Agency Data Breach Hits Vermont CUs

WILLISTON, Vt. - Yet another massive data breach is affecting the credit union industry, this time in the cold climate of the Green Mountain State.

Processing Content

While many data breaches involve a retailer wrongly keeping a customer's vital information or a computer hacker beating a card processor's safeguards, the Vermont breach involved a state agency trying to find parents who are behind in their child support payments. The State of Vermont's Agency of Human Services officials said the names, Social Security Numbers, account balances and account numbers of 70,000 people were compromised although they're not sure if the information was copied or taken.

Credit unions affected were New England FCU, Vermont State Employees CU, Granite Hills CU, Federal Family CU and Opportunities CU. State officials said the breach was an automated attack that might have sought to use Vermont's large government computers to relay video or other purposes. State and external forensic investigators found an episode of the television show "Bones" on the computer system. Hardest hit was New England FCU with 58,000 out of its 70,000 members possibly compromised by the breach, according to CEO David Bard.

Vermont state law calls for supplying account information to the Agency of Human Services and that no financial institution is involved any further in obtaining child support, Bard explained. The $508-million New England FCU had sent information to the state as far back as 2004 and that the information was still in the state's computer system. Bard said the state notified the public about the December 2006 breach on Jan. 22, 2007 and that his credit union will also mail its members letters detailing their options.

"Our focus has been entirely on how do we communicate with our members," Bard said. "The most important thing is to be available for them.

The State of Vermont is offering affected consumers 12 months of credit monitoring, he noted. A message to the public on the agency's website stated that investigators performed a "complete forensic review and while there is still no evidence that confidential files were accessed, unfortunately, there is also no evidence that they were not accessed."

Vermont Agency of Human Services Communications Director Heidi Tringe said the state's computer system called for information retention when it was created, a practice that is now ended. Tringe compared the data breach to someone walking through the back door of a file room full of file cabinets.

"We don't know if they opened any file drawers," she said, noting that Vermont Gov. Jim Douglas had ordered the state's CIO to review security measures on all state systems, an inspection that will be complete by March 1.

Vermont State Employees CU President Steven Post said 400 members of his CU were affected by the breach and that he's monitoring the developing story along with other CUs and is as frustrated as the public regarding data breaches on such a large scale.

"It's a new experience for all of us. It's not like replacing credit cards," Post said. "Anyone of these is a serous concern for us. It seems as if financial institutions have gotten better at protecting their information, the hackers go somewhere else to get the same information." (c) 2007 The Credit Union Journal and SourceMedia, Inc. All Rights Reserved. http://www.cujournal.com http://www.sourcemedia.com


For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More