COMPUTERS
June 12, 2007 12:58 PM PDT

Pzifer investigated for internal data breach

Posted by Robert Vamosi
  • Font size
  • Print

The Connecticut attorney general has launched an investigation into the compromise of up to 17,000 of Pfizer employees, including some 300 employees within his home state. Pfizer would not comment on when the breach occurred other than to say it involved a Pfizer employee who had taken the data home on a laptop, a machine that subsequently became compromised. The data, including the employees' name, home address, bonus information, and Social Security number, was surreptitiously uploaded and later appeared on an Internet site. Pfizer did not know how much of that information had been copied or used by others.

The company has offered the affected employees $25,000 in insurance to cover any costs resulting from the breach. Employees were asked to respond within 90 days. In a letter dated June 6, Attorney General Richard Blumenthal asked the pharmaceutical company to also freeze the affected employees' credit ratings and pay any fees associated.

Internal leaks of sensitive data are an emerging problem for enterprises. "Although the lost laptop appears to be the trend that people focus on," said Devin Redmond, director of the security product group at Websense, "the trend is more that (personal data) goes out over the Web." Redmond said that spyware and malware tend to be targeted to a specific organization, even specific file types. The potential attacker includes competing companies or organized crime.

Redmond said companies should discover where their assets are and then implement IT policies to protect them. For employee-issued laptops, this may include restricting or filtering Web sites that may be visited with that machine. As for employees wanting to take files home on a flash drive, ports and burners on the office desktop can be prevented from copying sensitive documents.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from News Blog
Was InfoWorld's CTO of the Year award a year late?
VMWare VI4 renamed to vSphere
Red Hat's new support product demonstrates subscription value
Teen listens to iPod during brain tumor removal
NASA, Google Maps track Southern California wildfires
Sprint first to offer HTC Touch Pro
Flipping out: RIM BlackBerry Pearl Flip 8220 debuts
Sprint HTC Touch Diamond outed early
advertisement

In the news now

Apple: DRM-free tunes, unibody MacBook Pro

roundup At Macworld, Phil Schiller touts 10 million songs sans DRM, plus 69-cent songs, a unibody 17-inch notebook, iLife updates, and more.


Countdown to CES

special coverage The tech community descends on Las Vegas as the Consumer Electronics Show gets ready to kick off in all its gadgety glory.


About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

News Blog topics

advertisement

Inside CNET News

Scroll Left Scroll Right