also @ TechSpot: Weekend Open Forum: Have you upgraded to Windows 7 yet?

Subscribe

Newsletter Our Feeds

Receive weekly updates on new articles, news and contests in your mail!

Email address:

Information Technology

Gap loses personal information on 800,000 people

By Justin Mann, TechSpot.com
Published: September 28, 2007, 9:31 PM EST
Another wonderful data breach in the news, this one affecting a huge number of people who applied for jobs at Gap Inc. Gap, a clothes retailer, apparently keeps job applicants on file for a long while – and in great numbers. A laptop was lifted, and on it was the information for 800,000 applicants. Since job applications often include phone numbers, street addresses, social security numbers and a lot of other goodies, it is prime real estate for an identity thief.

Why would gap, who employs about 152,000 people worldwide, have a single machine with nearly a million people who aren't even employed there on file? It seems odd, but with all the massive data thefts we've seen the past three years it is hardly surprising.

There are no reports yet of the data being “misused” according to Gap.

User Comments (9)

Post a comment
nirkon
on September 29, 2007
2:36 PM
I find it hard to believe that one laptop had 800,000 applications on it..
and if it did, and gap doesn't have a protection system on it, they probably deserve a law suit

TimeParadoX
on September 29, 2007
9:30 PM
Actually Nirkon, some major businesses can have over a million people on a computer, since all it is really is abunch of information like Phone Number each wouldn't take up much space

If you look at hospitals they can have a crapload of files on 1 computer

PanicX
on October 1, 2007
4:12 AM
The issue is that all this very sensitive information is on an unsecured laptop instead of a database hosted in a secured location requiring encrypted authentication like it should be.

I really hope that criminal charges are pressed against the user who was responsible for the laptop or the manager that authorized sensitive data to be removed from a secure location.

Gars
on October 1, 2007
5:10 AM
Last week MediaDefender, now that. Who's next?
Wtf going on?

Fornacis
on October 1, 2007
9:27 AM
I see a joke in this headline....

Deathstar17
on October 1, 2007
6:59 PM
woops...lol at Gap

kitty500cat
on October 1, 2007
7:06 PM
The issue is that all this very sensitive information is on an unsecured laptop instead of a database hosted in a secured location requiring encrypted authentication like it should be.
Exactly. It makes more sense to store it on a central server anyway, since others who need the data can access it more readily.

hejustlaughs
on October 2, 2007
10:31 PM
I actually got a letter from Gap INC.

I uploaded a picture of it here:

http://www.endlessgibberish.com/uploaded-letter-of-gap-apologizing-for-losing-my-name-and-social-security/

theitguy
on October 3, 2007
2:06 PM
The IT Guy wrote about it here: http://theitguysblog.com/?p=20
Lawsuit is right around the corner!

Browse more commented news