SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Government >> Technology

Computer theft shakes Revenue Canada

Computer theft shakes Revenue Canada

By:  Carly Suppa  On: 29 Sep 2003 For: IT World Canada Creator

Police have begun an investigation into the theft of computer equipment from a Canada Customs and Revenue Agency (CCRA) office which contained information on businesses and individuals, including some social insurance numbers.

Police have begun an investigation into the theft of computer equipment from a Canada Customs and Revenue Agency (CCRA) office which contained information on businesses and individuals, including some social insurance numbers.

Four laptop computers - one of which was acting as a server - and two desktops were stolen on Sept. 4 from the agency's Laval, Que. Tax Services Office. According to CCRA spokesperson Colette Gentes-Hawn, despite the theft's occurrence nearly one month ago, the CCRA waited until Sept. 30 to alert the public in order to figure out exactly what information was stolen.

The CCRA has stated that the databases contained no personal income tax information, and it has reconstructed them in order to recapture any lost data. In a statement, the CCRA said this process has enabled it to assess what information could have been stolen and potentially inappropriately used. The agency said in its statement that the majority of the information contained in the equipment was related to people within the construction industry including contractors and sub-contractors, and could include information such as names, addresses, payments and business numbers. It also stated that the records contained some social insurance numbers.

The government has started to send letters to approximately 120,000 people who might be affected, explaining the situation and advising them on the appropriate steps to be taken.

Gentes-Hawn told IT World Canada that perpetrators gained access to the Laval office by throwing a rock through a window. However, she added that the theft was indeed the result of human error as the main laptop, which held the majority of the stolen information, should have been locked away in a safe room - which it was not.

Revenue Minister Elinor Caplan has ordered the security of all CCRA offices across Canada to undergo additional review, and the CCRA is currently in the process of barring all windows on that particular building.

Despite changes in physical security, the CCRA did not comment on any new measures in terms of IT security. Although the stolen laptop/server was password-protected, the data on the machine was not encrypted. Gentes-Hawn did not know how many CCRA employees had access to the password.

According to Rosaleen Citron, CEO of Burlington, Ont.-based security software firm Whitehat Inc., a "smash and grab" can happen to anybody at anytime, but corporations need to ensure that data is protected. Assets like desktops and laptops can be replaced but information, if placed in the wrong hands, can become dangerous.

"It doesn't matter if it was an old database," Citron said referring to the information held on the CCRA stolen equipment. "The fact is that it had social insurance numbers, addresses, et cetera. That's all you need for identity theft. That's all you need in the black market to get a passport. It's all a terrorist needs to get their hands on."


Sign up for our Newsletters












Print |  Views: 1353   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Carly Suppa Carly Suppa is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Privacy, link analysis and counter-terrorism
Privacy, link analysis and counter-terrorismThe Canadian government can expect increasing pressure to match its IT policies with those of the United States, not least because the U.S. has had some recent success in data analysis for counter-terrorism. "We in the U.S. have become deeply convinced that enhanced exchanges of information are the key to preventing the next terrorist attack," says Paul Rosenzweig of Homeland Security.
The big chill
The big chillNewton’s Third Law works in the physical world, but politics is different. When citizens demand swift action, the reaction to every action is not equal. In a crisis, Newton’s theorem could be restated as: “Every action results in bureaucratic overreaction, in direct proportion to the emotional impact of the headlines.” The U.S. Sarbanes-Oxley legislation, or SOX, is a case in point.
department manager for security practices and technology with BMO Financial Group
department manager for security practices and technology with BMO Financial GroupLong before the federal government passed the Personal Information Protection and Electronic Documents Act (PIPEDA) at the start of 2004, BMO Financial Group discovered security and privacy were closely connected in the minds of the firm’s customers.
Dell debuts new, wee Internet device
dell unveiled today the new dell inspiron mini 9.the "internet companion" is a small laptop that is geared toward users wanting to engage in web 2.0 activities like messaging, blogging, viewing streaming content, uploading photos, and playing games online while on the go.built-in wifi, webcam, and bluetooth is included along with a partnership with box.net for web-based file s
Is your enterprise environment full of data leaks?
your company’s it security profile may be like an old leaky ship. data and information might be dangerously exposed and seeping into an outside malicious world – without you or your organization even knowing it. how secure is your it security? do you routinely test its robustness? do you know how? do you know the warning signs of “data leakage” – what to look for and where? could your current ris
Dan Swanson's Security Resources: #6
just who is responsible for information security? are we learning from incidents that have occurred at other organizations? do we leverage the research that is available from various institutions? do we take regulations seriously? this week’s resources discuss all these questions and more.enjoy.good luck and have another great week.dan swanson
blog comments powered by Disqus