Missing unencrypted thumb drive impacts 19,000 Colorado workers

Share this article:

Almost 19,000 current and former Colorado state workers may have had personal information compromised after a worker lost an unencrypted thumb drive containing the data.

How many victims? 18,800. 

What type of personal information? Names, addresses and Social Security numbers are among the information.

What happened? A state employee lost the drive containing data on 8,000 current employees and 10,800 former workers while transporting it between work locations.

What was the response? Colorado officials worked quickly to find out what type of information was stored on the drive so they could send out notification letters to all impacted workers. The Office of Information Security is continuing efforts to recover the thumb drive. Procedures and practices are being reviewed and revised to minimize the risk of recurrence.

Details: The drive was discovered to be missing in late November. Employees from multiple state agencies were involved.

Quote: “We have strict policy for the state about encryption,” Tauna Lockhart, a spokesperson with the Governor's Office of Information Technology, said. “That said, this employee did not follow stated protocol and has been disciplined.”

Source: idradar.com, “18,800 Colorado State Workers Wrapped Up In Data Breach,” Dec. 16, 2013

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

RECENT COMMENTS

FOLLOW US

More in The Data Breach Blog

Malware on Breyer Horses website for about 18 months, payment card data ...

Malware installed on the computer server hosting the Breyer Horses website may have compromised personal information for people who made purchases between March 31, 2013 and Oct. 6.

Transcript website flaw exposed personal data on 98k users

NeedMyTranscripts.com expose users' names, addresses and dates of birth, among other information, due to a site flaw that one user discovered.

Sourcebooks payment card breach impacts more than 5,000 customers

More than 5,000 customers had personal information stolen, but roughly 9,000 notification letters were sent out as a precautionary measure.