A quick Google search of Patricia O. (O My God I've Lost Customer's Social Security Numbers) Baker came up with a similar situation to my recent SSN loss.
Click here to read the notice at Datalossdb.
Seems Chase notified the state of New York in late 2006 that a tape with customer's SSN could not be found at a vendor's off-site facility. Want to bet it's the same vendor as my loss? Want to bet that Chase didn't change any policy from 2006 to 2009?
Of interest in the 2006 notification, Chase offered $10,000 in identity theft protection to each victim. Unfortunately for the 34,266 New York residents affected, the footnote to the letter to the NY state attorney general says that the theft protection is not available to NY residents.
Showing posts with label SSN. Show all posts
Showing posts with label SSN. Show all posts
Sunday, August 16, 2009
Saturday, August 8, 2009
Chase'ing My SSN Away
When comparing Citi and JPMorganChase (Chase bank), it's not hard to see how Chase is doing better. Citi's in the hole for $45 billion of taxpayer money and Chase returned the TARP funds it never wanted in the first place. Citi's got a revolving management team and board while Jamie Dimon has led Chase for five years. Their stock tells the story as Chase (JPM) is up 17% over roughly five years since Dimon joined and Citi is down 91%. Click here for an interactive chart.
Unfortunately, my belief in Chase's attention to detail and looking out for its customers was smacked by this letter I received yesterday. In short, Chase backs up its customer information on a tape and uses a vendor to store that tape. Chase's vendor can't find the tape that includes my name, address and social security number (SSN).
While Chase might be correct that the tape can "be read only with special equipment and software", let's not kid ourselves that this is rocket science. The larger question is why Chase's data wasn't encrypted so that even if it was able to be read (which it can be) that the data would be useless without the key to un-encrypt the data.
It's not even six weeks since I was Schwab'd by Chuck who's team also lost my SSN and personal information. Like Schwab, Chase is offering to monitor my identity with an Experian product. That's standard. Their offering to monitor it with their own branded product (Chase Identity Protection) that they hope I will like and will pay for in the future. That's Priceless. Leave it to Chase to turn an internal control and process f-up into a marketing and revenue opportunity.
Chase's letter is signed by Patricia O. Baker. That's 'O' as in O' My God, I just lost customer Social Security Numbers.
Perhaps now's the time to short Chase's stock as they've once again made the Companies Acting Badly list, this time by losing my Social Security Number and ID information. Or perhaps it's time for Chase to get a new CIO who can enforce protocols with a data storage vendor. Or perhaps it's time for Chase to get a new data storage vendor. Who's in charge of this at Chase?
JPMorganChase joins Charles Schwab, IBM, Intuit and BNY Mellon as Companies Acting Badly for managing to lose my social security number and other personal information.
Unfortunately, my belief in Chase's attention to detail and looking out for its customers was smacked by this letter I received yesterday. In short, Chase backs up its customer information on a tape and uses a vendor to store that tape. Chase's vendor can't find the tape that includes my name, address and social security number (SSN).
While Chase might be correct that the tape can "be read only with special equipment and software", let's not kid ourselves that this is rocket science. The larger question is why Chase's data wasn't encrypted so that even if it was able to be read (which it can be) that the data would be useless without the key to un-encrypt the data.
It's not even six weeks since I was Schwab'd by Chuck who's team also lost my SSN and personal information. Like Schwab, Chase is offering to monitor my identity with an Experian product. That's standard. Their offering to monitor it with their own branded product (Chase Identity Protection) that they hope I will like and will pay for in the future. That's Priceless. Leave it to Chase to turn an internal control and process f-up into a marketing and revenue opportunity.
Chase's letter is signed by Patricia O. Baker. That's 'O' as in O' My God, I just lost customer Social Security Numbers.
Perhaps now's the time to short Chase's stock as they've once again made the Companies Acting Badly list, this time by losing my Social Security Number and ID information. Or perhaps it's time for Chase to get a new CIO who can enforce protocols with a data storage vendor. Or perhaps it's time for Chase to get a new data storage vendor. Who's in charge of this at Chase?
JPMorganChase joins Charles Schwab, IBM, Intuit and BNY Mellon as Companies Acting Badly for managing to lose my social security number and other personal information.
Tuesday, June 30, 2009
Chuck I've Been Schwab'd
Last week I received the following letter from Charles Schwab that they had lost a computer that contained unencrypted personal information including my name, social security number and account number. Given that I've got a few accounts at Schwab all associated with my name and SSN, let's assume they lost them all.
Click the images to see the letter.
How nuts is this? Another year and another supposedly high tech firm can't handle basic technology protocols like storing customer information on a server in a data center and if they need to store it on a laptop or desktop, then encrypt it so it can't be read.
And Schwab's letter? This obviously wasn't written by the folks who do the Talk to Chuck campaign.
"It doesn't appear that the theft of this computer hard drive was intended for fraudulent purposes or identity theft".
Really? How do the braniacs at Schwab know the robber's intent? Have they spoken to them? Schwab can't monitor my credit reports so how would Chuck know if someone now had fraudulently taken out credit in my name? Even if Schwab could monitor my credit (which it can't) how would they know if a new credit card was taken out by me or fraudulently by someone who had stolen my SSN off their computer? Schwab can't and this line is useless and insulting.
Perhaps Schwab hired the same brilliant lawyers who helped BNY Mellon write that "we have no reason to believe your information has been or will be accessed or misused".
I checked Schwab's site to find their policy on personal information and found that they may have violated their own rules (click here to see their policy). According to Schwab, they "take steps to protect you from identity theft", including:
I tried calling the phone number Schwab gave in the letter and it was evident that this person and their supervisor were reading a script. In short, they didn't know when the theft occurred but could tell me it was in 2009 and they offered me a key fob random number generator to make my sign on to Schwab more complicated.
E*Trade and TD Ameritrade are offering me 25,000 frequent flyer miles to move my accounts. Will they have any better security over my personal info?
Charles Schwab joins IBM, Intuit and BNY Mellon as Companies Acting Badly for managing to lose my social security number and other personal information.
Click the images to see the letter.
How nuts is this? Another year and another supposedly high tech firm can't handle basic technology protocols like storing customer information on a server in a data center and if they need to store it on a laptop or desktop, then encrypt it so it can't be read.
And Schwab's letter? This obviously wasn't written by the folks who do the Talk to Chuck campaign.
- "You may have been impacted..."
No. I was impacted. Not may have been impacted. Someone has my personal info and it's Schwab's fault. I now have to monitor my credit reports once again. - "... a recent data incident."
No. This was a process incident. It was a control incident. It was a security incident. Data was involved. But it was not a data incident.
"It doesn't appear that the theft of this computer hard drive was intended for fraudulent purposes or identity theft".
Really? How do the braniacs at Schwab know the robber's intent? Have they spoken to them? Schwab can't monitor my credit reports so how would Chuck know if someone now had fraudulently taken out credit in my name? Even if Schwab could monitor my credit (which it can't) how would they know if a new credit card was taken out by me or fraudulently by someone who had stolen my SSN off their computer? Schwab can't and this line is useless and insulting.
Perhaps Schwab hired the same brilliant lawyers who helped BNY Mellon write that "we have no reason to believe your information has been or will be accessed or misused".
I checked Schwab's site to find their policy on personal information and found that they may have violated their own rules (click here to see their policy). According to Schwab, they "take steps to protect you from identity theft", including:
- using firewalls and encryption technology to protect personal information on our computer systems;
- training our employees on privacy and security to properly handle personal information about you.
I tried calling the phone number Schwab gave in the letter and it was evident that this person and their supervisor were reading a script. In short, they didn't know when the theft occurred but could tell me it was in 2009 and they offered me a key fob random number generator to make my sign on to Schwab more complicated.
E*Trade and TD Ameritrade are offering me 25,000 frequent flyer miles to move my accounts. Will they have any better security over my personal info?
Charles Schwab joins IBM, Intuit and BNY Mellon as Companies Acting Badly for managing to lose my social security number and other personal information.
Subscribe to:
Posts (Atom)


