Every prisoner in UK victim of data breach

The personal information on thousands of criminals in England and Wales has been lost on a USB drive.

Although the data had been encrypted in a database, it was not encrypted when moved to the mobile storage device.

The unencrypted details were lost by a private firm, PA Consulting, during what it termed “processing.”

The data includes information on about 10,000 prolific offenders, as well as the names, birth dates and some release information of all 84,000 prisoners in England and Wales -- and a further 33,000 records from the police national computer.

PA Consulting held the data as part of a contract to work on a database of "prolific and priority offenders" called JTrack. A spokesman for the company declined to comment on the data loss.

“On the face of it, this appears to be a very serious breach," Frances Anderson, a partner at UK law firm Cobbetts, said. "Not just because of its massive scale, but due to the extremely sensitive nature of the information.”

The dangers of allowing employees to use USB drives in confidential data environments have been widely publicized for some time, with many organizations going so far as to glue USB ports shut to prevent their use.

David Smith, deputy commissioner for the Information Commissioner's Office, said the news was “deeply worrying."
 
"The data loss by a Home Office contractor demonstrates that personal information can be a toxic liability if it is not handled properly and reinforces the need for data protection to be taken seriously at all levels,” he said. 

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.