Stolen Nationwide laptop prompts FSA probe

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

The theft of a laptop containing Nationwide Building Society customer information is being probed by the Financial Services Authority (FSA).

The laptop was stolen from an employee's house in a burglary in August. Both Nationwide and FSA have refused to say exactly what data was stolen. According to Alan Oliver, Nationwide's head of external affairs, the laptop contained "limited customer information for market research purposes".

The building society is willing to say what had not been stolen. No PINs, passwords or information about financial transactions were contained on the computer, and no account details such as customer names, account numbers or sort codes were compromised, Oliver told ZDNet UK on Monday.

However, there is a chance that the limited customer data stolen could be linked to other information about individuals and used for identity fraud.

Nationwide insists that victims of identity fraud would not suffer financial loss, as the building society has a policy of reimbursing money stolen. "There has been no loss of money, and no chance of any customers suffering financial loss. If they are the innocent victim of fraud they will not lose out," said Oliver. "The information on its own cannot be used for identity fraud."

Nationwide would not say how many customers' details were contained on the stolen laptop. It is in the process of writing to all of its 11 million UK customers to outline the security measures they need to take as a result of the theft.

"It's important at times like this to reassure people their information is safe and protected — and that it's a good thing to take precautions themselves," said Oliver. "It's important people take all necessary steps to protect their information."

Authorities, including the police and the Information Commissioner, have been informed about the loss of the data. Nationwide said it could not give any details of the burglary as it could compromise the police investigation.

"The police have asked us not to give details of the theft as to do so would compromise their ongoing investigation," said Oliver.

However, the police have told Nationwide that the crime was not targeted, and probably opportunistic.

Following the incident, Nationwide has taken "a number of different steps to increase security", although it would not say what steps had been taken. The building society also refused to comment on what kind of security policy it has regarding laptops, and whether encryption was used to protect the data.

The employee who had the laptop stolen may not have been acting in accordance with Nationwide security policy, the building society said.

"We're looking at our procedures as we speak. It appears that all procedures may not have been complied with," said Oliver.

Although Nationwide was keen to play down the severity of its security lapse, the Financial Services Authority (FSA) — which regulates the banking industry — is currently investigating the incident.

"We're continuing to discuss with Nationwide the incidence of a loss of data," said an FSA spokesman. "Our principle concern is to minimise the risk to consumers."

"Along with other authorities including the Information Commissioner and the police we considered when and how Nationwide should communicate with customers on this issue in a way that minimises any potential misuse of the data. We discussed what Nationwide needs to do to alert customers of the fact that data had been stolen."

While the FSA refused to comment on the nature of the data stolen, it said that the very act of alerting affected customers could have further compromised their security. This indicates that the data stolen could be used by criminals if linked to customer names or addresses.

Talkback

Once again, a laptop containing confidential consumer data is stolen, and the need for stricter security for mobile devices is highlighted once more.

'Random thefts' or loss of laptops and other physical assets inevitably occur, however, if access to the data on these stolen items is protected, for example through encryption, this information will remain protected and out of the reach of criminals.

Fiona Goldsworthy 14 November, 2006 10:46
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

SPM

The 2 million number quoted is shipments not sales, an exact repeat of last year's dire sales of WP7. Sales to customers are likely to number only...

4 hours ago by SPM on Nokia earnings fail to shine despite Lumia
apexwm

It sounds like this is just another variable in the complex equation of Microsoft licensing, which often results in customers overpaying as it is....

5 hours ago by apexwm on UK customers to lose out in Microsoft licensing change
chonzchor

I am really thankful to you for this nice and beautiful information.I really like this. cable ties

6 hours ago by chonzchor on Currys £16.99 USB cable rip-off.
Brian Jones

What would be nice would be if Microsoft practiced consistent pricing between the US and Europe.

11 hours ago by Brian Jones via Facebook on UK customers to lose out in Microsoft licensing change
Karen Friar

@Scott Deagan: Ofcom dedicated a section to upload speeds - see page 19 onward of its full report:...

11 hours ago by Karen Friar on UK broadband speed climbs 22 percent
EUDataProtection

The EU proposals can all be read in full on the reform website: http://ec.europa.eu/justice/data-protection/minisite/index.html

12 hours ago by EUDataProtection on Firms face tough new EU fines for data breaches
Jake Rayson

Found out that Taskwarrior stores all data in plain text files: "Task writes all pending tasks to the file ~/.task/pending.data and all completed...

14 hours ago by Jake Rayson on Taskwarrior: command line task manager
ians1

"...based 6,000 miles away..." Indeed, so who do you complain to when things go wrong? I would not buy shares in Faecebook even if I could...

15 hours ago by ians1 on Facebook plans to raise $5bn via share launch
servermanagement

These are really very useful tips of backing up the system. Each tips are important and essential to prevent loosing all the data that we have....

17 hours ago by servermanagement on Ten ways to take the sting out of IT disasters
Scott Deagan

Why is the upstream never discussed? I'd like to see Ofcom explain to Internet users why people in the UK can only get a maximum of 10Mb/s upstream...

1 day ago by Scott Deagan via Facebook on UK broadband speed climbs 22 percent
Moley

Seemingly a very strange decision, even perverse. Mind you, the basis of the decision is hardly explained here or in Cnet. Perhaps we will hear...

1 day ago by Moley on Free Maps costs Google £400K in damages in France
Jake Rayson

@OccupyACAT: I had heard mention of the Emacs extension but not the Ubiquity project. Interesting to see an idea spread almost simultaneously! Re....

1 day ago by Jake Rayson on Ubuntu HUD Intenterface? Sublime already there!
markhumphryes

With no Flash support on LoveFilm, mobile devices running Android will not be able to use it - I presume - I tried a trial via my Galaxy Tab 10.1...

2 days ago by markhumphryes on Lovefilm drops Flash, kills Linux support
manek

And people wonder why there is caution about doing business with large, consumer-focused technology companies, most of which are based 6,000 miles...

2 days ago by manek on Facebook plans to raise $5bn via share launch
manek

Yes, frameworks and smarter compilers - but I suspect a lot of the code will have to be written with parallel processing as one of its fundamental...

2 days ago by manek on Parallel computing takes a step forward
Simon Bisson and Mary Branscombe

Well, this is why I'm both fascinated and slightly worried; parallel computing and concurrency and complex architectures don't seem to be something...

2 days ago by Simon Bisson and Mary Branscombe on Parallel computing takes a step forward
ians1

Let's hope that they take more notice of their shareholders than they do of their poor customers! I have never experienced customer service as bad...

2 days ago by ians1 on Facebook plans to raise $5bn via share launch
servermanagement

Thanks for the heads up. Will definitely check this HUD Intenterface.

2 days ago by servermanagement on Linux Minterface
Will A

Some more observations by an extremely frustrated user in Canada (apparently every country has a different set of "issues"): The web interfaces...

2 days ago by Will A on Cambridge researchers knock Verified by Visa
Jake Rayson

@zdnetukuser: I hope there's more conciliation and less bitterness in the graphical shell camps, I'd like to Ubuntu to succeed, I *want* to have a...

2 days ago by Jake Rayson on Linux Minterface