Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cybersecurity
    • Database
    • Storage

    662 Major Data Breaches in 2010, More Go Undisclosed: Report

    Written by

    Fahmida Y. Rashid
    Published January 5, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      There were 662 reported data breaches in 2010, of which most involved thefts of Social Security data, according to a report from the Identity Theft Resource Center.

      The actual number is considerably higher because current regulations in the United States don’t require all data breaches to be disclosed, the group said. “Other than breaches reported by the media and a few progressive state Websites, there is little or no information available on many data breach events,” said the ITRC.

      While many organizations disclosed exactly how many customers or actual records were compromised, many didn’t say anything at all. The report found that only half of the reported data breaches included information about the number of records compromised, totaling 16.1 million records. While that is a staggering amount of data, the fact that it reflects only half of the breaches and that the records do not equal the number of people affected underscores “ingrained inaccuracy” in reporting breaches, the ITRC said.

      Honda reported a data breach on Dec. 28 affecting 2.2 million customers but didn’t disclose the total number of records compromised. Thieves stole customer names, e-mail addresses and vehicle identification numbers from an e-mail marketing provider Honda partnered with, but the full magnitude of the breach is still unknown at this point.

      Without a “mandatory national reporting requirement,” many data breaches will continue to be “unreported, or under-reported,” the group said.

      The numbers have fluctuated over the years, as there were 498 breaches reported in the United States in 2009, compared with 657 reported in 2008 and 446 incidents in 2007. The group estimated that more than 222 million records were compromised in 2009.

      In a majority of the data breaches, about 62 percent of reported incidents, Social Security numbers were stolen, according to the report. In contrast, credit card and debit card details were stolen in 26 percent of the reported incidents.

      While mandatory reporting has been helpful in learning about medical data breaches, the Department of Health and Human Services neglected to provide information about the types of records that were compromised, the report said. Of the 214 medical data breaches, “the public has no way” of knowing whether names or Social Security numbers were included in the exposed data, the ITRC said.

      Malicious theft still accounts for more data breaches than mere human error, the report found. About 17 percent of the data breaches were the result of someone hacking the systems, with insider thefts close behind at 15 percent. A fraud report by London-based consultancy Kroll recently said information theft is most likely to be an “inside job” with junior employees as well as senior management the most common perpetrators.

      Paper breaches accounted for nearly a fifth of known breaches, but for about 38 percent of incidents, it was not clear how the thieves accessed the data, according to the report.

      “Breaches happen,” the ITRC wrote, but the government and the business community “need to stop acting like ostriches with their heads in the sand,” with their refusal to publicize the breaches. It’s also “not acceptable” to decide whether or not to notify the public based on the company’s concept of “risk of harm,” as thieves can continue using the stolen data months after the original exposure, the authors said.

      Several states have mandated reporting all breaches, but the law applies only if the state’s residents are affected. In 2010, New Hampshire listed 96 breaches and Maryland had 160, the report found.

      A sightseeing firm CitySights NY reported a database breach that compromised credit card numbers belonging to 110,000 customers on Dec. 9. However, it was required to only notify the attorney generals in Massachusetts and New Hampshire because 2,150 of the affected customers were residents of those two states, which mandate reporting. While TwinAmerica, the parent company, is investigating the breach, there is no other information available about the other affected customers.

      About 29 percent of the total breaches were publicized because of the “mandatory reporting” rules in some states, the report said. “Mandatory reporting is on the horizon. It will be demanded either by consumer lobbying or legislation,” the group said.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.