CHAIRMAN: DR. KHALID BIN THANI AL THANI
EDITOR-IN-CHIEF: PROF. KHALID MUBARAK AL-SHAFI

Default / Miscellaneous

Call for action on data breach disclosure

Published: 31 Jan 2014 - 06:20 am | Last Updated: 26 Jan 2022 - 10:00 am

WASHINGTON: US spy agency chiefs called on Congress to draft stricter requirements for how retailers and other private businesses should inform government agencies and customers about big breaches of personal and financial data.
The intervention by intelligence chiefs came as Attorney General Eric Holder confirmed that the Justice Department was investigating the massive hacking of consumer data from No. 3 US retailer Target Corp during the holiday shopping season late last year. 
Also, several congressional committees signalled growing interest in recent data breaches, with the powerful House Oversight Committee scheduling a telephone briefing with Target representatives.
Separately, at Wednesday’s threat hearing before the Senate Intelligence Committee, Barbara Mikulski of Maryland, where the National Security Agency is headquartered, asked intelligence chiefs if media leaks by former NSA contractor Edward Snowden had affected US cybersecurity efforts. “Is the impact of the Snowden affair slowing us down in our work to be more aggressive in the cybersecurity area?” Mikulski asked.
FBI Director James Comey said political uproar over surveillance and Snowden’s leaks had complicated discussions about how to fight consumer data breaches. 
“There is the threat of fraud and theft because we’ve connected our lives to the Internet,” Comey said.  “We need to make sure that the private sector knows the rules of the road and how we share that information with the government.”
Some US officials with responsibility for cyber security have complained privately that, while states have created a “patchwork” of local rules requiring businesses to report breaches of consumer data to authorities and the public, there are no similar federal requirements.
Congress has been wrestling for years with proposals for  legislation on data security, but has been unable to reach agreement. There is no national standard to govern how and when businesses that suffer consumer data breaches must advise their customers and agencies like the US Secret Service and FBI. 
Holder, testifying at a Senate Judiciary Committee hearing, said the Justice Department would seek the perpetrators of the Target breach as well as “any individuals and groups who exploit that data via credit card fraud.”
“While we generally do not discuss specific matters under investigation, I can confirm the department is investigating the breach involving the U.S. retailer, Target,” Holder said.
Target has said a breach of its networks resulted in the theft of about 40 million credit and debit card records and 70 million other records with customer information such as addresses and telephone numbers.
The Secret Service has taken the lead investigating the recently revealed data breaches at Target and other retailers, including Neiman Marcus and Michaels Companies Inc, the largest US arts and crafts retailer.
Reuters reported on January 23 that the FBI also warned US retailers to prepare for more cyber attacks after discovering about 20 hacking cases over the past year that involved the same kind of malicious software used against Target during the holiday shopping season. Numerous congressional committees are accelerating efforts to gather more information about the data breaches.
Reuters