A backup tape containing Social Security numbers and account information belonging to potentially thousands of customers and investors in People’s United Bank, a Connecticut institution with a large subsidiary presence in Massachusetts, has been lost.
The security breach could affect hundreds of thousands People’s United customers and millions more consumers nationwide, according to Connecticut Attorney General Richard Blumenthal. The tape of unencrypted data – which has yet to be recovered – was lost in February from a storage facility for the Bank of New York Mellon.
The Bank of New York Mellon, meanwhile, said the problem goes beyond affecting banks and financial services companies. The New York bank provides shareholder services, such as acting as transfer agent and administrator “to a broad range of companies, not just companies in banking or financial services,” said Ron Sommer, spokesman for Bank of New York Mellon.
For any public company that issues common stock, when it comes time for dividends to be paid, for example, the data of who owns the stock – the record keeping and support related to company’s management of its outstanding shares – is part of shareholder services, Sommer said.
“The range of public companies out there engaging companies providing shareowner services is as broad as the mix of companies in the U.S. economy,” he said. “There are, of course, large financial institutions that are publicly owned which issue common stock, and they require the services of a shareowner-services provider. But they’re only one segment of the market.”
For People’s United, it was yet another security blow, as the bank was the victim of a “phishing” scheme revealed in court documents earlier this month.
The Bridgeport, Conn.-based bank expanded into Massachusetts on Jan. 1 by completing the acquisition of Burlington, Vt.-based Chittenden Corp., whose Massachusetts subsidiaries included Bank of Western Massachusetts in Springfield and Flagship Bank and Trust in Worcester. That purchase gave the bank more than 300 bank branches in Connecticut, Massachusetts, Vermont, New Hampshire, Maine and New York.
But People’s spokesman Brent DiGiorgio said Massachusetts customers weren’t affected by the security breach, because the loss of the customer information occurred before the acquisition took effect.
Bank of New York Mellon served as the transfer agent to People’s United when it was in the midst of its conversion to a fully public company in April 2007, DiGiorgio said. In that role, Bank of New York Mellon tabulated depositors’ votes on the conversion and later, their stock order requests.
Peoples sent its depositor information to Bank of New York Mellon for those purposes in encrypted format, he said, but the Bank of New York made a backup tape that was not encrypted, and was lost.
Bank of Western Massachusetts President and Chief Executive Officer Timothy P. Crimmins Jr. confirmed his bank’s customers are “unaffected.”
In addition to the risk of investors being exposed, Blumenthal said the security breach affected People’s United customers. The bank had provided customer information – lost on the tape – so Bank of New York Mellon could cross-sell and offer those consumers an investment opportunity, Blumenthal said in a press conference last week.
“I am alarmed and deeply concerned by a recent and serious data breach at the Bank of New York Mellon involving the loss of computer backup tapes containing sensitive information of some 4.5 million consumers, including People’s United Bank account holders and shareowners,” Blumenthal wrote in a letter to the Bank of New York Mellon.
Sommer declined to comment on Blumenthal’s remarks.
“We can’t speak to whatever it was that was alluded to in the announcements that were put out yesterday in connection with that particular client,” Sommer said.
Blumenthal expressed particular concern over the delay in the Bank of New York Mellon’s reporting the loss to People’s United and, subsequently, to the consumers affected. While the loss occurred on Feb. 27, Blumenthal said his office had not been notified until last week.
On Friday, Connecticut Gov. M. Jodi Rell announced that, at her direction, Consumer Protection Commissioner Jerry Farrell Jr. had issued subpoenas to Bank of New York Mellon Corp. and People’s United Bank of Bridgeport seeking more information about the loss of the tape, which the state said contained personal and financial data on millions of consumers, including more than half a million depositors in Connecticut, including names, addresses, dates of birth and Social Security numbers. The tape was lost in late February, and under Connecticut state law, banks are required to immediately notify customers when such information is lost. Yet BNY Mellon did not notify People’s of the breach until March 18, at which time it said information on about 170 shareholders was missing. It was not until May 13 – some eight weeks later – that BNY Mellon advised People’s that information on some 556,000 depositors was missing.
When Bank of New York Mellon became aware of problem, the bank notified law enforcement, and did its own investigation, Sommer said. The bank also did an initial run in March of notification letters to people whose information was exposed, he said. The bank then hired a data forensic expert and did a second database search to find anyone who might be at risk, he added, noting that the search had taken until last week to complete.
“The episode took place at the end of February, it’s [now] the middle of May, and throughout that period – we’ve been watching this very carefully – we’ve got no reason to think that the data is in the hands of an unauthorized person, [or] that anybody has made any attempt to make an inappropriate use of the data,” Sommer said. “The letters are a precaution.”
On Feb. 27, Bank of New York Mellon gave the tape, along with nine others, to the storage firm Archive Systems for transportation to a storage facility, according to Blumenthal’s office. When the storage company vehicle arrived at the storage facility, the tape was missing. The other nine were not.
‘Two-Sided Problem’
The attorney general is requesting that Bank of New York Mellon provide consumers two years of credit monitoring, $25,000 identity theft insurance and free credit freezes.
This form of security breach falls outside of the more familiar patterns. Often it happens at the retail level.
“It happens constantly. Literally every day we’ll get a list from Visa [stating] ‘the following cards have been compromised,'” said Robert V. Macklin, chairman of the Connecticut Bankers Association, and president and chief executive officer of The Milford Bank. He estimated his bank receives two or three such e-mails daily.
Unfortunately, those e-mails do not include information about who the retailer is, or any other details about the breach, he said.
“The problem for the banks is that we then have to notify our customers,” Macklin said. “And the customers often think it’s the bank’s fault because we can’t tell them who, what, when, where or anything else about it.”
The other threat banks have to guard against is protecting people from hacking into their computer systems, he said.
“The problem that we or any face is a two-sided problem,” Macklin said. “One is to protect against people from getting in from the outside. [But] the biggest concern these days is theft from the inside.”
“If you get a rogue employee, they can download a lot of information to an iPod and walk out the door,” Macklin said. “So that’s the thing we’re all concerned about now.”
“As fast as we try to plug the holes up, the bad guys are constantly looking for new ones,” he added.
One of those newer tricks is called phishing, where phony e-mails are first designed to look like they came from a bank, and then solicit personal information from account holders. In New Haven, a federal grand jury has unsealed an indictment against seven Romanian nationals accused of running an elaborate phishing scam.
According to the office of Nora R. Dannehy, acting U.S. attorney for the District of Connecticut, the seven individuals conducted the scam by fraudulently posing as representatives from People’s United Bank.
The investigation resulted from a citizen’s complaint concerning a fraudulent e-mail message made to appear as if it originated from People’s United. The e-mail message directed victims to a computer in Minnesota that had been hacked and used to host a counterfeit People’s United Bank Internet site.
The seven individuals were charged in an indictment returned by a federal grand jury in New Haven on Jan. 18, 2007, and unsealed on May 16 this year. Two of the individuals are named in a similar suit in Los Angeles.
The investigation was part of a larger effort to root out organized crime nationwide. The case was investigated by the FBI and the Connecticut Computer Crimes Task Force, and is being prosecuted by Assistant U.S. Attorney Edward Chang of the Computer Hacking and Intellectual Property Unit at the U.S. attorney’s office.
B&T Reporter Amy Wyeth contributed to this story.





