management Services building in Fullerton. The thieves stole five computers. The stolen patient data included Social Security numbers, dates of birth and in some cases, health related information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 20,000

April 28, 2010 The Medical Center
Bowling Green, Kentucky
MED PORT

5,418

The Medical Center at Bowling Green is notifying 5,418 patients whose medical information may have been breached when a computer hard drive was stolen. The computer hard drive was taken from the hospital's mammography suite and contained information from patients who underwent bone density testing between 1997 and 2009.

 
Information Source:
Dataloss DB
records from this breach used in our total: 5,418

April 28, 2010 Montana Tech
Butte, Montana
EDU DISC

260

A Montana Tech employee mistakenly included the personal information of former students in an e-mail message sent to faculty, staff and students last week. The e-mail was an invitation to watch students present their research projects. But the file that this year's information was taken from included the names, addresses, Social Security numbers and in some cases birth dates of students whose research projects were done from 1998 through 2005.

 
Information Source:
Dataloss DB
records from this breach used in our total: 260

April 26, 2010 South Carolina Department of Health and Environmental Control
Columbia, South Carolina
GOV PHYS

At least 1,824 (0 SSNs and financial information reported)

Over 1,800 people's information was found in a dumpster. It is not known what kind of personal information was included in the documents.

 
Information Source:
NAID
records from this breach used in our total: 0

April 23, 2010 ESB Financial
Ellwood City, Pennsylvania
BSF DISC

3,097

ESB Financial officials announced that a data backup seven years ago had inadvertently been sent to an unauthorized storage source. Only checking and money-market account information was backed up to the incorrect outside data-storage company. A total of 3,097 customers could have been affected by the backup. Names, addresses, account numbers and, in some cases, Social Security numbers, would have been available to someone who found them on the Internet. However, the jumble of numbers would not have been easily recognizable and ESB was not identified as the source of the information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 3,097

April 23, 2010 Blippy.com
Palo Alto, California
BSO DISC

Unknown

Blippy is a social Web service that lets users share with the world all their credit card transactions. One big problem though: Blippy appears to have inadvertently published some of its users' credit card numbers. Google search resulted in viewing of some of the credit card numbers.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

April 23, 2010 Chattanooga State
Chattanooga, Tennessee
EDU PHYS

1,700

Nearly two thousand students records from Chattanooga State are missing. The company hired to scan the documents, mishandled them. The school took the records to a company, United Imaging in Walker County, where the papers would be converted to computer discs. The school was contacted by individuals who said there was something awry going on at this scanning site. That's when the school found their records in disarray, and brought them back. The papers included students' names, Social Security numbers, addresses, phone numbers, some even contained high school transcripts. Chattanooga State went through each item, hand by hand, and found nearly 2000 missing documents from 2007.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,700

April 23, 2010 DRC Physical Therapy Plus
Monticello, New York
MED PHYS

Unknown

Officials have seized hundreds, perhaps thousands, of files containing Social Security numbers and other private patient information found dumped outside the shuttered office of DRC Physical Therapy Plus. The manila folders, dating back to at least 1998, include information sheets showing the names, addresses and birth dates of patients and, in some cases, Social Security numbers. Deputies impounded a dump truck loaded with patient files and about a dozen or so boxes stacked inside the bucket of a front-loader.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

April 23, 2010 Hutcheson Medical Center
Chattanooga, Tennessee
MED PHYS

Unknown

Anyone who peered inside the mixed paper bin at the Dupont Recycling Center in May of 2009 got an eyeful. Files, in plain sight, which contained sensitive medical and identity information. Authorities don't know how those thousands of files got there. Some of the records came from Hutcheson and a plastic surgery office in the area. The information inside those files included graphic photos, and Social Security numbers.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

April 22, 2010 JE Systems Inc.
Fort Smith, Arkansas
BSF HACK

Unknown

The company in Arkansas lost more than $110,000 this month when hackers stole the firm’s online banking credentials and drained its payroll account. On Wednesday, Apr. 7, Ft. Smith based JE Systems Inc. received a call from its bank stating that the company needed to move more money into its payroll account. Over the course of two days, someone had approved two batches of payroll payments — one for $45,000 and another for $67,000. A few days later, the First National Bank of Fort Smith sent JE Systems a letter saying the bank would not be responsible for the loss. It was their internet address that was used to process the payments, and their online banking user name and password.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

April 21, 2010 Massachusetts Eye and Ear Infirmary
Boston, Massachusetts
MED PORT

3,526

On February 19, 2010, a laptop belonging to a physician affiliated with the Massachusetts Eye and Ear Infirmary was stolen while the physician was lecturing in South Korea. The laptop belonged to a neurologist with a particular focus on ringing in the ears, or tinnitus. The following types of information about affected individuals associated with Mass. Eye and Ear may have been present on laptop, Names, Addresses, Telephone numbers, E-mails, Date of birth and age, Sex, Medical record numbers, Dates of service, Medical information, including diagnoses, symptoms, test results, and prescriptions, Name and contact information for patient pharmacies, and Research participant status. In addition, four individuals’ information also included their pharmacy insurance account number.

 
Information Source:
Dataloss DB
records from this breach used in our total: 3,526

April 21, 2010 US Army Reserve
Fort Totten, New York
GOV PHYS

12,000

The Army is warning about 12,000 military and civilian personnel once associated with a reserve command based at Fort Totten that they should check their credit records, after discovering that it cannot locate files containing information that could make them vulnerable to identity theft. The records cover reservists from Long Island, New York City and upstate who were assigned to the 77th Regional Readiness Command and its subordinate units from 2001 until the unit was absorbed by the 99th Regional Support Command in 2008. The files were discovered missing when the new command asked for an accounting of the old unit’s records. They could have been burned, shredded or stolen.

 
Information Source:
Dataloss DB
records from this breach used in our total: 12,000

April 21, 2010 Affinity Health Plan
Bronx, New York
MED PORT

409,262

Affinity Health Plan, a New York managed care service, is notifying more than 400,000 current and former customers employees that their personal data might have been leaked through the loss of an unerased digital copier hard drive. Some personal records were found on the hard drive of a copier found in a New Jersey warehouse. The copier had previously been leased by Affinity and was then returned to the leasing company. Affinity Health Plan says it has not had a chance to review the data found on the copier. The figure of 409,262 notifications includes former and current employees, providers, applicants for jobs, members, and applicants for coverage.

 
Information Source:
Dataloss DB
records from this breach used in our total: 409,262

April 21, 2010 Brooke Army Medical Center
San Antonio, Texas
MED PORT

1,272

An Army three-ring binder that may have included detailed information on soldiers and families being treated at Brooke Army Medical Center was stolen on Oct. 16 from a car belonging to a case manager. Names, phone numbers and health information of 1,272 patients being treated at hospitals may have been breached by the car break-in.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,272

April 21, 2010 St. Mary and Elizabeth Hospital Women's Center
Louisville, Kentucky
MED STAT

77 patients (0 SSNs reported)

A hard drive was stolen from a locked area. Medical information such as biopsy images, patient names, and medical exams were on the stolen hard drive.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

April 18, 2010 Rapid Return Tax
San Antonio, Texas
BSF PHYS

Dozens

Dozens of legible tax documents were found among ashes in a dumpster outside of a tax return business.  Social Security numbers may have been on the documents.  This appears to be the result of a failure to burn all of the documents.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

April 16, 2010 Blue Cross and Blue Shield of Rhode Island (BCBSRI)
Providence, Rhode Island
MED PHYS

Approximately 12,000

A filing cabinet containing survey information from approximately 12,000 BlueCHIP for Medicare members was donated to a local nonprofit organization.  The surveys were from 2001 to early 2004 and contained information such as names, Social Security numbers, telephone numbers, addresses and Medicare Identification numbers.

 
Information Source:
Databreaches.net
records from this breach used in our total: 12,000

April 16, 2010 Higher Education Serives Corp.
Albany, New York
BSF DISC

1,433

A "process error" may have lead to Social Security numbers and last names going through Internet servers outside of HESC's control.  Those who may have been affected received letters and free credit monitoring services.

 
Information Source:
Databreaches.net
records from this breach used in our total: 1,433

April 14, 2010 Strategic Workforce Solutions, Tatum SFN division
New York, New York
BSO PORT

Unknown

The Tatum division of SFN (Strategic Workforce Solutions) notified employees that a portable electronic device was stolen from the trunk of a car.  The device contained unencrypted files with names, addresses and Social Security numbers.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

April 14, 2010 Lam Research Corp.
Fremont, California
BSO PORT

Unknown

A laptop containing the information of people regularly employed at Lam Research Corp. on or after January 1, 2009 was stolen from an employee's car.  Temporary employees and contractors from August 1, 2007 and beyond may have also been affected.  The information included names and Social Security number; however, it was protected by passwords and fingerprints checks.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

April 14, 2010 Bay Pines VA Medical Center
Bay Pines, Florida
GOV PHYS

Nearly 800 (unknown number of SSNs)

Up to 800 police files were left in an area where the general public could easily access them.  Some of the files contained Social Security numbers, patient addresses, and treatment information.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

April 13, 2010 Virginia Beach Dept. of Social Services
Virginia Beach, Virginia
GOV INSD

Unknown

At least eight human services employees, including supervisors, have been fired or disciplined in the past year for wrongfully accessing confidential and personal information about former employees, family members and clients. The violations include a boss who forced her employees to gather information from a state database about her husband's child and a worker who checked on the status of a dead client's Medicaid benefits to help the client's family. Most of the cases stemmed from the agency's financial assistance department, which handles food stamps, Medicaid assistance, grants for the disabled and emergency relief for needy families. As part of their jobs, the 330 employees in the department who provide social services have varying degrees of access to secured databases. They need the information to determine whether a client qualifies for financial help.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

April 13, 2010 St. Peter's Hospital
Albany, New York
MED INSD

Unknown

An East Greenbush man who worked as a medical records clerk at St. Peter's Hospital is accused of stealing personal information from patient's files to open credit card accounts. The man allegedly stole Social Security numbers and other personal information from patient's records, then used the data to open credit card accounts for making personal purchases online. The man was charged April 12 with five counts of felony second-degree forgery, three counts of felony second-degree identity theft and three counts of misdemeanor second-degree criminal impersonation.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

April 13, 2010 Lorillard Tobacco, General Agencies Welfare Benefits Program, National Gypsum, Towers Watson
Greensboro, North Carolina
BSR PORT

At least 1,874

Two unencrypted DVDs containing employee information were lost in transit by a benefits consulting firm. Multiple organizations were involved.  Benefits consulting firm Towers Watson notified Lorillard and the General Council on Finance and Administration, which administers the General Agencies Welfare Benefits Program, of the loss in February.  The DVDs contained names, addresses, dates of birth, and Social Security numbers of current and former employees and their family members.

UPDATE (6/22/2010): National Gypsum notified the New Hampshire Attorney General Office of the possible exposure of employee data related to this incident in June.

 
Information Source:
Databreaches.net
records from this breach used in our total: 1,874

April 13, 2010 Room Store
Annapolis, Maryland
BSR PHYS

Unknown

A Maryland man found his own credit application lying on the ground near a dumpster.  The dumpster contained thousands of old credit applications and some newer ones.  The information included Social Security numbers, driver's licence numbers, names, addresses, and phone numbers.  Room Store employees were doing a massive cleanup and unknowingly dumped the bag of documents without shredding them.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

April 13, 2010 Atlanta Firefighters
Atlanta, Georgia
GOV DISC

1000

While attending a seminar on security, Atlanta police officers were astonished to discover that personal information from city firefighters was being used as an example of what could be found on the Internet. The information included Social Security numbers, names and addresses. It is believed that the information was hacked and/or uploaded to a file sharing website from a city employee's off-site laptop.

 
Information Source:
Databreaches.net
records from this breach used in our total: 1,000

April 12, 2010 Kern County Employee's Retirment Asociation
Bakersfield, California
GOV INSD

37,000

A former employee was convicted of using the Social Security number of a member to create a false identity. The county employee opened a line of credit and had committed felonies before being hired at KCERA in a position with access to retirees' personal information.

 
Information Source:
Databreaches.net
records from this breach used in our total: 37,000

April 9, 2010 Hollywood Video
Sparks, Nevada
BSR PHYS

Unknown

This Hollywood Video like many others has closed. Hundreds, perhaps thousands of pieces of paper, receipts, records and worst of all membership forms, were exposed.  It appears they were not even placed in the dumpster, but left out in the open and scattered everywhere by the wind. On these forms were names, addresses, birth dates, I-D numbers, credit card numbers and signatures.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

April 9, 2010 Mad Capper Saloon & Eatery
Stillwater, Minnesota
BSR HACK

200

Police have received about 80 complaints of victims' whose credit cards have been compromised. The police have connected the scam to cards used at the Mad Capper Saloon & Eatery. The owner of the Mad Capper Saloon & Eatery has been cooperating with police, he is frustrated that somehow his 30-year-old business is linked to identity theft. The restaurant's owner, has taken steps to make sure his customers are protected. "We've looked into our credit card processing. We've looked into our software program -- our routers in the building, We've scanned everything -- combed it with a fine tooth comb and we can't find anything off of it, so its frustrating."

UPDATE (4/10/10): The number of people affected is now nearing 200.

 
Information Source:
Dataloss DB
records from this breach used in our total: 200

April 9, 2010 Charles Schwab
Albany, New York
BSF HACK

Unknown

A Russian national was sentenced to 37 months in prison for hacking into victims' brokerage accounts at Charles Schwab, laundering more than $246,000 and sending a portion back to co-conspirators in Russia. The man also sold approximately 180 stolen credit card numbers to a cooperating witness and directed that they be fabricated into credit cards. According to the indictment, from approximately September 2006 through December 2007 two men participated in a scheme to steal funds from bank and brokerage accounts by hacking into those accounts through the Internet, using personal financial information obtained through a Trojan computer viruses and then laundering the stolen proceeds.  
Information Source:
Dataloss DB
records from this breach used in our total: 0

April 9, 2010 Woodbury Financial Services
Woodbury, Minnesota
BSF PORT

At least three

A USB containing client names, Social Security numbers, addresses, and dates of birth went missing. The data was unencrypted.  Woodbury is a broker with The Hartford.

 
Information Source:
Databreaches.net
records from this breach used in our total: 3

April 8, 2010 St. Francis Hospital
Tulsa, Oklahoma
MED INSD

60

A Sand Springs woman has been indicted on allegations that she used personal identifying information she copied from her then-employer's computer system as part of a scheme involving fraudulent credit cards and stolen mail. The indictment, released Wednesday in federal court in Tulsa, a 45 year old woman, exceeded her computer-access authority at St. Francis Hospital to obtain information such as Social Security numbers and dates of birth of at least 60 people.

 
Information Source:
Dataloss DB
records from this breach used in our total: 60

April 8, 2010 H&R Block
Bronx, New York
BSF INSD

At least 20

Police are investigating whether former H&R Block employees received fraudulent tax refunds by using customer information. At least customers 20 have come forward, but there could be many more customers who were affected.

 
Information Source:
Databreaches.net
records from this breach used in our total: 20

April 8, 2010 HBDirect.com
Waterbury Center, Vermont
BSO HACK

Unknown

A security breach resulted in the possibility that hackers accessed customer names, addresses, credit card information, email addresses and phone numbers. Customers who used the site between December 1, 2009 and February 10th, 2010 may have been affected.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

April 8, 2010 ManorCare Health Services
Wheaton, Maryland
MED INSD

Unknown

Montgomery County's Department of Health and Human Services is looking into how numerous Wheaton nursing home papers containing sensitive patient information have made their way into nearby neighbors' yards over the past few months. The county sent a nursing home inspector to investigate complaints from residents in the Wheaton Regional Park Civic Association who said they have found internal documents from the nearby ManorCare Health Services that contain patient conditions, names and Social Security numbers. The inspector cited ManorCare for inappropriate conduct.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

April 7, 2010 Bank of America
Charlotte, North Carolina
BSF INSD

Unknown

An IT staff member of Bank of America plead guilty to installing illegal software on Bank of America ATMs. The software caused the ATMs to erroneously dispense money; some of it may have affected customer accounts.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

April 6, 2010 Amarillo Tex's Steakhouse
Alton, Illinois
BSO CARD

At least four

An employee made a deal with an outside party to allow a skimmer device to collect customer credit card information. Four people reported identity theft to the police, but it is unknown how many were affected.

 
Information Source:
Databreaches.net
records from this breach used in our total: 4

April 6, 2010 Pediatric Sports and Spine Associates
Brentwood, Tennessee
MED PORT

955

A laptop was stolen from an employee on February 10. The theft occurred off-site.  The laptop contained names, addresses, phone numbers, dates of birth, medical information and Social Security numbers.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 955

April 6, 2010 Providence Hospital
Southfield, Minnesota
MED PORT

12

The hospital has sent letters alerting patients that a hard drive used for backing up data has been "lost or stolen from a locked office suite. The hospital explained that the data included patient names, medical record numbers and/or clinical information, addresses and phone numbers of some employees, and what the hospital called proprietary businesses information. The hospital would not comment on how many patients may be affected, but said only 12 patients' Social Security numbers were on the hard drive.

 
Information Source:
Dataloss DB
records from this breach used in our total: 12

April 5, 2010 John Muir Physician Network
Walnut Creek, California
MED PORT

5,450

John Muir Health, the Walnut Creek-based hospital system, has begun notifying 5,450 patients by mail of a potential breach of their personal and health information. Two months ago two laptop computers at the John Muir Physician Network Perinatal office in Walnut Creek were stolen. The laptops were password protected and contained data in a format that would not be readily accessible. External vendors and internal experts discovered that the missing laptops contained personal and health information going back more than three years.

 
Information Source:
Dataloss DB
records from this breach used in our total: 5,450

April 3, 2010 Middletown City Public Works and Utilities
Middletown, Ohio
GOV PHYS

Unknown

A mound of city documents containing Social Security numbers, phone numbers and carbon copies of checks filled a Dumpster at Smith Park, where they were accessible to anyone. Countless junked records containing personal information for Middletown residents, along with blueprints, contracts and tax papers were found. Most appear to have originated in the city’s public works and utilities department, with a few from the police and finance departments. Somebody made a mistake and threw something away that should have been shredded.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

April 3, 2010 Middletown City Government Building: Public Works, Utilities, Police, and Finance Departments
Middletown, Ohio
GOV PHYS

Unknown

Personal documents that originated from the city building were left in a dumpster. The documents contained Social Security numbers, phone numbers, and carbon copies of checks.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

April 2, 2010 Naval Facilities Engineering Service Center
Port Hueneme, California
GOV PHYS

244

More than 200 employees were notified that a non-government entity may have seen their personal information. The non-government entity were lawyers for two of three workers who fought a security access suspension against them. It take the Navy 17 months to inform employees at the Naval Facilities Engineering Service Center in Port Hueneme, Calif., that their Social Security numbers had been inadvertently released.

 
Information Source:
Dataloss DB
records from this breach used in our total: 244

March 30, 2010 Three Rivers Community College
Norwich, Connecticut
EDU HACK

Unknown

Three Rivers Community College may have suffered a security breach due to unauthorized access to its computer network. Data made vulnerable in the breach included names and Social Security numbers. Those affected would have been involved in the following programs during these years:
1997-2009: Participants in the Real Estate programs
2004-2009: Participants in the Life Long Learners programs
2003-2006: Participants in the Patient Care Technicians programs
2004-2006: Participants in the Certified Nursing Assistant programs
2004-2005: Participants in the Electric Boat academic programs
2007-2008: Participants in the Bridges to Health Care Careers programs
2006-2008: Participants in the Photons for Educators programs
2004-2009: Faculty or staff members of the Three Rivers Continuing Education office.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

March 30, 2010 Boulder Community Hospital, Family Medical Associates
Lafayette, Colorado
MED PHYS

At least 14

Anonymous letters were sent to at least 14 patients of the Family Medical Associates clinic in Lafayette.  The letters contained Social Security numbers, medical records, dates of birth and names.  The sender claimed that the clinic was improperly disposing patient personal information.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 14

March 29, 2010 Proxima Alfa Investments LLC
New York, New York
BSF PORT

Unknown

In November the firm discovered that several backup tapes were missing from its office. The tapes contained customer information such as names, e-mail addresses, addresses, phone numbers, Social Security numbers, bank account information, passport numbers and sometimes scans of passports. The firm ceased operations in mid-2009.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 29, 2010 University MRI Diagnostic Center, Holy Cross Hospital, North Ridge Medical Center, and Oncology and Hematology Associates of West Broward
, Florida
MED INSD

Unknown

In Fort Lauderdale and Tamarac Florida

A former employee of these organizations was involved in a identity theft scheme involving at least three other partners.  The woman had access to patient records such as names, dates of birth, Social Security numbers, Medicare numbers, and addresses.  The stolen information was used to obtain Care Credit accounts and Chevron Visa credit cards.  Victims lost a total of approximately $162,000.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 29, 2010 Griffin Hospital
Derby, Connecticut
MED INSD

957 (0 SSNs and financial documents reported)

A former employee appears to have continued accessing patient names, medical information, dates of birth and medical record numbers.  Patients received soliciting phone calls from a physician at another hospital.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

March 27, 2010 Laboration Corporation of America LabCorp
Burlington, North Carolina
MED PHYS

Thousands

Thousands of medical documents fell out of a truck bed while in transit.  The scattered documents contained billing information and possibly medical records from 1993 or later.

 
Information Source:
Media
records from this breach used in our total: 0

March 26, 2010 Educational Credit Management Corporation
ST. Paul, Minnesota
BSF PORT

3,300,000

ECMC, a guarantor of federal student loans, said that a theft has occurred from its headquarters involving portable media with personally identifiable information. The data was in two stolen safes and contained information on approximately 3.3 million individuals and included names, addresses, dates of birth and Social Security numbers. No bank account or other financial account information was included in the data.

 

UPDATE (4/16/10): The information was recovered shortly after the theft and discovered weeks later in a police evidence room.

 
Information Source:
Dataloss DB
records from this breach used in our total: 3,300,000

March 25, 2010 Evergreen Public Schools
Vancouver, Washington
EDU INSD

5,000

A 21-year-old former Evergreen Public Schools student has pleaded guilty to criminal charges in connection with a computerized payroll security breach that put more than 5,000 past and current Vancouver district school employees at risk of identity theft. The man had "shoulder-surfed" a password from an Evergreen school employee while still a student there.

 
Information Source:
Dataloss DB
records from this breach used in our total: 5,000

March 25, 2010 Northwestern Medical Faculty Foundation
Chicago, Illinois
MED INSD

At least 245

(877) 705-5544
legalinquiry@nmff.org

The Cook County Sheriff’s Department has uncovered an identity theft ring, a limited part of which may involve an employee of Millard Cleaning Service, the service contracted to clean the Foundation’s offices. The suspect may have stolen information from paper records, including names, dates of birth, Social Security numbers, and addresses. NMFF has reviewed the Sheriff’s Department’s list of identity theft victims in Illinois and other states. It has identified approximately 65 people who were recent patients of NMFF, and it is contacting those who are known identity theft victims and offering assistance. While the Sheriff’s Department has identified hundreds of other identity theft victims, the majority of them have no connection to NMFF and their personal information was not stolen from NMFF.

 

UPDATE (3/25/10): At least seven individuals linked to the Millard Cleaning Service janitor have been connected to the theft ring.

 
Information Source:
Dataloss DB
records from this breach used in our total: 245

March 25, 2010 New York State DMV
, New York
GOV INSD

Over 200 (0 reports of SSNs or financial information)

Two employees from the New York City office

Seven people, including two former New York State DMV employees from New York City, were indicted in a theft ring. The identify fraud ring involved New York State driver's licenses, learner's permits, and identification cards. The information was then sold to felons.  Fifteen other people were charged with buying the stolen information.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 25, 2010 Valencia High School
Valencia, California
EDU INSD

Unknown

A student gained access to the entire district of Hart's system, but only went into his high school's portion. The student claimed he changed some things and then returned them. The student most likely used a password, but it is not known whether he used a district computer or a personal one. The district is providing one year of free credit monitoring services.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 25, 2010 Yuma Proving Ground
Yuma, Arizona
GOV HACK

700

A home computer that contained personnel data may have picked up a virus from the Internet. This breach puts employee names and Social Security numbers at risk.

 
Information Source:
Databreaches.net
records from this breach used in our total: 700

March 25, 2010 Johns Hopkins University School of Education
Baltimore, Maryland
EDU DISC

Unknown

A file containing student enrollment information was accessible online.  Student names, races, genders, Social Security numbers, identification numbers and dates of birth were accessible for at least one month.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 24, 2010 Wachovia
Alexandria, Washington
BSF CARD

Unknown

A skimming device was spotted outside a Wachovia branch in Alexandria, Washington. It is estimated that over $60,000 in fraudulent charges was stolen from ATM customers of the Wachovia King Street branch.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 23, 2010 H&R Block
Chicago, Illinois
BSF INSD

60

After Highland, Ind., police pulled over a driver for suspicion of driving under the influence. A search of the car uncovered a treasure-trove of evidence: a file box full of H&R Block client information, numerous blank W-2 forms, more than 100 debit cards and yellow legal pads with columns of Social Security numbers, PIN numbers, dates of tax filings and whether the returns had been accepted or rejected. The two women stole the identities of more than 60 H&R Block customers from the East Chicago branch. Fraudulent tax returns were then filed in their names since January, and refunds went to bank accounts set up by the two, the complaint alleged. IRS agents have found 17 bank accounts with deposits totaling almost $290,000.

 
Information Source:
Dataloss DB
records from this breach used in our total: 60

March 23, 2010 Connecticut Office of Policy and Management
Hartford, Connecticut
GOV INSD

11,000

Police are investigating the theft of personal information — including Social Security numbers, names and addresses — from as many as 11,000 people who had applied for furnace rebate programs with the state. The investigation by Hartford and state police has led them to a woman who worked at the state Office of Policy and Management from May 2008 until May 2009. There have been no arrests. The state collected Social Security numbers because the refunds are federally taxable and the state was required to send a 1099 tax form to the recipients.

 
Information Source:
Dataloss DB
records from this breach used in our total: 11,000

March 22, 2010 Arkansas Crime Information Center
Little Rock, Arkansas
BSO INSD

Unknown

It appears that the owner of a bail bonds business accessed criminal, family, and financial background information by misusing a police password. The Arkansas Crime Information Center database was fraudulently accessed 1,200 times in less than one year.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 22, 2010 Yuma Proving Ground
Yuma, Arizona
BSO HACK

700

The personal information of more than 700 Yuma Proving Ground employees may be at risk of identity theft because a home computer that contained their data may have been compromised. According to YPG spokesman, personnel information from 2005-2007, which included the names and Social Security numbers of the employees at that time, was being stored on the personal home computer of an employee of the installation's Resource Management Division. That information, which was being maintained by the Department of the Army, could have been compromised and possibly accessed during that time because the employee's computer may have picked up a virus from the Internet.

 
Information Source:
Dataloss DB
records from this breach used in our total: 700

March 19, 2010 PNC Financial Services Group Inc.
Dayton, Ohio
BSF HACK

Unknown

PNC Financial Services Group is investigating a possible security breach involving some debit cards issued by the former National City Corp., which it acquired in December 2008. The problem surfaced when former National City customers began reporting unauthorized charges on their accounts. The breach involves a small number of cards in the Cincinnati area, and it appears to have been committed by someone outside PNC or National City prior to the merger. It doesn’t involve any PNC-branded cards or longtime PNC customers. PNC has shut down National City debit cards in the Cincinnati area and asks that customers who have not yet done so activate their PNC debit cards. PNC is working one-on-one with customers to refund accounts, and has been returning funds within 24 hours.

 
Information Source:
Media
records from this breach used in our total: 0

March 19, 2010 National Realty and Investment Advisors, LLC
Hoboken, New Jersey
BSF HACK

Unknown

Certain consumer information was accessed without proper authorization on March 9, 2010. Names and addresses were accessed, as well as additional information that may have included Social Security numbers, dates of birth and/or account numbers.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

March 19, 2010 MyPilotStore.com
Scottsdale, Arizona
BSO HACK

Unknown

In February, it was discovered that a database containing customer names, addresses, e-mails, telephone numbers, and credit card information had been hacked. Some customers received phony charges to their accounts as a result of this hack.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 18, 2010 California State University, Los Angeles (Cal State Los Angeles)
Los Angeles, California
EDU STAT

232

Cal State Los Angeles has notified 232 former students that a computer stolen from the mathematics department office last month may have contained personal information such as their Social Security numbers and grades.

 
Information Source:
Dataloss DB
records from this breach used in our total: 232

March 18, 2010 Vanderbilt University
Nashville, Tennessee
EDU STAT 7,174
A professor's desktop computer, containing the names and Social Security numbers of 7,174 current and former students was stolen some time during the weekend of Feb. 6.  
Information Source:
Dataloss DB
records from this breach used in our total: 7,174

March 18, 2010 Mary's Pizza Shack
Sonoma, California
BSO HACK

50

The Plaza location of Mary's Pizza Shack has been identified as the target of Internet hackers who penetrated the restaurant's computer system with a "logger" virus that captured credit card numbers at the transaction terminal. Only credit card numbers were taken by the virus, Albano emphasized, no personal identification information, such as Social Security numbers or bank account records were exposed, although VISA and MasterCard debit accounts were apparently raided. Trustwave identified and removed the virus doing the damage.

 
Information Source:
Dataloss DB
records from this breach used in our total: 50

March 17, 2010 Medical Office of Michael Branch, M.D.
Lake Mary, Florida
MED PHYS

Unknown

Police were looking for evidence of another crime when they found personal documents in the dumpster outside of a doctor's office. The doctor specializes in treating the ear, nose, and throat and claims there was nothing about patients in the documents. The doctor agreed to shred the documents while the police investigated whether or not patient information was compromised.

 
Information Source:
NAID
records from this breach used in our total: 0

March 16, 2010 Albany Police Department (ADP Georgia)
Albany, Georgia
GOV DISC

Unknown

Sensitive city documents were found near a garbage can in an alley. The documents may have contained Social Security numbers. It is believed that officers failed to shred the documents and dispose of them properly.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 15, 2010 Pizza Hut
Littleton, Colorado
BSR DISC

5

Littleton Colorado Pizza Hut employee information was left in an envelope in a trash can. The envelope contained employment applications, Social Security numbers, and tax information. It also contained invoices.

 
Information Source:
Databreaches.net
records from this breach used in our total: 5

March 13, 2010 St. Louis Metropolitan Police Department
St. Louis, Missouri
GOV HACK

24

24 people may have had their personal information compromised following the cyber attack of one computer in the St. Louis Metropolitan Police Department. The attack came through an e-mail. The department’s website was not attacked. The names, addresses and Social Security numbers of the 24 people may have been viewed.

 
Information Source:
Dataloss DB
records from this breach used in our total: 24

March 13, 2010 John Hancock Financial Services
Boston, Massachusetts
BSF PORT

At least 1,085

A CD that contained customer names, Social Security numbers, and dates of birth went missing. The CD was password protected and encrypted and credit monitoring services were offered to customers who may have been affected.

 
Information Source:
Databreaches.net
records from this breach used in our total: 1,085

March 13, 2010 Beer and Wine Hobby
Woburn, Massachusetts
BSR HACK

35,000 (0 complete credit card numbers reported)

Personal information may have been accessed during a breach of Beer and Wine Hobby's computer system. The personal information included partial credit card numbers.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 13, 2010 TD Bank
Mount Laurel, New Jersey
BSF INSD

Unknown

A former TD Bank employee provided information to outside accomplices who stole over $200,000 from customer accounts. The insider passed along driver's license numbers and bank account numbers.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 13, 2010 California Pizza Kitchen
Plymouth Meeting, Pennsylvania
BSR CARD

Unknown

A credit card thief and his partner used skimming devices to obtain credit card account information. The thief provided his partner with a skimming device while she worked at a California Pizza Kitchen in Plymouth Meeting, Pa. from 2008 to 2009. Around 26 customer credit cards were fraudulently charged.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 13, 2010 Beecher Carlson
Boston, Massachusetts
BSO PORT

1,012

Two laptops were stolen from employees attending an off-site company meeting in January. The laptops contained names and Social Security numbers for employees of Beecher Carlson’s clients, including 1,012 people who live in Massachusetts.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,012

March 13, 2010 Nuance Communications Inc.
Burlington, Massachusetts
BSO PORT

1,191

Nuance Communications Inc., a Burlington speech technology company, reported a laptop stolen from a locked car in Burlington may have contained personal information such as names and Social Security numbers of 1,191 Massachusetts residents.The company notified its employees, installed security and encryption software on laptops, and purchased credit monitoring services for those workers whose information was on the laptop.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,191

March 12, 2010 Beecher Carlson Holdings Inc.
Atlanta, Georgia
BSF PORT

At least 1,012

Two laptops were stolen from employees while they were off-site. The laptops contained employee names and Social Security numbers. Many more people may have been affected since the total number of Massachusetts residents affected is 1,012.

 
Information Source:
Databreaches.net
records from this breach used in our total: 1,012

March 11, 2010 monoprice.com
Rancho Cucamonga, California
BSR HACK

Unknown

The company took their web site offline, after it received e-mails and phone calls from several customers complaining about fraudulent charges on their debit and credit cards that they had used on monoprice.com.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

March 11, 2010 First Convenience Bank
Killeen, Texas
BSF INSD

Unknown

A former employee sold customer information which led to the theft of at least $53,000 from customer accounts.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 11, 2010 Bennett College
Greensboro, North Carolina
EDU HACK

1,100

A payroll computer was breached. Names, Social Security numbers, birth dates, pay rates, and bank transit numbers were exposed.

 
Information Source:
Databreaches.net
records from this breach used in our total: 1,100

March 10, 2010 Atlanta Veterans Affairs Medical Center
Atlanta, Georgia
MED INSD

Unknown

An assistant allegedly recorded two sets of patient data on to a personal laptop for research purposes. One set included three years' worth of patient data and another held 18 years of medical information. The physician assistant's laptop was never connected to the VA network and any data she recorded on her laptop was hand entered. The department has not disclosed the number of patients involved in the incident, what kind of personal data was copied, or whether it plans to notify the veterans whose records were downloaded.

 
Information Source:
Media
records from this breach used in our total: 0

March 10, 2010 Thrivent Financial for Lutherans
Mechanicsburg, Pennsylvania
BSF PORT

Unknown

Thrivent Financial for Lutherans, Minneapolis, experienced a break-in at one of its offices in Pennsylvania. A laptop computer was among the items stolen. The laptop had safeguards to protect sensitive information, including strong password protection and encryption. But Thrivent Financial says the information stored on the laptop may be at risk. The information on the laptop included personal information, including names, addresses, Social Security numbers and health information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

March 10, 2010 Wickenburg Unified School District
Wickenburg, Arizona
EDU DISC

1,438

State auditors found that the District's network was accessible to unauthorized users.  Backup servers were kept in an easily accessible room.  Names, Social Security numbers, addresses and birth dates of students were left exposed.

 
Information Source:
Databreaches.net
records from this breach used in our total: 1,438

March 9, 2010 LPL Financial
Boston, Massachusetts
BSF PORT

Unknown

An unencrypted portable hard drive was stolen from a car of an LPL representative. As a result of the theft, private client information, including names, addresses, dates of birth and Social Security numbers may have been breached.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

March 8, 2010 Arrow Electornics
Melville, New York
BSR PORT

4,004

A laptop containing current and former employee personal information was stolen. The information included names, Social Security numbers, addresses, telephone numbers, and some corporate and personal credit cards.

 
Information Source:
Databreaches.net
records from this breach used in our total: 4,004

March 8, 2010 Huntington Place Senior Community
Chalmette, Louisiana
MED DISC

Unknown

Personal documents were found in the abandoned nursing home. The documents included names, Social Security numbers, medical records and dates of birth of patients.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

March 8, 2010 McNair Eye Center
Heber Springs, Arkansas
MED STAT

9,000

A computer server with patient personal information was stolen.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 9,000

March 8, 2010 Arrow Electronics
Melville, New York
BSO PORT

4,004

The theft of a laptop from the office of Arrow Electronics has resulted in the company notifying 4,004 current and former employees that their personal information was on the laptop. The laptop was stolen during a break-in on February 18. Personal information on the laptop included names, addresses, telephone numbers, and for some of those who used company Blackberry, wireless AirCard and calling card services, their Social Security numbers, some credit card information such as last four digits, security code, and expiration date.

 
Information Source:
Media
records from this breach used in our total: 4,004

March 7, 2010 Randle Eastern Ambulance Service inc.
Miami, Florida
MED INSD

Unknown

A man and his wife who were previously charged with selling patient information in 2009, were charged with stealing personal informaiton of individuals transported by Randle Eastern Amubulance Service inc. (American Medical Response).  The information was then sold to South Florida personal injury attorneys and clinics.  The stolen information included names, telephone numbers, medical diagnoses, and addresses.  They used the help of a former AMR employee.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 6, 2010 Westin Bonaventure Hotel & Suites
Los Angeles, California
BSO HACK

Unknown

Westin Bonaventure Hotel & Suites four restaurants in Lake View Bistro, Lobby Court Bar, Bonavista Lounge and L.A. Prime., along with its valet parking operation, may have been hacked at some time between April and December, disclosing names, credit card numbers and expiration dates printed on customers' debit and credit cards.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

March 5, 2010 Arkansas Army National Guard
Camp Robinson, Arkansas
GOV PORT

35,000

An external hard drive has gone missing. Approximately 35,000 current and former members of the Arkansas Army National Guard are affected by the loss. The drive included names, Social Security numbers and other personal information which potentially places the affected soldiers at risk for identity theft.

UPDATE (5/18/10): The external hard drive containing personal information on over 32,000 current and former Arkansas Guardsmen that was reported missing on February 22 has now been recovered and destroyed. The drive was reported missing by an Arkansas Soldier who used the device as a personal backup of his work related information. This included a copy of the Guard's personnel database which contained personal information on all Soldiers who have served in the Arkansas Army National Guard since 1991.

 
Information Source:
Dataloss DB
records from this breach used in our total: 35,000

March 5, 2010 UT Southwestern Medical Center
Dallas, Texas
MED INSD

200

UT Southwestern recently sent out a mass mailing to 10,000 of its patients, claiming that a former employee disclosed patients' information to a third party that intended to use it for credit, loans and open bank accounts. UT Southwestern representatives claim 200 patients were actually affected.

 
Information Source:
Dataloss DB
records from this breach used in our total: 200

March 5, 2010 University of Texas Southwestern Medical Center
Dallas, Texas
GOV INSD

At least 200

A former employee was arrested on patient information and identity theft.  The stolen patient information includes names, Social Security numbers, birth dates, addresses, phone numbers and financial data.  The employee allegedly sold patient information to an outside party for the purpose of creating bank accounts and misusing credit and loans.

 
Information Source:
Databreaches.net
records from this breach used in our total: 200

March 5, 2010 Hancock Fabrics
Baldwyn, Mississippi
BSR DISC

Unknown

Employee documents were found near a dumpster behind the Huntsville, Alabama store. The documents were not shredded and contained payroll records dating back to 2005 with Social Security numbers, names, and pay rates.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 4, 2010 Wake Forest United Baptist Medical Center (WFUBMC)
Winston-Salem, North Carolina
MED PORT

554

A bag containing a document with the names and Social Security numbers of 554 patients was stolen from an employee's locked car.

 
Information Source:
Databreaches.net
records from this breach used in our total: 554

March 4, 2010 Courage to Change
Houston, Texas
MED INSD

Unknown

The owner of the business used patient Medicaid information to fraudulently claim $968,583 from Medicaid between January of 2003 and September of 2006.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

March 4, 2010 Akel Business Services (also Silva Bookkeeping and Tax Services)
La Mesa, California
BSF INSD

At least 32

A dishonest business owner filed fraudulent tax returns by using his clients' information. He also created fictitious identities by using the Social Security numbers of his clients' children.

 
Information Source:
Databreaches.net
records from this breach used in our total: 32

March 3, 2010 Small Dog Electronics
Waitsfield, Vermont
BSR HACK

3,000

After Small Dog began collecting and matching customer donations for Haiti relief efforts, a hacker breached the website and began stealing customer credit card information. The breach lasted from December of 2009 to January of 2010.

 
Information Source:
Databreaches.net
records from this breach used in our total: 3,000

March 2, 2010 Shands at UF
Gainesville, Florida
MED PORT

12,500

Shands at UF sent notification letters to about 12,500 people Monday warning them that a laptop containing their personal and medical information was stolen. An employee had uploaded the information onto his home laptop for work-related purposes. The laptop held information about patients referred to the gastroenterology clinical services department. Included were names, addresses, medical record numbers, and in the case of 650 patients, Social Security numbers.

 
Information Source:
Dataloss DB
records from this breach used in our total: 12,500

March 2, 2010 Open Door Clinic of Greater Elgin
Elgin, Illinois
MED HACK

260

According to a lawsuit, the clinic stores patient information, including Social Security numbers, addresses, telephone numbers, insurance information and medical history on a file-sharing network. That network is accessible to employees’ personal laptops and home computers. A spreadsheet with information of about 260 of its patients was leaked as a result of the installation and use of file sharing software on computers containing patients’ personally identifiable information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 260

March 2, 2010 Family Health Center
Reston, Virginia
MED DISC

Unknown

Boxes containing patient information ended up in a dump.  The easily accessible information included health history, surgeries performed, test results, pictures, insurance cards, bank account information and addresses.  The boxes were traced back to Family Health Center on Town Center Parkway.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

March 2, 2010 Diabetes Direct Inc
Juniper, Florida
MED INSD

Unknown

A former employee is accused of stealing patient information to commit identity theft. The former employee also had multiple driver's licenses and was able to open utility, bank and credit accounts.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

March 1, 2010 US Bank
Cleveland, Ohio
BSF PORT

Unknown

A laptop was stolen from the desk of a financial adviser. The laptop contained personal information about bank customers.  This occurred at the 5154 Wilson Mills branch in Cleveland, Ohio.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

February 28, 2010 Wyndham Hotels & Resorts
Dallas, Texas
BSO HACK

Unknown

International hotel group Wyndham Hotels and Resorts (WHR) has suffered yet another serious data breach after hackers broke into its computer systems, stealing customer names and payment card information.

UPDATE (5/18/10): An open letter from Wyndham to its customers: www.wyndhamworldwide.com/customer_care/data-claim.cfm

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

February 27, 2010 AT&T
Chicago, Illinois
BSF INSD

Unknown

A former employee of an unknown service provided for AT&T removed documents that contained customer credit card information.  The information may have also included Social Security numbers, driver's license numbers, names and addresses.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

February 27, 2010 GroupM
New York, New York
BSO PORT

1,501

Eight laptops were stolen from an office. They most likely contained unencrypted employee information such as Social Security numbers and bank account information.

 
Information Source:
Databreaches.net
records from this breach used in our total: 1,501

February 27, 2010 California Business Bureau Inc., Medical Billing Services
Monrovia, California
MED INSD

8,861

A former employee accessed unencrypted files between December of 2006 and March of 2008. The files contained patient Social Security numbers, names, addresses, and dates of birth.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 8,861

February 27, 2010 Ameripath
Palm Beach Gardens, Florida
MED PORT

Unknown

A laptop containing sensitive information was stolen from an employee. The data included names, Social Security numbers, and addresses for patients, employees, or both.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

February 25, 2010 Wyoming Department of Health
Cheyenne, Wyoming
GOV DISC

9,000

The personal information of about 9,000 children in the state's children's health insurance program could have been exposed on the Internet. The error resulted in the names, birthdays, Social Security numbers, addresses and phone numbers of Kid Care CHIP participants being accessible on an unsecured Web page for months.

 
Information Source:
Dataloss DB
records from this breach used in our total: 9,000

February 25, 2010 Logic World Medical
Houston, Texas
MED INSD

Unknown

The owner and operator of Logic World Medical used the names, addresses, and account numbers of Medicaid beneficiaries to file false claims for payment of services and goods that he never provided.  Approximately $1,101,865.37 was fraudulently claimed between April of 2004 and August of 2006.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

February 24, 2010 Citigroup
New York, New York
BSF DISC

600,000

About 600,000 Citigroup customers got a shock earlier this month when they received their annual tax documents with their Social Security numbers printed on the outside of the envelope. The digits were not identified as a Social Security number, and they were printed at the lower edge of the mailing envelope with other numbers and letters that together resembled a mail routing number.

 
Information Source:
Dataloss DB
records from this breach used in our total: 600,000

February 24, 2010 University of Washington Medical Center (UWMC)
Seattle, Washington
MED INSD 210
The UWMC sent letters to patients telling them that their Social Security numbers, credit card information, birth dates and addresses were accessed by dishonest persons. The personal information was found in the possession of a convicted felon who had ties to an employee who works with the hospital. The employee worked at NCO Financial Systems, a company which UWMC uses to process patient payments.  
Information Source:
Databreaches.net
records from this breach used in our total: 210

February 24, 2010 7-Eleven
Sandy, Utah
BSR CARD

Unknown

A skimming device monitored transactions at a gas station pump in Sandy, Utah. The device could have been active for 60 days before being discovered and was used to steal over $11,000.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

February 22, 2010 SunTrust Bank
Atlanta, Georgia
BSF CARD

Well over 200

Throughout the summer of 2009, four men put skimming devices on SunTrust Bank ATMs in the Florida counties of Hillsborough and Pinellas.

 
Information Source:
Databreaches.net
records from this breach used in our total: 200

February 19, 2010 TennCare
Nashville, Tennessee
MED DISC

3,900

An electronic error caused information such as Social Security numbers for about 3,900 enrollees to be sent to incorrect addresses. The error was the result of a modification to the system that pulls addresses into an electronic file for TennCare, the state's expanded Medicaid program. Letters and cards that contained one or more pieces of personal information were sent to incorrect addresses.

 
Information Source:
Dataloss DB
records from this breach used in our total: 3,900

February 19, 2010 Valdosta State University
Valdosta, Georgia
EDU HACK

170,000

http://www.valdosta.edu/notify/

A Valdosta State server that was reported as being breached could have exposed the information of up to 170,000 students and faculty. Valdosta State officials reported the discovery of a breach on Dec. 11 and estimated it began on Nov. 11. The university said the grades and Social Security numbers of up to 170,000 students and faculty were exposed in the breach.

 
Information Source:
Dataloss DB
records from this breach used in our total: 170,000

February 17, 2010 Cardiology Consultant Inc.
Pensacola, Florida
MED PORT

8,000 Not included in total because Social Security numbers and financial information not involved.

Cardiology Consultants Inc. today reported that a laptop used to process ultrasound images was stolen from one of its Pensacola offices. The computer did not contain patient financial information or Social Security numbers. The stolen computer did contain the first and last names, dates of birth, medical record numbers, exam dates and in some cases, the reason for the ultrasound.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

February 17, 2010 Southern Illinois University
Carbondale, Illinois
EDU HACK

900

A computer security breach at Southern Illinois University may have put hundreds of alumni at risk of identity theft. A faculty member's computer in the Mathematics Department was found to be infected with malicious software. When the computer files were searched, university officials discovered there were Social Security numbers for approximately 900 students who took introductory math classes at SIU in 2004 and 2005 stored on the hard drive.

 
Information Source:
Dataloss DB
records from this breach used in our total: 900

February 17, 2010 Dairy Queen
Hanceville, Alabama
BSO HACK

Unknown

Hanceville police are cautioning residents to be on guard against a sophisticated debit card wire scam that has leached hundreds of thousands of dollars from customers whose card numbers have been stolen remotely from pay terminals at one or more local businesses. The primary target in the theft so far has been the Dairy Queen restaurant. It's unsure whether this is ultimately involving other businesses. At the Dairy Queen location, somebody has apparently tapped into the Internet server and hacked into the debit card system. They are printing the customers’ debit card numbers and using them all over California and Georgia.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

February 17, 2010 T.G.I. Friday's (TGIF)
Coon Rapids, Minnesota
BSR CARD

At least 5

A former employee used a skimming device to gain credit card information from customers of the Coon Rapids T.G.I. Friday's. The dishonest employee was involved with a partner who used skimming devices in a variety of locations throughout Minnesota.

 
Information Source:
Databreaches.net
records from this breach used in our total: 5

February 16, 2010 New York Social Security Administration
New York, New York
GOV PORT

969

A computer disc containing detailed personal information about 969 New Yorkers was lost by a Social Security Administration employee traveling to Queens from the Bronx. The disc was lost as the employee was going to the Queens Social Security hearing office, and the information on it included administrative decisions, medical evidence and internal agency documents containing people’s names and Social Security numbers.

 
Information Source:
Dataloss DB
records from this breach used in our total: 969

February 16, 2010 Eclipse Property Solutions
St. Petersburg, Florida
BSO INSD

Unknown

A St. Petersburg man has been charged with stealing customers' credit card numbers from a marketing company he worked for to buy nearly $30,000 in dinners, limos and other luxuries. The man and another employee, listened from their cubicles as co-workers repeated customer credit card information aloud to confirm accounts.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

February 15, 2010 West Memphis Police Department
Memphis, Tennessee
GOV INSD

Unknown

FBI is investigating, after the security of the West Memphis Police Department's computer network was apparently compromised. The FBI had information that somebody had used a computer that shouldn't have used it. The suspect in the breach was a detective in the police department. Files containing the names and Social Security numbers of police department employees were stored on the computer network, making the employees vulnerable to identity theft.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

February 12, 2010 Galeton, Gloves Inc.
Mansfield, Massachusetts
BSR HACK

At least 89

The Gloves Inc. website for Galeton was hacked. Customer names, addresses, credit card numbers and expiration dates were exposed.

 
Information Source:
Databreaches.net
records from this breach used in our total: 89

February 12, 2010 Daedalus Books Inc.
Columbia, Maryland
BSR HACK

At least 1,285

A hacker accessed a database with customer information.  The information included names, addresses, and credit card numbers from people who made orders between August 25, 2009 and November 23, 2009.

 
Information Source:
Databreaches.net
records from this breach used in our total: 1,285

February 12, 2010 ING Fund
Amsterdam,
BSF DISC

106

Customer information was accessible through a web search from August of 2008 through January of 2010.  The information included names, Social Security numbers, addresses, and account numbers of shareholders in New Hampshire and other locations.

 
Information Source:
Databreaches.net
records from this breach used in our total: 106

February 11, 2010 Equifax
Atlanta, Georgia
BSF DISC

Unknown

An unknown number of current and former employees of credit reporting firm Equifax received W-2 forms in the mail with their Social Security numbers visible through a window on the envelope. Some of the tax forms mailed by Equifax's payroll vendor through the U.S. Postal Service had the Social Security number in a Control Number field, which was partially or fully viewable through the return address window.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

February 11, 2010 University of Texas Medical Branch
Galveston, Texas
MED INSD

2,400

The University of Texas Medical Branch has mailed letters notifying 1,200 patients that sensitive information about them had been available to a woman charged with identity theft in an unrelated case. Officials sent out the letters this week after MedAssets, which the medical branch hired to assist with billing from third-party payers, warned of a security breach by one of its employees. Law enforcement officials notified MedAssets that a former employee had been arrested and charged with identity theft. The person also was alleged to have used a stolen identity to misrepresent herself and gain employment at Georgia-based MedAssets and had been involved in other instances of identity theft. That employee is implicated in a widespread identity theft investigation involving cases from Texas to Wisconsin and losses upward of $1 million.

Update (3/9/10): 1,200 more letters were sent out to people who's financial information may have been exposed.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,200

February 11, 2010 Lawrence Welk Resort
Escondido, California
BSR HACK

1,427

After its security system was disabled, customer credit and debit card information was exposed. The exposure of the information led to some unauthorized transactions.

 
Information Source:
Databreaches.net
records from this breach used in our total: 1,427

February 11, 2010 Sandwich Board Cafe
Greenwood Village, Colorado
BSO INSD

Unknown

An employee used customer credit card information to purchase $200,000 worth of Wal-Mart shopping cards.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

February 10, 2010 Wellpoint, Anthem/Blue Cross and Blue Shield
Chicago, Illinois
MED INSD

Unknown

A former employee accessed health care professionals' Social Security numbers, names, dates of birth, and home addresses. Between 2007 and 2010, the employee created fictitious identities and created e-mail addresses, opened bank accounts and credit card accounts.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

February 9, 2010 California Department of Health Care Services
Sacramento, California
GOV DISC

50,000

The personal security of nearly 50,000 people may have been breached by the California Department of Health Care Services. Social Security numbers were printed on the address labels of letters that were mailed by the department. State employees mistakenly included the numbers in a list of patient addresses. The list was sent to an outside contractor, who printed and mailed the envelopes.

 
Information Source:
Dataloss DB
records from this breach used in our total: 50,000

February 9, 2010 Ohio Department of Administrative Services
Columbus, Ohio
GOV DISC

6,000

Personal banking information for 6,000 state employees was inadvertently included in a e-mail distributed to dozens of payroll officers of state agencies. The e-mail from an unnamed administrative-services employee included an attached spreadsheet listing 6,000 state employees whose bank accounts are to be moved from National City Bank, which was bought by PNC Bank.

 
Information Source:
Media
records from this breach used in our total: 6,000

February 9, 2010 Kansas City Art Institute
Kansas City, Kansas
EDU STAT

145

About 145 employees at the Kansas City Art Institute have been notified of potential identity theft in connection with the disappearance of a computer from the campus. An Apple computer that contained Social Security numbers, dates of birth and other personal information about the school's professors and staff employees was stolen from the human resource office.

 
Information Source:
Dataloss DB
records from this breach used in our total: 145

February 6, 2010 University of Texas, El Paso
El Paso, Texas
EDU DISC

15,000

University of Texas at El Paso is notifing students that their Social Security number were visible when their tax form was sent out. The University notified 15,000 students but they don't know exactly how many students were affected. UTEP blames a glitch in a machine used to fold letters when student’s forms were sent out. Some of the forms were folded in such a way that the document shifted on the envelope and allowed for the Social Security numbers to be visible through the mailing window on the envelope.

 
Information Source:
Dataloss DB
records from this breach used in our total: 15,000

February 6, 2010 AvMed Health Plans
Gainesville, Florida
MED PORT

208,000

Additional 860,000 added June 3rd

AvMed Health Plans announced that personal information of some current and former subscribers may have been compromised by the theft of two company laptops from its corporate offices in Gainesville. The information included names, addresses, phone numbers, Social Security numbers and protected health information. The theft was immediately reported to local authorities but attempts to locate the laptops have been unsuccessful. AvMed determined that the data on one of the laptops may not have been protected properly, and approximately 80,000 of AvMed's current subscribers and their dependents may be affected. An additional approximate 128,000 former subscribers and their dependents, dating back to April 2003, may also have been affected.

UPDATE (6/3/2010): The theft of the laptops compromised the identity data of 860,000 more Avmed members than originally thought.  The total now nears 1.1 million.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,068,000

February 5, 2010 Wyoming Department of Health Kid Care CHIP
Cheyenne, Wyoming
GOV DISC About 5,000
Applicants of the Wyoming Kid Care CHIP program had their information exposed online. Family home addresses and the Social Security numbers of children involved were available to the general public via a Google search.  
Information Source:
Databreaches.net
records from this breach used in our total: 5,000

February 4, 2010 Highmark Insurance
Pittsburgh, Pennsylvania
MED PHYS 3,700
Highmark was notifying some 3,700 members that documents containing their names, policy identification and Social Security numbers were missing, the second such data spill involving the region’s dominant health insurer in four months. In January, the company mailed a premium billing statement to Boscov’s Department Store, a client in Reading, according to Highmark. The envelope arrived damaged and torn and pages were missing. The pages included the names and other identifying information for some 3,700 members.  
Information Source:
Dataloss DB
records from this breach used in our total: 3,700

February 4, 2010 Ozarks Area Community Action Corporation
Springfield, Missouri
NGO DISC

250

The organization printed two 1099 forms on one piece of paper. They were supposed to separate them and send each to the rightful owner. Instead one person got both. The mistake sent tax forms and Social Security numbers to strangers. More than 500 landlords work with OACAC. On January 28, 2010, half of those landlords didn't receive tax forms. The other half got their forms and someone else's private information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 250

February 4, 2010 Ceridian Corporation
Bloomington, Minnesota
BSF HACK 27,000
A hacker attack at payroll processing firm Ceridian Corp. of Bloomington has potentially revealed the names, Social Security numbers, and, in some cases, the birth dates and bank accounts of 27,000 employees working at 1,900 companies nationwide. In a Jan. 29 letter to an affected worker obtained by the Star Tribune, Ceridian said a hacker attacked its Internet payroll system Dec. 22 and 23  
Information Source:
Dataloss DB
records from this breach used in our total: 27,000

February 4, 2010 HyCentral Medical Supplies and Equipment
Derry, New Hampshire
MED INSD

Unknown

The owner of the business used Medicare client information to obtain approximately $1.6 million worth of fraudulent claims.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

February 3, 2010 Memorial Hermann Hospital
Houston, Texas
MED INSD

At least one

A former employee stole a document that contained the name, Social Security number, date of birth, and address from a deceased patient's medical records.

 
Information Source:
Databreaches.net
records from this breach used in our total: 1

February 3, 2010 Dr. Barry Bupp's Dental Practice in Medical Commons One
Greensburg, Pennsylvania
MED PORT Unknown
A laptop containing patient information was stolen.  
Information Source:
Databreaches.net
records from this breach used in our total: 0

February 3, 2010 Dr. Elie Abdallah's office in Medical Arts Building
Greensburg, Pennsylvania
MED PORT Unknown
A laptop containing patient information was stolen.  
Information Source:
Databreaches.net
records from this breach used in our total: 0

February 1, 2010 West Virginia University
Morgantown, West Virginia
EDU DISC 53
Around 53 West Virginia University students’ personal information was available to others following an "operational error" during a routine update of tax information. The students’ 1098-T forms, which include their Social Security number and tax identification numbers, among others, were uploaded to the University’s 1098-T Web site. The forms are distributed to WVU students who are U.S. citizens who paid tuition during the 2009 calendar year. They can be used to claim federal tax credit. Students can typically access their forms on the site for tax purposes, but the error made the information viewable to any WVU student on the site.  
Information Source:
Dataloss DB
records from this breach used in our total: 53

January 31, 2010 Iowa Racing and Gaming Commission
Des Moines, Iowa
GOV HACK

80,000

The Iowa Racing and Gaming Commission says someone gained access to a computer server that holds more than 80,000 records containing casino employee information. The person who hacked into the system had used a computer with an external account. The server contains records including names, birth dates and Social Security numbers.

 
Information Source:
Dataloss DB
records from this breach used in our total: 80,000

January 30, 2010 Ameriquest Mortgage Company
Apple Valley, Minnesota
BSF INSD

100

A man working for Ameriquest Mortgage Company as a mortgage associate for only six weeks. Turned out to be a pretty fruitful month and a half for him -- and a pretty costly one to nearly 100 people and several financial institutions. Using personal information he lifted from the mortgage applications of nearly 100 people -- as well as mail and even items taken from gym lockers of a couple of hundred more. The man eventually stole more than $150,000 from at least eight banks. The man used stolen personal information to create fraudulent identification documents and checks, which he then used to obtain cash, pay for services and buy items. For example, he used one victim's identification to obtain a credit card through U.S. Bank. With that card, he wound up withdrawing $30,529.63 in cash from ATMs throughout Minnesota. Those withdrawals were charged to the victim

 
Information Source:
Dataloss DB
records from this breach used in our total: 100

January 28, 2010 PricewaterhouseCoopers
New York, New York
BSO UNKN

77,000

The names, birth dates and Social Security numbers of 77,000 people were lost in their Chicago office. The people at risk for identify theft are those who were in the PERS and TRS system in 2003-04 as active or inactive employees or retirees. PricewaterhouseCoopers has agreed in a settlement to pay for credit monitoring and other security measures and cover any losses to individuals caused by its mishandling of the information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 77,000

January 28, 2010 Humboldt State University
Arcata, California
EDU HACK

3,500

A Humboldt State University computer infected with a virus may have exposed the personal information of 3,500 people employed by the school between 2002 and 2006. The computer was found to have a sophisticated virus that is used to steal login information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 3,500

January 28, 2010 University Medical Clinics
Port St. Lucie, Florida
MED PHYS

Unknown

Files containing Social Security numbers, phone numbers, patient names, and addresses were found in a trash bin outside of the clinic. A woman found the files and notified police after receiving an anonymous tip.

 
Information Source:
NAID
records from this breach used in our total: 0

January 27, 2010 Department of Commerce
Washington, District Of Columbia
GOV DISC

Unknown

A Department of Commerce employee inadvertently transmitted over the Internet a file containing the Personally Identifiable Information (PII) of Commerce employees to other Department employees. Although the Department employees were authorized to send and receive the PII, the transmission of the PII over the Internet in unencrypted form may have compromised their name and Social Security numbers.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

January 27, 2010 University of California, San Francisco (UCSF) School of Medicine
San Francisco, California
MED PORT

7,300 Not included in the total because information did not contain any Social Security numbers or other financial data

A laptop containing files with information on 4,400 patients was stolen from a UCSF School of Medicine employee. Information “potentially exposed” included name, medical record number, age and clinical information, but the stolen laptop did not contain any Social Security numbers or other financial data. The same laptop also contained data for approximately 2,900 patients at Beth Israel Deaconess Medical Center in Boston

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

January 27, 2010 Seattle Municipal Court
Seattle, Washington
GOV INSD

Unknown

A former customer service representative sold the names and credit card information of court customers to ID thieves who then used the information to make fake credit cards in the victims' names.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

January 27, 2010 Methodist Hospital
Houston, Texas
MED PORT

689

Methodist Hospital notified people that someone stole a laptop from an office at the Smith Tower in the Texas Medical Center. A thief took the laptop on January 18. The computer was attached to a medical device that tests pulmonary function and contained private health information and Social Security numbers.

 
Information Source:
Dataloss DB
records from this breach used in our total: 689

January 22, 2010 Brio Tuscan Grille in Country Club Plaza
Kansas City, Missouri
BSR CARD

20

A man used a skimming device to obtain the credit card information of customers while working as a waiter at Brio Tuscan Grille of Kansas City, Missouri.

UPDATE (7/26/10): The former employee was sentenced to three years of federal prison time for credit card fraud and mail fraud.  He originally gained access to the customer information during July and August of 2008. His fraudulent purchases totalled thousands of dollars.

 
Information Source:
Databreaches.net
records from this breach used in our total: 20

January 21, 2010 Columbus Public Health
Columbus, Ohio
GOV UNKN Unknown

An investigation is under way after hundreds of city health workers’ personal information was stolen. Investigators have identified a person of interest in connection with the stolen information. The person of interest was an employee within the department over the past three years. Current employees and those who previously worked at the department within the last three years may be affected

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

January 21, 2010 University of Missouri System
Columbia, Missouri
EDU DISC 75,000
About 100 people responded to an e-mail notifying students that their Social Security numbers may have been visible in the envelope window of a tax form sent by the University of Missouri System. More than 75,000 Form 1098-Ts were mailed. The four-campus system has no way of assessing how many envelopes displayed the numbers. Form 1098-T is an Internal Revenue Service form that reports tuition billed and paid. Campus Mail Services committed the folding errors.  
Information Source:
Dataloss DB
records from this breach used in our total: 75,000

January 19, 2010 CHASE
Louisville, Kentucky
BSF DISC

Unknown

CHASE customer information that was sold to another business was accidentally posted on a website.  The information included names, addresses and bank account numbers.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

January 18, 2010 Goodwill Industries of Grand Rapids
Grand Rapids, Michigan
NGO PORT

Unknown

A man broke into a Goodwill store and stole a safe, but instead of money that thief got the names, addresses, dates of birth, and Social Security numbers from thousands of people.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

January 18, 2010 City of Oakridge
Oakridge, Oregon
GOV DISC Unknown
A list of the names, addresses and Social Security numbers of employees of the City of Oakridge was sent out with monthly water bills in this town of about 1,400 households. The city has signed up all employees for a credit monitoring service. The city does not know how many people received the list of employee information in a newsletter included with their water bill  
Information Source:
Dataloss DB
records from this breach used in our total: 0

January 14, 2010 Defense Finance and Accounting Service/ Defense Department’s Document Automation and Production Service
Arlington, Virginia
GOV DISC

18,000 Not added to total No Social Security numbers or financial information was on the statements

Pay statements containing names and sensitive information about the finances of about 18,000 recipients of a special pay for disabled retirees were sent to wrong addressees. The statements, a page of which contained information about annual increases in Concurrent Retirement and Disability Pay, mistakenly listed data including at least a portion of another recipient’s name, their bank or insurance company name, the amount of their allotment and the allotment type. There is “no indication” that any Social Security numbers, bank account numbers or phone numbers were listed on the erroneously mailed pages.

 
Information Source:
Media
records from this breach used in our total: 0

January 14, 2010 Lincoln National Corporation
Radnor, Pennsylvania
BSF INSD

1,200,000

Lincoln National Corp. (LNC) last week disclosed a security vulnerability in its portfolio information system that could have compromised the account data of approximately 1.2 million customers. In a disclosure letter sent to the Attorney General of New Hampshire Jan. 4, attorneys for the financial services firm revealed that a breach of the Lincoln portfolio information system had been reported to the Financial Industry Regulatory Authority (FINRA) by an unidentified source. The unidentified source sent FINRA a username and password to the portfolio management system. "This username and password had been shared among certain employees of [Lincoln Financial Services] and employees of affiliated companies," the letter says. "The sharing of usernames and passwords is not permitted under the LNC security policy."

 
Information Source:
Media
records from this breach used in our total: 1,200,000

January 14, 2010 BlueCross BlueShield
Chattanooga, Tennessee
MED PORT

220,000

Additional locations: Memphis, Jackson, Knoxville, Nashville and additional locations in Tennessee

The theft of 57 hard drives from a BlueCross BlueShield of Tennessee training facility last October has put at risk the private information of approximately 500,000 customers in at least 32 states. The hard drives containing 1.3 million audio files and 300,000 video files. The files contained customers' personal data and protected health information that was encoded but not encrypted, including: Names and BlueCross ID numbers. In some recordings-but not all-diagnostic information, date of birth, and/or a Social Security number. BCBS of TN estimates that the Social Security numbers of approximately 220,000 customers may be at risk.
UPDATE (4/29/10): The number of plan members whose data were exposed has grown from 521,761,an estimate made in March, to nearly 1 million, as of April 2, according to a report issued by Mary Thompson, spokeswoman for the Tennessee Blues.

 
Information Source:
Dataloss DB
records from this breach used in our total: 220,000

January 14, 2010 Perinton Square Post Office
Perinton, New York
GOV PHYS

20

A group of thieves was able to obtain letters from an outdoor mailbox. They used the information to forge around $75,000 worth of checks; and affected 20 victims.

 
Information Source:
Databreaches.net
records from this breach used in our total: 20

January 12, 2010 Suffolk County National Bank
Long Island, New York
BSF HACK

8,373

Hackers have stolen the login credentials for more than 8,300 customers of small New York bank after breaching its security and accessing a server that hosted its online banking system. The intrusion at Suffolk County National Bank happened over a six-day period that started on November 18. It was discovered on December 24 during an internal security review. In all, credentials for 8,378 online accounts were pilfered, a number that represents less than 10 percent of SCNB's total customer base.

 
Information Source:
Dataloss DB
records from this breach used in our total: 8,373

January 12, 2010 SouthTrust
Bossier, Louisiana
BSF PHYS

Unknown

The financial planning company left sensitive retirement information in a publicly accessible dumpster.  The information included account ID numbers, personal addresses, and Social Security numbers. Information about people living in Shreveport, Haughton, Minden, Monroe, Farmerville, Eros and Downsville, Louisiana was found.  Information from people living in Orange, Port Neches, Vidor and Deweyville, Texas was also found.

 
Information Source:
NAID
records from this breach used in our total: 0

January 12, 2010 Valley Kaiser, Kaiser Permanente
Sacramento, California
MED PORT

15,500 Not added to total because no Social Security numbers or financial information of patients were on the device

Additional location: Fresno, CA

An electronic storage device stolen from an employee's car in Sacramento last month contained health information from 15,500 patients, including about 800 in the Fresno area. Information included patient names, medical-record numbers and, for some individuals, ages, dates of birth, gender, phone numbers and other information related to their care and treatment.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

January 6, 2010 Eugene School District
Eugene, Oregon
EDU HACK

Unknown

databreach@4j.lane.edu, (541) 790-7730

Hackers breached the security of a computer server containing the names, phone numbers and employee ID numbers of current and former Eugene School District employees. The server in question did not contain other personal information but was attached to servers that contain Social Security numbers and other sensitive data. It is possible that the individuals responsible may have accessed names, addresses, dates of birth, Social Security numbers, tax identification numbers and direct-deposit bank account information for current and former staff members.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

January 5, 2010 Housing Authority of New Orleans (HANO)
Algiers, Louisiana
GOV PHYS

Unknown

Personal documents relating to section 8 were left in an unsecured and abandoned office.  The documents included copies of birth certificates, driver's license numbers, pay stubs, and Social Security cards.

 
Information Source:
NAID
records from this breach used in our total: 0

January 5, 2010 Metropark
Los Angeles, California
BSR DISC

Unknown

Personal documents were found at the Palisades Mall in West Nyack, New York. The documents had names, Social Security numbers, contact information, and other personal information. They appeared to be mishandled applications from a clothing store called Metropark.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

January 3, 2010 Logan International Airport
Boston, Massachusetts
GOV INSD

16

A Lynn couple is accused of selling the identities of at least 16 TSA workers at Logan. The ID data was taken by a female TSA contract worker who is related to one of the two Lynn suspects. The couple got the stolen TSA employee names from their niece, a contract clerical worker in the TSA human resources department at Logan. She no longer works there. The couple sold the names, Social Security numbers and dates of birth for $40 each to a contact who set up phony cable, gas and cell phone accounts

 
Information Source:
Dataloss DB
records from this breach used in our total: 16

January 1, 2010 collective2.com
Tenafly, New Jersey
BSO HACK

25,000

Users of the do-it-yourself trading site collective2.com received an “urgent” e-mail notifying them that the company's computer database had been breached by a hacker and that all users should log in to change their passwords immediately. That e-mail stated that the information accessed by the hacker included names, e-mail addresses, passwords and credit card information.

 
Information Source:
Media
records from this breach used in our total: 25,000

January 1, 2010 Washington Department of Corrections
Tumwater, Washington
GOV PHYS

43

A briefcase full of sensitive personnel records was stolen from the vehicle of a Larch Corrections Center manager. Larch human resources manager reportedly took the records home over last weekend to review them, then left his briefcase on the seat of his car while he worked out at the 24-Hour Fitness Center. While he was inside, someone smashed a window in the car. He returned to find the briefcase and 43 files missing. Others had spilled out of the briefcase inside the car. He took the files home to conduct an annual review required by the U.S. Department of Homeland Security. The files contained forms known as I-9s, which provide documentation that employees are legally able to work in the United States. They included driver’s license and Social Security information such as home addresses and dates of birth.

 
Information Source:
Dataloss DB
records from this breach used in our total: 43

January 1, 2010 Netflix
Los Gatos, California
BSO UNKN

100 million not added to total

A class action suit was filed against Netflix, Inc., in United States District Court for the Northern District of California. Plaintiffs in the suit are claiming that Netflix has “perpetrated the largest voluntary privacy breach to date.” According to the Complaint, Netflix knowingly and voluntarily disclosed the sensitive and personal information of approximately 480,000 Netflix subscribers when Netflix provided participants in a contest initiated to improve Netflix’s movie recommendation systems with data sets containing over 100 million subscriber movie ratings and preferences. Netflix has claimed that the data sets provided to the contest participants were anonymized and that the subscribers’ movie ratings were accompanied only by “a numeric identifier unique to the subscriber” (as opposed to the subscriber’s name or other personal information). However, the complaint cites the results of several researchers who, in fact, were able to crack Netflix’s anonymization process and identify individual subscribers.

 
Information Source:
Media
records from this breach used in our total: 0

December 31, 2009 Eastern Washington University
Cheney, Washington
EDU HACK

130,000

Eastern Washington University is trying to notify up to 130,000 current or former students whose names, Social Security numbers and dates of birth were on a computer network involved in a security breach. The student information goes back to 1987. The notification process could take up to two weeks. The University recently discovered the breach during an assessment of its network. Information-technology staff also discovered that the hacker installed software to store and share video files on the system.

 
Information Source:
Dataloss DB
records from this breach used in our total: 130,000

December 31, 2009 Time Inc.
New York, New York
MED INSD

Unknown

A customer service center employee may have misused customer credit card information.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

December 28, 2009 Providence Health
Portland, Oregon
MED DISC

4,500

Providence Health Plans is re-issuing thousands of insurance cards after personal information was accidentally sent to the wrong policy-holders. Officials with Providence Health Plans say about 4,500 mailings were sent out with the incorrect group and member ID numbers, meaning that some policy holders received others’ information. Officials noticed the problem Monday.

 
Information Source:
Dataloss DB
records from this breach used in our total: 4,500

December 23, 2009 Penn State University
University Park, Pennsylvania
EDU HACK

30,000

The University sent out letters notifying those potentially affected by malware infections, which are believed responsible for breaches. The areas and extent of the records involved in the malicious software attack included Eberly College of Science, 7,758 records; the College of Health and Human Development, 6,827 records; and one of Penn State's campuses outside of University Park, approximately 15,000 records.

 
Information Source:
Dataloss DB
records from this breach used in our total: 30,000

December 22, 2009 Western Michigan University
Kalamazoo, Michigan
EDU DISC

Unknown

University officials discovered that student employee information was viewable online. The information included names, addresses and Social Security numbers.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

December 18, 2009 Dickinson School of Law
Carlisle, Pennsylvania
EDU HACK

261

A computer in the Dickinson School of Law that contained 261 Social Security numbers from an archived class list was found to be infected with malware that enabled it to communicate with an unauthorized computer outside the network.

 
Information Source:
Dataloss DB
records from this breach used in our total: 261

December 17, 2009 North Carolina Libraries
Raleigh, North Carolina
EDU HACK

51,000

Library users at 25 campuses, were the victims of a security breach in August. The libraries collect drivers license and Social Security numbers to help identify computer users. The information is stored on a central server in Raleigh. Other campuses affected are Alamance, Beaufort, Bladen, Blue Ridge, Brunswick, Central Carolina, College of the Albemarle, Gaston, Halifax, Haywood, Lenoir, Martin, Nash, Pamlico, Piedmont, Richmond, Roanoke-Chowan, Rowan-Cabarrus, Sandhills, Southwestern, Tri-County, Vance Granville and Wilson.

 
Information Source:
Dataloss DB
records from this breach used in our total: 51,000

December 15, 2009 U.S. Army
Fort Belvoir, Virginia
GOV PORT

42,000

http://www.army.mil/-news/2009/12/16/31955-laptop-containing-personal-information-about-mwr-customers-stolen/

A laptop computer belonging to a Family and Morale, Welfare and Recreation Command (FMWRC) employee was stolen.  Types of information compromised included name, Social Security number, home address, date of birth, encrypted credit card information, personal e-mail address, personal telephone number and family member information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 42,000

December 15, 2009 RockYou
Redwood City, California
BSR HACK

Unknown

The security firm Imperva issued a warning to RockYou that there was a serious SQL Injection flaw in their database. Such a flaw could grant hackers access to the the service's entire list of user names and passwords in the database. Imperva said that after it notified RockYou about the flaw, it was apparently fixed over the weekend. But that's not before at least one hacker gained access to what they claim is all of the 32 million accounts. 32,603,388 to be exact. The database included a full list of unprotected plain text passwords and email addresses.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

December 15, 2009 The Beijing Center for Chinese Studies
Chicago, Illinois
EDU PORT

Unknown


(877) TBS-5060
http://www.thebeijingcenter.org/securityqns

A Stolen laptop exposes applications for study abroad students. Names and Social Security numbers exposed. unknown number of NH residents affected.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

December 15, 2009 Detroit's Health Department
Detroit, Michigan
GOV PORT

5,000

(877) 737-4780

Police are investigating two incidents in which patients' medical records -- including social security numbers -- were stolen from the city's health department. The first theft occurred in late October when a flash drive was stolen from a health department employee's car. It contained files with birth certificate information for babies born in 2008 and the first half of 2009 whose parents reside in the 48202 and 48205 zip codes. Also a part of the files were information on the mothers' names and health conditions, the fathers' names, addresses, Medicaid numbers and social security numbers. The second incident happened over the Thanksgiving break when five computers were stolen from the immunization program at the department's Herman Kiefer Health Complex. One of the computers contained Medicare and Medicaid seasonal flu billing information for 2008.

 
Information Source:
Dataloss DB
records from this breach used in our total: 5,000

December 11, 2009 Lookout Services
Bellaire, Texas
BSO DISC

500

The state of Minnesota has directed all of its agencies to stop using a Texas company state officials hired to verify the identities of new employees. A state official told MPR News that it is notifying some 500 employees that their personal data -- including names, dates of birth and Social Security numbers -- may have been accessible on the company's Web site. For more than three months, state agencies have used Lookout Services of Bellaire, Texas, to verify that new hires are authorized to work in the United States. The state had paid the company $1.50 a name to run employee data through the federal Department of Homeland Security's E-Verify program, which confirms that a worker has legal status and a valid Social Security number.

 
Information Source:
Dataloss DB
records from this breach used in our total: 500

December 10, 2009 Bushland Elementary School
Bushland, Texas
EDU PHYS

100

A Potter County school district has improved security protecting its student records after paperwork containing Social Security numbers, family incomes and student addresses was discovered at a recycling site in Canyon. The documents listed names of about 100 students at Bushland Elementary School who were eligible for free or reduced-price meals through a federal program during the 2003-04 and 2005-06 school years. Applications for subsidized meals from more than 20 families included their Social Security numbers, incomes, addresses and phone numbers.

 
Information Source:
Dataloss DB
records from this breach used in our total: 100

December 7, 2009 Gateway Community College
New Haven, Connecticut
EDU HACK

Unknown

The College attempted to notify potential victims of a breach caused by malware discovered on campus computers. College alumni who donated to the College, potential donors, and students receiving scholarships between 2004 and 2006 may have been affected.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

December 5, 2009 Wake County Schools
Raleigh, North Carolina
EDU DISC

5,000

The Wake County school system accidentally sent out about 5,000 postcards with students' Social Security Numbers printed on the front. Wake schools mailed about 15,000 reminders asking parents to specify if they want to keep their children in magnet or traditional calendar schools. About a third of those cards had the Social Security Numbers printed alongside the child's name - a holdover from recent years when those nine-digit numbers were used to identify students.

 
Information Source:
Dataloss DB
records from this breach used in our total: 5,000

December 4, 2009 Eastern Illinois University
Charleston, Illinois
EDU HACK

9,000

A computer was compromised by a virus. That caused the university’s Office of Admissions server to be infected with a number of viruses, including several that could allow an external person to access the server. The incident was discovered during a routine security check. The investigation later determined the breach extended to two other computers with personal data from student files or applications.

 
Information Source:
Dataloss DB
records from this breach used in our total: 9,000

December 4, 2009 MedSolutions
Raleigh, North Carolina
MED DISC

Unknown

For a period of time that has not been clearly defined the name, address, email, and taxpayer ID number (which in some cases is the physician’s Social Security number) for an undetermined number of NC physicians could be viewed on the MedSolutions website. Access to this information apparently was not limited to physicians or physician staff. Based on the information available at the time of this posting, any person with an email address could enter physician names and view the information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

December 4, 2009 University of Nebraska
Omaha, Nebraska
EDU HACK

1,400

A computer in the College of Education and Human Sciences at the Lincoln campus was breached. The security breach was discovered last month at the University of Nebraska involving the names, addresses and Social Security Numbers of 1,400 Hinsdale High School District 86 graduates. The University's investigation revealed the computer had not been adequately secured, allowing unauthorized external access to the computer and its information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,400

December 4, 2009 Eastern Illinois University
Charleston, Illinois
EDU HACK

9,000

A computer was compromised by a virus. That caused the University’s Office of Admissions server to be infected with a number of viruses, including several that could allow an external person to access the server. The incident was discovered during a routine security check. The investigation later determined the breach extended to two other computers with personal data from student files or applications.

 
Information Source:
Dataloss DB
records from this breach used in our total: 9,000

December 4, 2009 Deo B. Colburn Foundation Scholarship
Lake Placid, New York
EDU DISC

341

If you received the Deo B. Colburn scholarship for the 2003-04 academic year, your Social Security number may have been made public. Hundreds of Social Security numbers of former students from all over the northern Adirondacks, including Lake Placid, were released onto the Internet, potentially compromising those people's credit and financial status. Information included names, addresses, academic institutions, the amount of money recieved and Social Security numbers of the scholarship recipients.

 
Information Source:
Dataloss DB
records from this breach used in our total: 341

December 1, 2009 Children's Hospital of Philadelphia
Philadelphia, Pennsylvania
MED PORT

942

A laptop computer containing Social Security Numbers and other personal information was stolen from a car outside an employee's home on Oct. 20. The billing information on the computer was password-protected, but an analysis found it was possible to decode the security controls on the laptop and gain access to the personal information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 942

November 29, 2009 Salem Housing and Community Services
Salem, Oregon
GOV DISC

Unknown

Sloppy handling of confidential records by a state agency in Salem left people's names, Social Security numbers, ages and addresses exposed in an open recycling bin outdoors. In a separate security lapse by another state agency, confidential records with the names and Social Security numbers of former state parks and recreation employees landed in the same recycling bin.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

November 26, 2009 Penn State
University Park, Pennsylvania
EDU HACK

303

A Penn State professor's grade book from 2001 to 2004 that contained 303 students' Social Security numbers, among other personal information, was found to be compromised by a computer virus.

 
Information Source:
Dataloss DB
records from this breach used in our total: 303

November 25, 2009 Aurora St. Luke's Medical Center
Milwaukee, Wisconsin
MED PORT

6,400

6,400 people who were in-patients at St. Luke's are being warned that their name, Social Security number and other information may have landed in the hands of thieves, due to a stolen laptop computer. All of the at-risk individuals were cared for there at some point by a hospitalist, a physician other than the patient's primary care doctor, who works for an independent physician group called Cogent Healthcare. The computer was stolen from a locked office in a secure physician office building that is located adjacent to the hospital; the computer belonged to an employee of Cogent Healthcare of Wisconsin.

 
Information Source:
Dataloss DB
records from this breach used in our total: 6,400

November 24, 2009 ACORN
San Diego, California
BSO DISC

Unknown

Documents that contained personnel information were accidentally thrown away in a dumpster. San Diego staff were doing an office clean-up in preparation for a major 10-station phone bank program being set up in their offices; it appears that included in the piles of garbage being thrown out there were some documents containing private information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

November 23, 2009 Hancock Fabrics
Baldwyn, Mississippi
BSR HACK

At least 140

Bank customers in California, Wisconsin and Missouri are reporting fraudulent ATM withdrawals that are tied to transactions conducted with the Hancock Fabrics retail chain. The Hancock Fabrics store in Napa was the "common thread" among the numerous people who reported credit and debit card fraud. The store had recently replaced its point-of-sale machines. At about the same time, as many as 70 Wisconsin victims reported suspicious ATM withdrawals from their accounts.

 
Information Source:
Dataloss DB
records from this breach used in our total: 140

November 21, 2009 Notre Dame University
Notre Dame, Indiana
EDU DISC

Unknown

Notre Dame is warning university employees to keep an eye on their bank accounts after a security breach.Personal information of some past and current employees - including name, Social Security number and birth date - was accidentally posted onto a public website. The error was corrected and the information removed from the website.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

November 20, 2009 University Medical Center
Las Vegas, Nevada
MED INSD

Unknown

Someone at UMC is selling a compilation of the hospital’s daily registration forms for accident patients. This is confidential information — including names, birth dates, Social Security numbers and injuries. Private information about accident victims treated at University Medical Center has apparently been leaking for months, allegedly so ambulance-chasing attorneys could mine for clients.
UPDATE (4/29/10): A man was indicted today by a federal grand jury in an alleged conspiracy to pay a University Medical Center employee for private information about traffic accident victims that was used to drum up clients. The man was indicted on one count of conspiracy to illegally disclose personal health information, in violation of the Health Insurance Portability and Accountability Act, better known as HIPAA. Between January and November 19, 2009 the man allegedly conspired with people, including a UMC employee, to use hospital "face sheets" to solicit personal injury cases for attorneys. The UMC employee faxed the registration sheets of trauma patients to the man on at least 55 occasions and was paid about $8,000, the indictment said. The U.S. Attorney's press release said theh man has been summoned for a May 14 hearing. If convicted, he faces up to five years in prison and a $250,000 fine.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

November 20, 2009 Johns Hopkins Medicine
Baltimore, Maryland
MED INSD

100

A woman who worked as a patient services coordinator for Johns Hopkins Medicine has been sentenced to 18 months in prison for stealing patient information. Thirty-one-year-old woman of Baltimore was also ordered to pay more than $200,000 in restitution. According to her plea agreement and court documents, from August 2005 to April 2007, the woman provided a conspirator with names, Social Security numbers and other identifying information of more than 100 current and former patients of Johns Hopkins. That information was used to apply for credit.

 
Information Source:
Dataloss DB
records from this breach used in our total: 100

November 19, 2009 TAD Gear
San Francisco, California
BSR HACK

Unknown

action@tadgear.com

TAD Gear recently learned that their database was illegally accessed from an external source, and it appears that some customer data was taken, which may include customer names, contact information and credit card data. The possibility of a security breach came to their attention when certain customers notified them that unauthorized charges had appeared on their credit cards. Upon learning of the potential breach of security, TAD Gear immediately initiated an investigation, and took corrective steps.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

November 19, 2009 FCI USA
Manchester, New Hampshire
BSO PORT

2,000

An employee's laptop was stolen.  The laptop contained a spreadsheet with Social Security numbers, dates of birth and names for 2,000 employees.

 
Information Source:
Databreaches.net
records from this breach used in our total: 2,000

November 18, 2009 Universal American Action Network
St. Petersburg, Pennsylvania
MED DISC

80,000

Thousands of Pennsylvanians are at risk for identity theft because postcards were sent to their homes with their Social Security numbers printed in plain view. The postcards were from the Universal American Action Network, a subsidiary of Universal American Insurance. 80,000 postcards with SSNs on them were sent to Universal clients throughout the country. More than 10,000 were mailed to Medicare participants in Pennsylvania.

 
Information Source:
Dataloss DB
records from this breach used in our total: 80,000

November 18, 2009 Health Net
Shelton, Connecticut
MED PORT

1,500,000

The personal information for almost half a million Connecticut residents could be at risk after a portable disk drive disappeared from Health Net six months ago. Health Net is a regional health plan and the drive included health information, Social Security number and bank account numbers for all 446,000 Connecticut patients, 1.5 million nationally. The information had been compressed, but not encrypted, although a specialized computer program is required to read it. Patients in Arizona, New Jersey and New York were also affected.


UPDATE(1/22/10): Connecticut Attorney General (AG) Richard Blumenthal is suing Health Net of Connecticut for failing to secure private patient medical records and financial information involving 446,000 Connecticut enrollees and promptly notify consumers exposed by the security breach. The AG is seeking a court order blocking Health Net from continued violations of HIPAA by requiring that any protected health information contained on a portable electronic device be encrypted. This case marks the first action by a state attorney general involving violations of HIPAA since the Health Information Technology for Economic and Clinical Health (HITECH) Act, which authorized state attorneys general to enforce HIPAA.

UPDATE(7/7/10): Health Net and the Connecticut AG reached a $250,000 settlement in connection with this incident.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,500,000

November 17, 2009 Nebraska Workers' Compensation Court
Omaha, Nebraska
GOV HACK

Unknown

Someone broke into a server that temporarily held injury reports. Whenever a worker has a job-related injury, a report is filed with the Workers' Compensation Court and the information is temporarily stored on that server. Personal information, including birth dates and Social Security numbers, would have been on the server.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

November 10, 2009 Obsidian Financial Group
Woodbury, New York
BSF INSD

Unknown

A former employee broke into a Woodbury financial services company, photocopied customers' Social Security numbers and bank reference numbers and took the photocopied data with him when he left.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

November 7, 2009 Renal Treatment Centers Southeast, DaVita Inc.
Denver, Colorado
MED STAT

Unknown

Multiple desktop computers were stolen from a facility in Dallas.  The computers contained the names, addresses, Social Security numbers, insurance numbers, and other personal information of patients.

 
Information Source:
PHIPrivacy.net
records from this breach used in our total: 0

November 6, 2009 National Archives and Records Administration
College Park, Maryland
GOV STAT

250,000

The National Archives and Records Administration violated its information security policies by returning failed hard drives from systems containing personally identifiable information of current government employees and military veterans back to vendors. By agency policy, NARA is supposed to destroy the hard drives rather than return them. On two separate occasions the agency sent defective disk drives back to vendors under a maintenance contract, rather than destroying and disposing of them in-house.

UPDATE (1/12/2010):There was a rather large amount of data on this hard drive -- as much as two terabytes of data. The NARA is having to, in effect, do a forensic analysis to try to identify individuals and their information. They had a rolling production of notices to individuals. It had been 26,000, and then their forensic contractor came up with a new group, which was as many as 150,000 names.

UPDATE (1/27/2010) Media stories now put the number of records involved at 250,000.

 
Information Source:
Dataloss DB
records from this breach used in our total: 250,000

November 6, 2009 Chaminade University
Honolulu, Hawaii
EDU DISC

4,500

www.chaminade.edu/infosecure
infosecure@chaminade.edu

Chaminade University inadvertently posted confidential information, including Social Security numbers, of thousands of students, on its Web site for months. An investigation determined the report was placed on obscure -- though publicly accessible -- Web pages because of human error, according to a university news release. The information was accessible for about eight months, although there is no evidence of its use, officials said. The university estimates that personally identifiable data for 4,500 students were in the report. Those affected include undergraduate students who attended the university from 1997 to 2006.

 
Information Source:
Dataloss DB
records from this breach used in our total: 4,500

November 6, 2009 MassMutual
Springfield, Massachusetts
BSF HACK

Unknown

According to MassMutual, a "limited amount" of personal employee information maintained in a database by an outside vendor may have been subject to unauthorized access. The vendor engaged a forensics team to investigate, and at this time they believe that no misuse of the information or fraudulent activity involving the data has occurred. This database does not include client or field representative information; it also did not contain personal Social Security or bank account information, according to the company.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

October 27, 2009 Baptist Hospital East
Loiuisville, Kentucky
MED DISC

350

Hundreds of people in Kentuckiana are worrying about identity theft after their employer accidentally released their Social Security numbers. 350 names and Social Security numbers of hospital employees appear on a list that was circulated in an e-mail.

 
Information Source:
Dataloss DB
records from this breach used in our total: 350

October 27, 2009 FirstMerit Bank
Streetsboro, Ohio
BSF PHYS

Unknown

 Additional locations; Westlake and Elyria, OH

Police in three Ohio cities are investigating the theft of three large storage bins from bank branches earlier this month. The storage bins were used to store paper waiting to be shredded. Three branches of the FirstMerit Bank in Streetsboro, Westlake and Elyria, OH each reported a bin missing beginning on October 7. One of the three bins contained personal documents of bank customers.

 
Information Source:
Media
records from this breach used in our total: 0

October 26, 2009 CalOptima
Orange County, California
MED PORT

68,000

Personally identifiable information on members of CalOptima, a Medicaid managed care plan, may have been compromised after several CDs containing the information went missing. The unencrypted data on the CDs includes member names, home addresses, dates of birth, medical procedure codes, diagnosis codes and member ID numbers, and an unspecified number of Social Security numbers. The discs had been put in a box and sent via certified mail to CalOptima by one of its claims-scanning vendors, according to a statement by the health plan. CalOptima received the external packaging material minus the box of discs.

 
Information Source:
Dataloss DB
records from this breach used in our total: 68,000

October 21, 2009 Bullitt County Public Schools
Shepherdsville, Kentucky
EDU DISC

676

A Bullitt County Public Schools employee accidentally sent an e-mail message to about 1,800 school district workers that included the names and Social Security numbers of 676 district employees. The employees were identified as not having completed the district's 2010 open-enrollment process for insurance, and the e-mail was intended as a reminder to complete the process.

 
Information Source:
Dataloss DB
records from this breach used in our total: 676

October 21, 2009 Roane State Community College
Harriman, Tennessee
EDU PORT

14,783

Hotline (865) 882-4688, (866) 462-7722 ext. 4688

Roane State Community College has announced that the names and Social Security numbers of 9,747 current or former students were on a data storage device stolen from an employee's vehicle, along with 1,194 current/former employees' information. The Social Security numbers alone, with no names, were also stolen for 5,036 additional current or former students. The data was on a 4GB USB drive used for work-related purposes. An employee took it home to do work after hours, and left it in the car. The employee forgot to lock the car doors. The USB drive was stolen along with a personal hand-held device.

 
Information Source:
Dataloss DB
records from this breach used in our total: 14,783

October 20, 2009 ChoicePoint
Alpharetta, Georgia
BSO DISC

13,750

http://www.ftc.gov/opa/2009/10/choicepoint.shtm

ChoicePoint has been fined $275,000 by the U.S. Federal Trade Commission for a data breach that exposed personal information of 13,750 people last year. In April 2008, ChoicePoint turned off a key electronic security tool that it used to monitor access to one of its databases and failed to notice the problem for four months, according to an FTC statement. During that period, unauthorized searches were conducted for 30 days on a ChoicePoint database that contained Social Security numbers and other sensitive information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 13,750

October 17, 2009 Feeney Insurance Agency
Pittsburgh, Pennsylvania
BSF STAT

Unknown

A break in resulted in the theft of an unencrypted computer. The computer contained contact information, Social Security numbers, birth dates, and driver's license numbers.

 
Information Source:
Databreaches.net
records from this breach used in our total: 0

October 15, 2009 Virginia Department of Education
Richmond, Virginia
EDU PORT

103,000

(877) 347-5224

A flash drive containing the personal information of more than 103,000 former adult education students in Virginia was misplaced. The information included names, Social Security numbers and employment and demographic information. The flash drive contained information on all students who finished an adult education course in Virginia from April 2007 through June 2009 or who passed a high school equivalency test between January 2001 and June 2009.

 
Information Source:
Dataloss DB
records from this breach used in our total: 103,000

October 15, 2009 Halifax Health
Daytona Beach, Florida
MED PORT

33,000

A laptop computer from a Halifax Health employee's vehicle in Orange County was stolen -- which might have contained password protected patient information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 33,000

October 15, 2009 PayChoice
Moorestown, New Jersey
BSF HACK

Unknown

Hackers broke into the company's servers and stole customer user names and passwords. The attackers then included that information in e-mails to PayChoice's customers warning them that they needed to download a Web browser plug-in in order to maintain uninterrupted access to onlineemployer.com. The plug-in was instead malicious software designed to steal the victim's user names and passwords.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

October 13, 2009 Pitt County Memorial Hospital
Greenville, North Carolina
MED PORT

1,700

(877) 676-0376

Patient names and Social Security numbers were placed onto a portable computer storage device, used to move the information between different computer systems. Employees have since discovered that USB flashdrive is missing from where it was stored.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,700

October 7, 2009 CLP Skilled Trade Solutions
Palm Springs, Florida
BSO PHYS

Unknown

Boxes full of documents that had the CLP Skilled Trade Solutions logo on them were found in a dumpster in the back of a Newport Café. Some of the information found included Social Security cards, tax papers, driver's licenses and home IDs. Many of the documents were from a company that CLP acquired a few years ago.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

October 6, 2009 BlueCross BlueShield Assn.
Chicago, Illinois
MED PORT

187,000

A file containing identifying information for every physician in the country contracted with a Blues-affiliated insurance plan was on a laptop computer stolen from a BlueCross BlueShield Assn. employee. The file included the name, address, tax identification number and national provider identifier number for about 850,000 doctors. Some 16% to 22% of those physicians listed -- as many as 187,000 -- used their Social Security numbers as a tax ID or NPI number.

 
Information Source:
Dataloss DB
records from this breach used in our total: 187,000

October 5, 2009 U.S. Army Special Forces
Fort Bragg, North Carolina
GOV DISC

463

A recent breach involved a U.S. Army Special Forces document containing the names, Social Security numbers, home phone numbers and home addresses of 463 soldiers. The document also contained names and ages of soldiers' spouses and children. The document was discovered in connection with a Congressional move to address the continuing risk of data leaks on peer-to-peer (P2P) networks. Through its research, the firm, Tiversa, turned up the document among 240 others belonging to federal government agencies and military branches, all sitting on P2P networks.

 
Information Source:
Media
records from this breach used in our total: 463

October 4, 2009 Suffolk Community College
Selden, New York
EDU DISC

300

Suffolk Community College has agreed to pay a company for the next year to monitor the credit of 300 students whose last names and Social Security numbers were mistakenly listed in an attachment to an e-mail sent to those students last month.

 
Information Source:
Dataloss DB
records from this breach used in our total: 300

October 2, 2009 U.S. Military Veterans
Washington, District Of Columbia
GOV PORT

76 Million

The issue involves a defective hard drive the agency sent back to its vendor for repair and recycling without first destroying the data. The hard drive helped power eVetRecs, the system veterans use to request copies of their health records and discharge papers. When the drive failed last year, the agency returned the drive to GMRI, the contractor that sold it to them, for repair. GMRI determined it couldn't be fixed, and ultimately passed it to another firm to be recycled. The drive was part of a RAID array of six drives containing an Oracle database that held detailed records on 76 million veterans, including millions of Social Security numbers dating to 1972, when the military began using individuals' Social Security numbers as their service numbers.

 
Information Source:
Dataloss DB
records from this breach used in our total: 76,000,000

September 28, 2009 Penrose Hospital
Colorado Springs, Colorado
MED PHYS

175

Officials at Penrose Hospital believe someone has stolen the personal information of 175 patients. The missing information consists of names, addresses, phone numbers, Social Security numbers and the reason for the patients' visits. The information was stored on a computer print-out and kept in a binder stored in a cabinet. The print out has gone missing.

 
Information Source:
Dataloss DB
records from this breach used in our total: 175

September 25, 2009 University of North Carolina, Chapel Hill
Chapel Hill, North Carolina
EDU HACK

236,000 (Only 163,000 was added to the total.)

A hacker has infiltrated a computer server housing the personal data of 236,000 women enrolled in a UNC Chapel Hill research study. Among the information exposed: the Social Security numbers of 163,000 participants. The data is part of the Carolina Mammography Registry, a 14-year-old project that compiles and analyzes mammography data submitted by radiologists across North Carolina.

 
Information Source:
Dataloss DB
records from this breach used in our total: 163,000

September 25, 2009 Doctors' offices in Tennessee
Nashville, Tennessee
GOV DISC

Unknown

Doctors' offices in Tennessee have been accidentally sending patient information, including Social Security numbers and medical histories, to an Indiana businessman's fax machine for the past three years. The sensitive medical information was supposed to be sent to the Tennessee Department of Human Services, but the owner of SunRise Solar Inc. in Indiana, says hundreds of confidential medical faxes having been coming to him.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

September 23, 2009 Eastern Kentucky University
Richmond, Kentucky
EDU DISC

5,045

(859) 622-7777, ecert@eku.edu

The names and Social Security numbers of about 5,000 Eastern Kentucky University faculty, staff and student workers were posted inadvertently on the Internet last September, where they have been displayed for a year.

 
Information Source:
Dataloss DB
records from this breach used in our total: 5,045

September 22, 2009 Bernard Madoff Investors
Dallas, Texas
BSF PORT

2,246

More than 2,200 Bernard Madoff investors are learning that some of their personal and financial information has potentially been breached after the theft of a laptop in Dallas. The names, addresses, Social Security numbers and some Madoff account information on 2,246 investors was contained in a computer stolen from the car of an employee of AlixPartners Llp.

 
Information Source:
Dataloss DB
records from this breach used in our total: 2,246

September 22, 2009 Sagebrush Medical Plaza/Kern Medical Center
Bakersfield, California
MED PHYS

31,000

Thousands of patients at a Kern County health clinic have been warned their personal information could have been stolen. A break-in happened at the Sagebrush Medical Plaza in July, and Kern Medical Center officials have notified 31,000 patients to take precautions against possible identity theft. One or more unknown individuals broke into a locked storage area that contained confidential patient information. All patient information has now been moved to a location inside the clinic building.

 
Information Source:
Dataloss DB
records from this breach used in our total: 31,000

September 21, 2009 Rocky Mountain Bank
Pinedale, Wyoming
BSF DISC

1,325

A customer of the Rocky Mountain Bank asked a bank employee to send certain loan statements to a representative of the customer. The employee, however, inadvertently sent the e-mail to the wrong Gmail address. Additionally, the employee had attached a sensitive file to the e-mail that should not have been sent at all. The attachment contained confidential information on 1,325 individual and business customers that included their names, addresses, tax identification or Social Security numbers and loan information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,325

September 17, 2009 Akron Children's Hospital
Akron, Ohio
MED HACK

Unknown

A 38-year-old Avon Lake, Ohio, man is set to plead guilty to federal charges after spyware he allegedly meant to install on the computer of a woman he'd had a relationship with ended up infecting computers at Akron Children's Hospital. He allegedly sent the spyware to the woman's Yahoo e-mail address, hoping that it would give him a way to monitor what she was doing on her PC. But instead, she opened the spyware on a computer in the hospital's pediatric cardiac surgery department, creating a regulatory nightmare for the hospital. Between March 19 and March 28 the spyware sent more than 1,000 screen captures via e-mail. They included details of medical procedures, diagnostic notes and other confidential information relating to 62 hospital patients. He was also able to obtain e-mail and financial records of four other hospital employees as well, the plea agreement states.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

September 16, 2009 Downeast Energy & Building Supply
Brunswick, Maine
BSO HACK

800

Downeast sent a notice after discovering that hackers had broken in and stolen more than $200,000 from the company's online bank account. Sometime prior to September, attackers planted keystroke logging malware on Downeast's computer systems, and stole the credentials the company uses to manage its bank accounts online. Hackers had gained access to the bank account the company uses to let customers pay for fuel with electronic transfers from their checking accounts. Then, on or around Sept. 2, the hackers used that access to initiate a series of sub-$10,000 money transfers out of the company's account to at least 20 individuals around the United States who had no prior business with Downeast Energy. The personal information to which the thieves had access included customers' names, banks and checking account numbers

 
Information Source:
Dataloss DB
records from this breach used in our total: 800

September 14, 2009 University of Florida
Gainesville, Florida
EDU DISC

25

(866) 876-HIPA (4472)

In August, the University's Privacy Office was notified of a privacy breach after the discovery of an unprotected computer file containing 34 names and 25 Social Security numbers. It's believed the personal information belongs to trainers working with the Florida Traffic and Bicycle Safety Education program in 2006. The file was immediately removed.

 
Information Source:
Dataloss DB
records from this breach used in our total: 25

September 14, 2009 Jones General Store/Root of the Hill
Boulder, Colorado
BSR PHYS

Unknown

Boulder police are investigating two burglaries on University Hill that could have compromised some local shoppers' personal and credit card information. A manager for Jones General Store called police to report an overnight break-in and theft of credit card receipts. A short time later, an owner of Root of the Hill, a business in the same building, called officers to report a break-in, theft and extensive vandalism.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

September 7, 2009 School for the Physical City
New York, New York
EDU PHYS

Unknown

Boxes of student records were piled in the street in front of the old home of the School for the Physical City. Some records contained the Social Security numbers, grades, signatures and even psychological reports of former students of the public intermediate high school. The boxes were sitting next to a trash bin filled with old desks and other discarded school supplies. The School for the Physical City moved to a new location over the summer and apparently the records were thrown out with the trash during the relocation.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

September 5, 2009 Mitsubishi Corp.
New York, New York
BSR HACK

52,000

A Mitsubishi Corp. Internet shopping unit lost credit card details on 52,000 customers after its servers were hacked from overseas. The company has informed customers and relevant authorities of the leaks and has suspended the Web site until it can improve the system.

 
Information Source:
Dataloss DB
records from this breach used in our total: 52,000

September 2, 2009 Bluegrass Community and Technical College
Danville, Kentucky
EDU UNKN

100

A file containing the personal information including Social Security numbers of nearly 100 students at the Bluegrass Community and Technical College has been stolen.

 
Information Source:
Dataloss DB
records from this breach used in our total: 100

September 2, 2009 Naval Hospital Pensacola
Pensacola, Florida
MED PORT

38,000

Naval Hospital Pensacola will be notifying thousands of beneficiaries who use its pharmacy services, following the disappearance of a laptop computer. The computer's database contains a registry of 38,000 pharmacy service customers' names, Social Security numbers and dates of birth on all patients that used the pharmacy in the last year. It does not contain any personal health information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 38,000

August 21, 2009 Battleground Urgent Care/Prompt Med
Greensboro, North Carolina
MED PHYS

623

Medical files were found in a dumpster. It seems a third party moving company was hired to transfer the boxes from one warehouse to another. It is unknown at this time how the files ended up in the dumpster. The information in the files contained Social Security numbers, driver's license copies, medical histories, and employers.

 

UPDATE (5/24/10): Prompt Med agreed to pay a $50,000 fine to the state of North Carolina.

 
Information Source:
Dataloss DB
records from this breach used in our total: 623

August 21, 2009 University of Massachusetts
Amherst, Massachusetts
EDU HACK

Unknown

Nearly a year ago, hackers broke into a computer server that contained Social Security numbers and a very limited amount of credit card information for graduates of University of Massachusetts. Hackers gained access to one server on the university's computer system, which held information of students who attended UMass between 1982 and 2002, as well as a few who attended before 1982. A UMass spokesman declined to say how many people's records were exposed, except that it was a large number of undergraduate and graduate students who attended the university during the 20-year period.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

August 20, 2009 Cal State Los Angeles
Los Angeles, California
EDU PORT

600

(800) 883-4029

The theft of two desktop and 12 laptop computers from an office at Cal State Los Angeles is causing identity theft concerns for more than 600 students and faculty members. Someone broke a window in the office of the university's Minority Opportunities in Research program to steal the computer. The computers stolen contained individual names, Social Security numbers and addresses, according to campus.

 
Information Source:
Dataloss DB
records from this breach used in our total: 600

August 15, 2009 Northern Kentucky University
Highland Heights, Kentucky
EDU PORT

200

A Northern Kentucky University employee's laptop computer - which contained personal information about some current and former students -- was stolen from a restricted area. The personal information stored on the employee's computer included Social Security numbers of at least 200 current and former students.

 
Information Source:
Dataloss DB
records from this breach used in our total: 200

August 14, 2009 American Express
New York, New York
BSF INSD

Unknown

Some American Express card members' accounts may have been compromised by an employee's recent theft of data. The former employee has been arrested and the company is investigating how the data was obtained. American Express declined to disclose any more details about the incident. The company has put additional fraud monitoring and protection controls on the accounts at issue.

 
Information Source:
Media
records from this breach used in our total: 0

August 14, 2009 Calhoun Area Career Center
Battle Creek, Michigan
EDU DISC

455

Personal information from 455 students at Calhoun Area Career Center during the 2005-2006 school year was available online for more than three years. The information included names, Social Security numbers, 2006 addresses and telephone numbers, birth dates and school information. There were about 1,000 students at the career center during that time, but an investigation by the Calhoun County Intermediate School district found that information for 455 students was available.

 
Information Source:
Dataloss DB
records from this breach used in our total: 455

August 13, 2009 National Guard Bureau
Arlington, Virginia
GOV PORT

131,000

An Army contractor had a laptop stolen containing personal information on 131,000 soldiers. on the stolen laptop contained personal information on soldiers enrolled in the Army National Guard Bonus and Incentives Program. The data includes names, Social Security numbers, incentive payment amounts and payment dates.

 
Information Source:
Dataloss DB
records from this breach used in our total: 131,000

August 11, 2009 Bank of America Corp.
Charlotte, North Carolina
BSF CARD

Unknown

Charlotte-based BofA (NYSE:BAC) and Citigroup (NYSE:C) each recently issued replacement cards to consumers, telling them that their account numbers may have been compromised. Account information from certain Bank of America debit cards may have been compromised at an undisclosed third-party location. Bank officials are not certain if this is a new breach or a previously disclosed one.

 
Information Source:
Media
records from this breach used in our total: 0

August 11, 2009 Citigroup Inc.
New York, New York
BSF CARD

Unknown

Citigroup (NYSE:C) each recently issued replacement cards to consumers, telling them that their account numbers may have been compromised. Citigroup told credit-card customers in Massachusetts your account number may have been illegally obtained as a result of a merchant database compromise and could be at risk for unauthorized use. Bank officials are not certain if this is a new breach or a previously disclosed one.

 
Information Source:
Media
records from this breach used in our total: 0

August 11, 2009 University of California, Berkeley School of Journalism
Berkeley, California
EDU HACK

493

https://security.berkeley.edu/jschool-info

Campus officials discovered during a computer security check that a hacker had gained access to the journalism school's primary Web server. The server contained much of the same material visible on the public face of the Web site. However, the server also contained a database with Social Security numbers and/or dates of birth belonging to 493 individuals who applied for admission to the journalism school between September 2007 and May 2009.

 
Information Source:
Dataloss DB
records from this breach used in our total: 493

August 4, 2009 New Hampshire Department of Corrections
Laconia, New Hampshire
GOV PHYS

1,000

A 64-page list containing the names and Social Security numbers of about 1,000 employees of the state Department of Corrections ended up under the mattress of a minimum security prisoner. The prison contracts with vendors to shred documents and investigators are trying to find out why documents were not destroyed.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,000

August 3, 2009 National Finance Center
Washington, District Of Columbia
GOV DISC

27,000

An employee with the National Finance Center mistakenly sent an Excel spreadsheet containing the employees' personal information to a co-worker via e-mail in an unencrypted form. The names and Social Security numbers of at least 27,000 Commerce Department employees were exposed.

 
Information Source:
Media
records from this breach used in our total: 27,000

August 1, 2009 Williams Cos. Inc.
Tulsa, Oklahoma
BSO PORT

4,400

A laptop containing personal and compensation information for more than 4,400 current and former employees was stolen from a worker's vehicle. The computer had names, birth dates, Social Security numbers and compensation data for every Williams employee since Jan. 1, 2007.

 
Information Source:
Dataloss DB
records from this breach used in our total: 4,400

July 31, 2009 Jackson Memorial Hospital
Miami, Florida
MED INSD

Unknown

A Miami man was charged with buying confidential patient records from a Jackson Memorial Hospital employee over the past two years, and selling them to a lawyer suspected of soliciting the patients to file personal-injury claims.

 
Information Source:
Media
records from this breach used in our total: 0

July 29, 2009 University of Colorado, Colorado Springs
Colorado Springs, Colorado
EDU PORT

766

The university is notifying nearly 800 students and alumni that some of their personal information may have been on a stolen laptop. That laptop was taken from a professor's home on July 5th after the home was burglarized. The laptop contained class roster information - name, student ID number, e-mail address, graduating class year and grade information - for current and past UCCS students. No financial information was stored on the laptop, but there is a possibility that Social Security numbers may have been involved for students enrolled prior to summer, 2005.

 
Information Source:
Dataloss DB
records from this breach used in our total: 766

July 24, 2009 Hampton Redevelopment and Housing Authority
Hampton, Virginia
NGO PHYS

900

The Social Security numbers and other personal information of nearly 900 people who were banned from public housing in Hampton were accidentally given to a resident who requested the information. A housing authority employee printed a spreadsheet and mailed it but forgot to exclude the personal information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 900

July 24, 2009 Network Solutions
Herndon, Virginia
BSO HACK

573,000

Hackers have broken into Web servers owned by domain registrar and hosting provider Network Solutions, planting rogue code that resulted in the compromise of more than 573,000 debit and credit card accounts over the past three months. Network Solutions discovered that attackers had hacked into Web servers the company uses to provide e-commerce services - a package that includes everything from Web hosting to payment processing -- to at least 4,343 customers, mostly mom-and-pop online stores. The malicious code left behind by the attackers allowed them