Social Security agency leaks thousands of SSNs every year, report says
- 15 October, 2011 03:57
- Comments
The Social Security Administration (SSA) puts thousands of Americans at risk of identity theft each year by accidentally leaking their Social Security Numbers, names and dates of birth, according to an investigative report by the Scripps Howard New Service .
The leaks are the result of keying errors made by SSA employees when entering data into the agency's Death Master File, a database containing the records of 90 million deceased Americans.
Since 1980, when the SSA first started making the file publicly available, more than 400,000 SSNs belonging to living Americans may have been inadvertently published in the Death Master File as a result of the errors, according to the report.
In most cases, the victims of the inadvertent leaks are not informed of the breach. Many discover the error only after they ran into problems such as having their bank accounts frozen, job interviews refused or having their credit, mortgage or student loan applications declined, Scripps Howard reported.
The SSA did not immediately respond to a Computerworld request for comment.
For its report, Scripps Howard reviewed three files from the Death Master File and discovered 31,931 living Americans listed erroneously in them. Dozens of those who were incorrectly listed were later contacted by the news service. None said they'd been informed of the breach by the SSA.
The SSA has admitted that it inadvertently lists about 14,000 living people in the Death Master File each year, Scripps Howard said. Using that estimate, more than 400,000 records have been released since 1980, the report noted.
In the report, Scripps Howard quotes SSA Commissioner Michael Astrue, who spoke to members of Congress about the issue last month. Astrue said that the SSA takes prompt action to correct any errors it discovers. Any breach involving the accidental leakage of SSNs is also promptly reported to the U.S. Computer Emergency Response Team.
Astrue said the SSA has so far found no instance of fraud or misuse as a result of the inadvertent exposure.
Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan or subscribe to Jaikumar's RSS feed . His e-mail address is jvijayan@computerworld.com .
Read more about privacy in Computerworld's Privacy Topic Center.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Apple aims iPads at High Schools
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Reconciling Datacenter consolidation and security: It starts with an integrated approach
There is no question that datacenter consolidation has gone mainstream. A recent IDG Research survey of IT managers found that three out of four organizations are in the midst of, or just completing, consolidation of multiple applications or systems onto a smaller number of servers. Improving performance and availability was the key driver of consolidation efforts for 85% of those surveyed. -
CISO Guide to Next Generation Threats - Combating Advanced Malware, Zero-Day and Targeted APT Attacks
Over 95% of businesses unknowingly host compromised endpoints, despite their use of firewalls, intrusion prevention systems (IPS), antivirus and Web gateways.1 Today’s attacks look new and unknown to signature-based tools because the attacks employ advanced malware and zero-day vulnerabilities. To regain the upper hand against next-generation attacks, enterprises must turn to true next-generation protection: signature-less, proactive and real time. Read on. -
NetScaler 2048-bit SSL performance advantage
Citrix® NetScaler® provides advanced layer 4-7 traffic management and load balancing. Like other leading Application Delivery Controllers (ADCs), NetScaler can offload computationally expensive SSL processing responsibilities from web and application servers to speed the delivery of SSL-protected applications. Learn more.
-
Microsoft Office
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 for Dummies
-
Windows 7 for Seniors for Dummies®
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
Windows 7 for Dummies®
-
Teach Yourself Visually Windows 7








Comments
Post new comment