Heh. You'd be surprised at how blasé a lot of companies are about people's personal information. The vast majority of the corporate world still thinks it's perfectly reasonable to do their work by emailing excel files of personal data around.
And this is the real problem. This will happen again. That email should have been sent with something like PGP encryption to ensure that only the intended recipient could open it.
no customer data of any sort has been viewed or used by any inappropriate user during this data lapse
Since the email was apparently sent "in the clear" they cannot say this with certainty. A copy could have been siphoned off any intermediate network or smtp server.
Gmail, at least, forces you to use a SSL-encrypted SMTP server, so it's possible that the entire system of servers all communicated with each other securely. Not likely, though.
Comments
Heh. You'd be surprised at how blasé a lot of companies are about people's personal information. The vast majority of the corporate world still thinks it's perfectly reasonable to do their work by emailing excel files of personal data around.
And this is the real problem. This will happen again. That email should have been sent with something like PGP encryption to ensure that only the intended recipient could open it.
no customer data of any sort has been viewed or used by any inappropriate user during this data lapse
Since the email was apparently sent "in the clear" they cannot say this with certainty. A copy could have been siphoned off any intermediate network or smtp server.
Gmail, at least, forces you to use a SSL-encrypted SMTP server, so it's possible that the entire system of servers all communicated with each other securely. Not likely, though.