Has anyone here been helped by FEMA? There's been a huge data breach

PJ_SoulPJ_Soul Vancouver, BC Posts: 49,987

FEMA data breach hits 2.5 million disaster survivors



March 22 at 6:42 PM

The Federal Emergency Management Agency shared personal addresses and banking information of more than 2 million U.S. disaster survivors in what the agency acknowledged Friday was a “major privacy incident.”

The data breach, discovered recently and the subject of a report by the Department of Homeland Security’s Office of Inspector General, occurred when the agency shared sensitive, personally identifiable information of disaster survivors who used FEMA’S Transitional Sheltering Assistance program, according to officials at Federal Emergency Management Agency.

In a statement, FEMA Press Secretary Lizzie Litzow said the breach happened because “FEMA provided more information than was necessary” while transferring disaster survivor information to a contractor.

“We believe this oversharing has impacted approximately 2.5 million disaster survivors,” said a Department of Homeland Security official who asked for anonymity in order to provide background information beyond the official FEMA statement.

He said 1.8 million people had both their banking information and addresses revealed, and about 725,000 people had just their addresses shared.

The U.S. government mishandled personal information from victims of some of the country’s worst disasters -- including hurricanes Harvey, Irma and Maria in 2017 -- in a major privacy mishap that threatens survivors with “identity theft and fraud,” according to the watchdog report. That report, dated March 15, estimated that 2.3 million people had been affected, slightly less than the estimate from the DHS official on Friday.

The security mishap involved a program managed by the Federal Emergency Management Agency that places people affected by disasters in temporary housing. The agency shared “unnecessary” amounts of data -- including home addresses and birth dates and in some cases more sensitive information about their bank accounts -- according to findings of the Office of the Inspector General.

It is unclear if the data breach had led to identify theft or other malicious actions, he said.

“We don’t have any information that it has been compromised in a detrimental fashion,” he said.

The Inspector General report told FEMA it needed to install controls to make sure such data would not continue to be shared with contractors and that the agency needed to assess how wide the breach was and to make sure that data in the contractor’s system was destroyed.

In the OIG’s report, FEMA said that once it became aware of the problem, the agency installed a data filter on in December to prevent unnecessary survivors’ personal data from leaving its system. FEMA also said in the report that it had sent internal security experts twice since implementing its new procedures to conduct on-site checks of its network.

Litzow said that FEMA has taken “aggressive measures to correct this error. FEMA is no longer sharing unnecessary data with the contractor and has conducted a detailed review of the contractor’s information system.”

FEMA declined to identify the contractor.

Litzow said FEMA has been working with the contractor to remove the unnecessary data from its system. As an added measure, Litzow said, FEMA instructed contracted staff to complete additional DHS privacy training.




With all its sham, drudgery, and broken dreams, it is still a beautiful world. Be careful. Strive to be happy. ~ Desiderata

Comments

  • mickeyratmickeyrat Posts: 39,286
    thats not a breach. thats an agency fuck up. my understanding is a breach is a hack of the data base, not stupidly oversharing .....
    _____________________________________SIGNATURE________________________________________________

    Not today Sir, Probably not tomorrow.............................................. bayfront arena st. pete '94
    you're finally here and I'm a mess................................................... nationwide arena columbus '10
    memories like fingerprints are slowly raising.................................... first niagara center buffalo '13
    another man ..... moved by sleight of hand...................................... joe louis arena detroit '14
  • brianluxbrianlux Moving through All Kinds of Terrain. Posts: 42,300
    mickeyrat said:
    thats not a breach. thats an agency fuck up. my understanding is a breach is a hack of the data base, not stupidly oversharing .....
    Big time!
    "Pretty cookies, heart squares all around, yeah!"
    -Eddie Vedder, "Smile"

    "Try to not spook the horse."
    -Neil Young













  • Halifax2TheMaxHalifax2TheMax Posts: 39,355
    brianlux said:
    mickeyrat said:
    thats not a breach. thats an agency fuck up. my understanding is a breach is a hack of the data base, not stupidly oversharing .....
    Big time!
    Big time incompetence. 4th string running the world.
    09/15/1998 & 09/16/1998, Mansfield, MA; 08/29/00 08/30/00, Mansfield, MA; 07/02/03, 07/03/03, Mansfield, MA; 09/28/04, 09/29/04, Boston, MA; 09/22/05, Halifax, NS; 05/24/06, 05/25/06, Boston, MA; 07/22/06, 07/23/06, Gorge, WA; 06/27/2008, Hartford; 06/28/08, 06/30/08, Mansfield; 08/18/2009, O2, London, UK; 10/30/09, 10/31/09, Philadelphia, PA; 05/15/10, Hartford, CT; 05/17/10, Boston, MA; 05/20/10, 05/21/10, NY, NY; 06/22/10, Dublin, IRE; 06/23/10, Northern Ireland; 09/03/11, 09/04/11, Alpine Valley, WI; 09/11/11, 09/12/11, Toronto, Ont; 09/14/11, Ottawa, Ont; 09/15/11, Hamilton, Ont; 07/02/2012, Prague, Czech Republic; 07/04/2012 & 07/05/2012, Berlin, Germany; 07/07/2012, Stockholm, Sweden; 09/30/2012, Missoula, MT; 07/16/2013, London, Ont; 07/19/2013, Chicago, IL; 10/15/2013 & 10/16/2013, Worcester, MA; 10/21/2013 & 10/22/2013, Philadelphia, PA; 10/25/2013, Hartford, CT; 11/29/2013, Portland, OR; 11/30/2013, Spokane, WA; 12/04/2013, Vancouver, BC; 12/06/2013, Seattle, WA; 10/03/2014, St. Louis. MO; 10/22/2014, Denver, CO; 10/26/2015, New York, NY; 04/23/2016, New Orleans, LA; 04/28/2016 & 04/29/2016, Philadelphia, PA; 05/01/2016 & 05/02/2016, New York, NY; 05/08/2016, Ottawa, Ont.; 05/10/2016 & 05/12/2016, Toronto, Ont.; 08/05/2016 & 08/07/2016, Boston, MA; 08/20/2016 & 08/22/2016, Chicago, IL; 07/01/2018, Prague, Czech Republic; 07/03/2018, Krakow, Poland; 07/05/2018, Berlin, Germany; 09/02/2018 & 09/04/2018, Boston, MA; 09/08/2022, Toronto, Ont; 09/11/2022, New York, NY; 09/14/2022, Camden, NJ; 09/02/2023, St. Paul, MN; 05/04/2024 & 05/06/2024, Vancouver, BC; 05/10/2024, Portland, OR;

    Libtardaplorable©. And proud of it.

    Brilliantati©
  • brianluxbrianlux Moving through All Kinds of Terrain. Posts: 42,300
    brianlux said:
    mickeyrat said:
    thats not a breach. thats an agency fuck up. my understanding is a breach is a hack of the data base, not stupidly oversharing .....
    Big time!
    Big time incompetence. 4th string running the world.
    No joke! 
    "Pretty cookies, heart squares all around, yeah!"
    -Eddie Vedder, "Smile"

    "Try to not spook the horse."
    -Neil Young













  • mfc2006mfc2006 HTOWN Posts: 37,483
    What the HELL?!???
    I LOVE MUSIC.
    www.cluthelee.com
    www.cluthe.com
  • mfc2006mfc2006 HTOWN Posts: 37,483
    What the HELL?!???
    I LOVE MUSIC.
    www.cluthelee.com
    www.cluthe.com
Sign In or Register to comment.