• On TechRepublic: Why VISTA HATERS will love Windows 7
June 12, 2007 12:58 PM PDT

Pzifer investigated for internal data breach

by Robert Vamosi

The Connecticut attorney general has launched an investigation into the compromise of up to 17,000 of Pfizer employees, including some 300 employees within his home state. Pfizer would not comment on when the breach occurred other than to say it involved a Pfizer employee who had taken the data home on a laptop, a machine that subsequently became compromised. The data, including the employees' name, home address, bonus information, and Social Security number, was surreptitiously uploaded and later appeared on an Internet site. Pfizer did not know how much of that information had been copied or used by others.

The company has offered the affected employees $25,000 in insurance to cover any costs resulting from the breach. Employees were asked to respond within 90 days. In a letter dated June 6, Attorney General Richard Blumenthal asked the pharmaceutical company to also freeze the affected employees' credit ratings and pay any fees associated.

Internal leaks of sensitive data are an emerging problem for enterprises. "Although the lost laptop appears to be the trend that people focus on," said Devin Redmond, director of the security product group at Websense, "the trend is more that (personal data) goes out over the Web." Redmond said that spyware and malware tend to be targeted to a specific organization, even specific file types. The potential attacker includes competing companies or organized crime.

Redmond said companies should discover where their assets are and then implement IT policies to protect them. For employee-issued laptops, this may include restricting or filtering Web sites that may be visited with that machine. As for employees wanting to take files home on a flash drive, ports and burners on the office desktop can be prevented from copying sensitive documents.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from News Blog
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Was InfoWorld's CTO of the Year award a year late?
VMWare VI4 renamed to vSphere
advertisement

Look before leaping to short URLs

Fueled by Twitter's rise, services that scrunch Web addresses are taking off. They bring a host of problems, but some are working to fix them.

In Utah desert, it's bombs away

road trip At the massive Utah Test & Training Range, the Air Force runs 15,000 sorties a year to ensure that pilots and weapons are on the mark.
• Photos: Training and testing

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right