Every prisoner in UK victim of data breach

The personal information on thousands of criminals in England and Wales has been lost on a USB drive.

Although the data had been encrypted in a database, it was not encrypted when moved to the mobile storage device.

The unencrypted details were lost by a private firm, PA Consulting, during what it termed “processing.”

The data includes information on about 10,000 prolific offenders, as well as the names, birth dates and some release information of all 84,000 prisoners in England and Wales -- and a further 33,000 records from the police national computer.

PA Consulting held the data as part of a contract to work on a database of "prolific and priority offenders" called JTrack. A spokesman for the company declined to comment on the data loss.

“On the face of it, this appears to be a very serious breach," Frances Anderson, a partner at UK law firm Cobbetts, said. "Not just because of its massive scale, but due to the extremely sensitive nature of the information.”

The dangers of allowing employees to use USB drives in confidential data environments have been widely publicized for some time, with many organizations going so far as to glue USB ports shut to prevent their use.

David Smith, deputy commissioner for the Information Commissioner's Office, said the news was “deeply worrying."
 
"The data loss by a Home Office contractor demonstrates that personal information can be a toxic liability if it is not handled properly and reinforces the need for data protection to be taken seriously at all levels,” he said. 

Sign up to our newsletters

More in News

Bitcoin mining botnet has become one of the most prevalent cyber threats

Fortinet researchers have tracked 100,000 new ZeroAccess trojan infections per week, making the botnet very lucrative to its owners.

House Intelligence Committee OKs amended version of controversial CISPA

House Intelligence Committee OKs amended version of controversial ...

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

Judge rules hospital can ask ISP for help ...

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.