in

This Blog

Syndication

Tags

News

AlertBoot offers a cloud-based full disk encryption and mobile device security service for companies of any size who want a scalable and easy-to-deploy solution. Centrally managed through a web based console, AlertBoot offers mobile device management, mobile antivirus, remote wipe & lock, device auditing, USB drive and hard disk encryption managed services.

Archives

AlertBoot Endpoint Security

AlertBoot offers a cloud-based full disk encryption and mobile device security service for companies of any size who want a scalable and easy-to-deploy solution. Centrally managed through a web based console, AlertBoot offers mobile device management, mobile antivirus, remote wipe & lock, device auditing, USB drive and hard disk encryption managed services.

Email Encryption: NY Yankees Breaches Info For 20,000 Season Ticket Holders

A spreadsheet containing New York Yankees season ticket holders' information was emailed to nearly 2,000 people.  The spreadsheet contained information on 21,446 ticket holders.  When dealing with emails that hold quite a bit of data, it's always advisable that one look into data encryption like AlertBoot.

VIPs Not Affected

The NYY revealed in a public statement that credit cards, dates of birth, and SSNs were not breached.  The spreadsheet contained names, addresses, phone and fax numbers, email addresses, and Yankee account numbers.  Also, Yankees rep names and ticket package codes were breached as well, although these would be corporate data, not personal data.

Deadspin.com has noted that the information only affects "non-premium" seats (the spreadsheet excluded luxury suites and the first rows).  The breach was accidentally instigated by an employee who  tried to recall the email.  As people familiar with Outlook know, it only works when both the sender and the receiver are using the same system.

If some kind of data loss prevention (DLP) software had been set up, or if potentially the spreadsheet had been saved in encrypted format, this breach wouldn't have occurred.

Such Data is Pretty Valuable

Overall, it doesn't sound like this is a calamitous breach.  On the other hand, it depends on how you define calamitous.  The lack of financial account information and SSNs means that the breach won't hit anyone's pocketbooks (unless some kind of spam/phishing campaign is carried out succesffuly).

You've got to admit, though, that the information would be somewhat of a boon to telemarketers: they know people's names, where they live, have a way of contacting them, and know that the love for the Yankees is what sets them apart from other people.

But, the information that can be gleaned goes further than this.  I don't follow the Yankees, or even baseball for that matter, but apparently the Yankees' management keep their ticket sales figures close to the vest.  Deadspin.com notes:

These numbers are fascinating in light of the Yankees' repeated refusal to comment on their ticket sales, at a time when the stadium is obviously not full every night. The contents of the files are ripe for analysis. Members of the NYYfans.com message board are already deciphering the data, and one person made an attempt at crunching some of the raw numbers.

Apparently, the non-premium season ticket revenue is (remember now, this figure is very rough...and possibly waaaaaay off the mark) $131,978,910.

Of course, it doesn't have to be off the mark.  Someone who works in the industry, or is familiar with it, may be able to use the information and their background knowledge to make a more precise guesstimate.  That the Yankee group won't reveal such figures implies that the data could be of use to someone.

What can I say?  Encryption software works, and hindsight shows that the file ought to have been cryptographically protected.  Mistakes will happen, so policies that ask employees to check carefully before sending e-mails don't always work (as in this case.  The employee must have immediately realized what happened).  A better data security policy may be to always encrypt files if they contain sensitive data and will be placed in an e-mail.

On the other hand, that too suffers from the fact that an employee has to encrypt it.  The answer might be a DLP that will automatically pick up on particular types of information, and either stops it from being sent or encrypts it on the fly.


Related Articles and Sites:
http://gothamist.com/2011/04/28/whoops_yankees_accidentally_email_p.php
http://www.tgdaily.com/business-and-law-features/55637-yankees-release-private-info-of-17000-fans-in-epic-email-fail
http://www.scmagazineus.com/new-york-yankees-expose-season-ticket-holders-data/article/201633/
http://deadspin.com/#!5796294/yankees-accidentally-leak-personal-info-of-20000-season-ticket-holders

 
<Previous Next>

Massachusetts Data Breach Cost: 201 CMR 17 Claims First Victim - Briar Group

Data Encryption Software: Sony Says Credit Cards Were Encrypted

Comments

No Comments

About sang_lee

Sang Lee is a Senior Account Manager and Security Analyst with AlertBoot, Inc., the leading provider of managed endpoint security services, based in Las Vegas, NV. Mr. Lee helps with the deployment and ongoing support of the AlertBoot disk encryption managed service. Prior to working at AlertBoot, Mr. Lee served in the South Korean Navy. He holds both a B.S. and an M.S. from Tufts University in Medford, Massachusetts, U.S.A.