Shostack + Friends Blog Archive


Laptop theft

The Register has been on Ernst & Young’s case. The latest Exclusive! talks about a laptop stolen in early January, and how we now know it had info on BP employees, along with those from IBM and others.
The article also observes that:

It’s difficult to obtain an exact figure on how many people have been affected by Ernst & Young’s security lapse given that it won’t say anything on the subject.

The number, as we reported 10 days ago, is 84,000.
The figure was reported to the New York State Consumer Protection Board by E&Y on February 10, 2006.
The laptop contained, according to E&Y’s report to New York officials:

files relating to a number of Ernst & Young corporate clients, and that these files contained various personal information relating to employees of those clients. [Ernst & Young] also determined that the laptop contained a separate file with the names and Social Security numbers of individuals for whom Ernst & Young provided services.

That letter goes on to explain that E&Y is working with their corporate clients to notify the relevant individuals impacted by the disclosure of the corporate files, and is itself notifying the individuals whose information was in the other file.
This may explain why, in an earlier report to NY’s Consumer Protection Board, AG’s office, and the Office of Cyber Security and Critical Infrastructure Coordination, Goldman Sachs described a loss of info by E&Y which exposed info on about 9000 Goldman employees and dependents. It seems that this loss was due to the same laptop theft.
IANAL, so I can’t say whether the legal responsibility to notify those potentially affected lies with E&Y’s corporate clients or with E&Y. Perhaps the shortage of information on this has something to do with that aspect of this particular incident.

One comment on "Laptop theft"

  • Celeste Bernardo says:

    My name is Celeste Bernardo. I bought my laptop before Christmas of last year 2005. it was brand new laptop, but then few days after that my laptop got stolen from my car. I would like to find out if there is any way that you can helping me locate my laptop?. I have my receipt here with me and my network wireless ‘gear’ bad code and the receipt of my purchase here with me. Please let me know on how you caln help me locate my laptop.
    My email address is included with this comments. I look forward to hearing from and hopefully you are able to contact very soon.
    Thank you for time and consider my need of relocate my laptop…..
    Celeste Bernardo

Comments are closed.