This incident has 0 proposed changes. Know of details that have changed? Submit them Showing Incident 1239 To_xml

SUMMARY

Misconfigured server allowed a user to see 6 SSNs and other info which should not have been accessible
Records Unknown
Record Types SSN NAA
Breach Type Web
Data Family Electronic
Source Inside - Accidental
Organization New York State Comptrollers Office
Other Affected/Involved Organizations None
Lawsuit? NO/UNKNOWN
Data Recovered? NO/UNKNOWN
Arrest? NO/UNKNOWN
Submitted By: cwalsh

TIMELINE

DateEvent
None. Add Data Incident Occurred
2006-10-23 Incident Discovered By Organization
2006-10-27 Organization Reports Incident
None. Add Data Organization Mails Notifications
None. Add Data Records Recovered
None. Add Data Lawsuit Filed
None. Add Data Arrest Made

SIMILAR INCIDENTS

recordsdateorganizations
0 2001-05-25 Health.org
0 2006-04-10 Broward Co. Records Division FL
0 2006-06-26 King County Elections
0 2006-12-03 City of Grand Prairie Texas

MAP OF INCIDENT LOCATION

Address: New York, NY, USA
Have a better address for this incident? Suggest it!

suggest a new reference

REFERENCES

suggest a new attachment

ATTACHMENTS

PRIMARY SOURCES

Primary Source ID: 514

add details to this primary source Description
Documents submitted to NY state Consumer Protection Board regarding exposure of 6 names and SSNs to an employer legitimately using a NYS retirement-related web site, where the names and SSNs should have been visible only to two other employers.
FilenameSourceResearcher Incident IDs
NYSComptrol-20061023.PDFNew York State Consumer Protection Boardcwalsh <a href='/incidents/show/1239'>1239</a>
RecordsFile DateUploadedUpdated
6 2006-10-27 2008-12-04 23 Sep 16:30
Excerpt
514

` i .- g · IG'!]. it - , vga 0:-**;; 110 State Street 111A ”“7“77' 7"`T7 i'7iT""`i"’“"—”—‘ :TiT“"A1bzmyir`v’ewe1’orke12e236··m~· e—~~—~— ——-·· W- ·· ----— -4- -4 — —- - Phone.- (518) 474-601 1...

Click here for the Full Details | Download Raw PDF

Primary Source ID: 391

add details to this primary source Description
State of New York, Office of the State Comptroller, due to a programming error, caused the name and Social Security number of six employees of two other employers to be visible to arbitrary users of the web site via the Internet.
FilenameSourceResearcher Incident IDs
NYSComptrol-200610230001.PDFNew York State Consumer Protection Boardcwalsh <a href='/incidents/show/1239'>1239</a>
RecordsFile DateUploadedUpdated
6 2006-10-27 2008-12-04 23 Sep 15:59
Excerpt
391

` "t)15·°' l i . , _ . ALAN G. Haves! . .. 1 10 STATE sriuzizr A · cotvrpraottsn 111 ALBANY, new voax 12236 ¤·l tj 1 if STATE OF New YORK OFFICE OF THE STATE COMPTROLLER p A October 27, 2006...

Click here for the Full Details | Download Raw PDF

COMMENTS

New Comment

captcha
Are you human?

Sponsored By: Credant_200x51 Rbs Tenable Zecurion
Use of the DataLossDB, and its exports, RSS feeds, reports, or other materials produced on this site by the Open Security Foundation requires authorization and potential licensing arrangements. For more information, please e-mail officers@opensecurityfoundation.org with a brief summary of how you would like to use this information; product, service, research, etc.
© 2005 - 2012, Open Security Foundation, All Rights Reserved.