Interior loses CD with personal data for 7,500 federal employees

Department's shared services center says data encrypted, password-protected

A compact disc that contains personally identifiable information for about 7,500 federal employees has been reported lost by the Interior Department’s shared services center.

The incident occurred on or about May 26, when a procurement specialist at Interior’s National Business Center in Denver reported that the CD could not be located. The disc was sent to the business center by a third-party service provider, according to a June 10 news release.

The CD has not been found, Terri Raines, a spokeswoman for the National Business Center, said today.

The data on the CD was encrypted and password-protected, and was used to support billings from the vendor, Raines said. The disc was presumed to be lost in the center’s secured, restricted-access area, she added.

“National Business Center believes the risk of someone gaining malicious access to the data is low,” the business center said in the news release.

Interior has followed breach notification procedures to contact the federal employees involved, who work for a number of federal agencies, including Interior, according to Raines.

“We also are reviewing processes so that this does not happen again,” Raines said. The business center has changed its procedures so that this type of data is received only through secure network connections in the future, rather than from a CD.

Because the business center is a shared service center, the CD contained data for federal employees from multiple agencies, including Interior.

All persons affected by the breach will receive a letter of advisement through the U.S. Postal Service alerting them to the breach. The business center has established an Incident call center to provide information and answer questions.

 

About the Author

Alice Lipowicz is a staff writer covering government 2.0, homeland security and other IT policies for Federal Computer Week.

2014 Rising Star Awards

Help us find the next generation of leaders in federal IT.

Reader comments

Wed, Jun 30, 2010 Doug B California

The director of this shared services center was fired several months ago. Obviously that was not a wake up call so I think the CIO and security officer should be next!! I am a federal employee and not even associated with Interior, but my information could have been included in that breach. So because of them I now have to watch my credit report for the next 5 years? Thanks for protecting my data!!

Wed, Jun 30, 2010

The National Business Center is such a dysfunctional organization. Keep in mind this is the same organization whose director was just fired, escorted out of the building, and is currently under investigation. The entire Interior department laughs at the lack of information security at this office. And by the way, as a system administrator, the chances of that CD being encrypted and password protected are very, very slim. And once an attacker has the encrypted information, they have all day to use one of the hundreds of free tools on the internet to break that encryption, its not rocket science!!

Tue, Jun 22, 2010 Geoff

Key word, "Encrypted"... It isn't now, nor will it likely ever be cracked open by a third party. That's what encryption at DOD standards gives us... Confidence that "lost" things on CDs remain inaccessible.

Tue, Jun 22, 2010

As a postal employee, my first reaction when my husband received this announcement was that those responsible obviously are not taking this seriously. They sent this important information "presort standard", the lowest class of mail. This is what most people call "junk mail" and is not forwardable, so anyone who is having mail forwarded would not receive it. It would be thrown out. Also, how many of you reading this actually read your junk mail or do you just round file it?

Mon, Jun 21, 2010

"data on the CD was encrypted and password-protected"
"Interior has followed breach notification procedures to contact the federal employees involved"
In other words, it sounds like the agency has learned lessons from VA on how to properly care for PII data. The article doesn't state that the PII is now in the hands of people intending to perform malice. This is exactly why encryption and password-protection procedures are in place - to protect the data when it gets lost. If objects NEVER got lost it would hardly be worth encrypting and password protecting it.

Show All Comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above