FTC warns firms, organizations of widespread data breach

February 22, 2010
The US Federal Trade Commission (FTC) building in Washington, DC. The US Federal Trade Commission (FTC) said Monday it has notified nearly 100 companies and organizations of data breaches involving personal information about customers or employees.

The US Federal Trade Commission (FTC) said Monday it has notified nearly 100 companies and organizations of data breaches involving personal information about customers or employees.

The FTC declined to identify the companies or organizations involved, but said they were both "private and public entities, including schools and local governments."

The companies and organizations ranged in size from "businesses with as few as eight employees to publicly held corporations employing tens of thousands," the FTC said in a statement.

It said sensitive data about customers and employees had been shared from the computer networks of the companies and organizations and made available on Internet peer-to-peer (P2P) file-sharing networks.

The information was accessible to "any users of those networks, who could use it to commit identity theft or fraud," the FTC said.

"Unfortunately, companies and institutions of all sizes are vulnerable to serious P2P-related breaches, placing consumers' sensitive information at risk," FTC chairman Jon Leibowitz said.

"For example, we found health-related information, financial records, and driver's license and social security numbers -- the kind of information that could lead to identity theft," Leibowitz said.

"Companies should take a hard look at their systems to ensure that there are no unauthorized P2P file-sharing programs and that authorized programs are properly configured and secure," he said.

"Just as important, companies that distribute P2P programs, for their part, should ensure that their software design does not contribute to inadvertent file sharing," he added.

P2P file-sharing software is used in a variety of ways including for playing games, making online telephone calls or sharing music, video and documents.

Chris King, director of product marketing at California-based security firm Palo Alto Networks, said the sharing of sensitive company information over such P2P services as BitTorrent or Limewire was indeed often unintentional.

"People are not stealing identities, medical records, financial records and sticking them on these networks," King told AFP.

"In a lot of cases what's happening is someone who works for one of these organizations... will install an application on their laptop or desktop so they can get to music or movies or something like that," he said.

"Next thing you know a whole bunch of medical records are in the wild," he said. "It's not necessarily malicious from the get-go."

King said a study had found that P2P programs have a nearly 90 percent penetration rate in "enterprise organizations -- folks that have firewalls and all kinds of security mechanisms in place."

The FTC, in the notification letters to the companies and organizations, urged them to review their security practices "to ensure that they are reasonable, appropriate, and in compliance with the law."

"It is your responsibility to protect such information from unauthorized access, including taking steps to control the use of P2P software on your own networks and those of your service providers," the letters stated.

Explore further: Veoh runs public tests of peer-share video

Related Stories

FTC warns of explicit content in virtual worlds

December 10, 2009

The US consumer protection agency warned parents Thursday that children can easily bypass age requirements in virtual worlds and access violent or sexually explicit content.

Recommended for you

Team develops targeted drug delivery to lung

September 2, 2015

Researchers from Columbia Engineering and Columbia University Medical Center (CUMC) have developed a new method that can target delivery of very small volumes of drugs into the lung. Their approach, in which micro-liters ...

Not another new phone! But Nextbit's Robin is smarter

September 2, 2015

San Francisco-based Nextbit wants you to meet Robin, which they consider as the smarter smartphone. Their premise is that no one is making a smart smartphone; when you get so big it's hard to see the forest through the trees. ...

Team creates functional ultrathin solar cells

August 27, 2015

(Phys.org)—A team of researchers with Johannes Kepler University Linz in Austria has developed an ultrathin solar cell for use in lightweight and flexible applications. In their paper published in the journal Nature Materials, ...

Magnetic fields provide a new way to communicate wirelessly

September 1, 2015

Electrical engineers at the University of California, San Diego demonstrated a new wireless communication technique that works by sending magnetic signals through the human body. The new technology could offer a lower power ...

0 comments

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.