HMRC loses personal data for 25 million people in the post
UK HM Revenue & Customs has lost two CDs carrying names, addresses and bank details for the entire UK child benefit database
LONDON – The chairman of the UK’s HM Revenue & Customs (HMRC), Paul Gray, resigned yesterday (November 20) after it was announced HMRC had lost the names, addresses, bank sort codes and account numbers for 25 million people.
Chancellor of the exchequer Alastair Darling – already under fire over his £24 billion Northern Rock rescue – admitted to parliament yesterday that the loss occurred over a month ago and that the government had known about the disks lost in the post since November 10.
It emerged that a junior employee sent the entire child benefit database on two CDs to the National Audit Office against all security protocol – they were then lost in the post.
UK police are making inquiries at HMRC, which does not believe the details have fallen into the hands of identity thieves. A single set of personal address and bank details could sell for £10 to £50 on the black market.
Gray – until his resignation one of the UK’s best-paid civil servants – might not have prevented political repercussions with his decision to take personal responsibility.
The impact of such lapses of security has been highlighted in recent years with high profile losses from a number of organisations, mainly in the US: “America has seen major security breaches in both the public and private sector,” says Jonathan Armstrong, partner at international law firm Eversheds. “Last year the US Department of Veterans Affairs, a government agency which deals with the payment of benefits to current and former servicemen in the US, lost data on 26.5 million people. Store group TJX, who own TK Maxx stores in the UK also lost the bank data of more than 90 million customers. Breaches involving the loss of audit data are also not uncommon - again in the US audit firms have been involved in incidents with the loss of over 240,000 records in a single breach.”
“The effect on the banking system should also not be underestimated,” he adds. “Some of the banks whose customers were involved in the TJX breach have started proceedings to recover their losses which they put at between $68 and $83 million. It is common in the US (where a different credit system exists) to pay for credit monitoring for all of those affected in addition to the actual losses suffered.”
HMRC was created in 2005, when the Inland Revenue and Customs and Excise institutions were merged to create the largest UK government department, cutting 25,000 jobs. “The HMRC breach will undoubtedly focus attention on the security procedures of the private sector as well as Government. Now is the time for businesses to update their response plans,” says Armstrong.
The news came as a study by CA and research consultancy YouGov highlighted growing fears in the UK about identity theft and the inadequate security of consumer details.
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@risk.net to find out more.
You are currently unable to copy this content. Please contact info@risk.net to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@risk.net
More on Regulation
Foreign banks want level playing field in US Basel III redraft
IHCs say capital charges for op risk and inter-affiliate trades out of line with US-based peers
CFTC’s Mersinger wants new rules for vertical silos
Republican commissioner shares Democrats’ concerns about combined FCMs and clearing houses
Adapting FRTB strategies across Apac markets
As Apac banks face FRTB deadlines, MSCI explores the insights from early adopters that can help them align with requirements
Republican SEC may focus on fixed income – Peirce
Commissioner also wants a revival of finders’ exemption, more guidance for UST clearing
Streamlining shareholding disclosure compliance
Shareholding disclosure compliance is increasingly complex due to a global patchwork of regulations and the challenge of managing vast amounts of data
Banks take aim at Gruenberg’s brokered deposit rule
Regulatory lawyers question need to reverse 2020 rulemaking just four years later
Time running out to backload Emir derivatives reporting
Significant slice of legacy trades still not ready for new formats, as October 26 deadline looms
Gensler to stick to Treasury clearing timetable
SEC chief promises to keep up the pressure for done-away trades