Electronic Privacy Information Center deputy counsel Chris Hoofnagle told TechNewsWorld that there is an increased risk for information exposure, especially as a result of the war-on-terrorism mandate to collect information.
Success is just a matter of knowing the right "secrets." Download the free eBook, "The Edge of Success: 9 Building Blocks to Double Your Sales." You will discover the fastest, most effective ways to grow your business and still have time to live your life.
Consumer information held by Acxiom (Nasdaq: ACXM), one of the largest collectors and processors of such data, was reportedly accessed and downloaded recently by an intruder who broke into the company's massive database.
Law enforcement officials, who notified Acxiom of the breach, have arrested a suspect in Ohio. Acxiom claims the unlawful access to files containing personal information did not result in theft or other harm to any individuals. However, security and privacy experts said that as large consumer databases become more valuable, they are more likely to be targeted by attackers.
Today, there are legislative and other pressures forcing public disclosure of data breaches that in the past might have been kept quiet. "I think we're going to be hearing about it a lot more –- an awful lot more," Forrester research director Michael Rasmussen told TechNewsWorld. "The climate's changing now, and there's a huge amount of liability pressure."
Unlawful Access
In a security alert on its Web site, Acxiom said the unauthorized access occurred as information was being exchanged with Acxiom clients -- which include IBM (NYSE: IBM), Microsoft (Nasdaq: MSFT), AT&T, General Electric, Bank of America and Sears -- over a single File Transfer Protocol (FTP) server.
"The files that were accessed contained a wide variety of client information, some of which was personally identifiable and some of which was not," the alert said. "Most of the data was nonsensitive, and some of the data was encrypted."
Acxiom spokesperson Dale Ingram told TechNewsWorld that the access involved one of the company's thousands of servers and that the Little Rock, Arkansas-based company was made aware of the breach by law enforcement officials.
Keeping Track
Electronic Privacy Information Center deputy counsel Chris Hoofnagle told TechNewsWorld that there is an increased risk for information exposure, especially as a result of the war-on-terrorism mandate to collect information.
"The risk is heightened now that Acxiom, ChoicePoint and other database aggregators are focused on selling personal information to the government," Hoofnagle said. "This data, of course, is going to become more attractive to hackers."
He said if law enforcement tipped off Acxiom to the breach, it might indicate the company has either no intrusion detection or poor-quality intrusion detection, which Hoofnagle said is a problem.
Closing Off Holes, Consumers
Acxiom's Ingram said the company has conducted a "quick review" and has eliminated the vulnerability that allowed access to the information. Acxiom also is working with law enforcement as part of an ongoing investigation.
While the company claims "only a small portion of all the information Acxiom processes for our clients was accessed," Acxiom is not informing consumers whether or not their information was among the exposed data.
"Because the information belongs to Acxiom's clients, we are not currently authorized to answer questions from individuals about whether their information was accessed in the breach," said the security alert. "We are working with our clients to assess the impact on their customers."
Liability Looms Large
Hoofnagle, who said companies like Acxiom are finding a new market for consumer information with the government, said a California database security law that took effect in July represents a larger push for disclosure of such lapses.
"As a result, you're going to see more notices to the public about security breaches," he said. "That is going to foster concern over the security of these databases."
Forrester's Rasmussen agreed, referring to the California law -- introduced at the federal level -- and Federal Trade Commission efforts to force disclosure.
"There's just a lot of pressure from a lot of different angles," Rasmussen said. "Companies are going to protect themselves and do the right thing. I'm sure Acxiom is going to be changing its privacy policy."
IBM's Future Strategy: Grid Computing Everywhere August 06, 2003
IBM recently installed a grid system at Charles Schwab. The system reduced the processing time on a wealth-management application from more than 4 minutes to 15 seconds.
How Much PC Does IT Really Need? August 05, 2003
A steady influx of laptops into IT departments might boost PC makers' revenues even in the absence of widespread upgrades -- and it might even be a leading indicator of an overall move toward the bleeding edge.
A Brilliant Future for the Smart Home August 04, 2003
Two years ago, South Korea's LG Electronics made big news with an Internet-ready refrigerator designed to give users the ability to surf the Web and even make telephone calls.
Heavy-Duty Database Showdown: The Microsoft Challenge July 30, 2003
Seventy percent of the features and functionality in RDBMS programs are not used by businesses, making 9i and DB2 seem like overkill in many instances, Forrester senior analyst Noel Yuhanna told the E-Commerce Times.
The Heavy-Duty Database Showdown: Oracle vs. IBM July 29, 2003
Oracle 9i is generally considered to be the most robust RDBMS software available, Gartner Dataquest principal analyst Colleen Graham told the E-Commerce Times, but it is also considered to be the most expensive.
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.