Author Topic: Who do you report a major PII breach to - Also, don't use eFax!  (Read 2776 times)

Fitz

  • Face-melter
  • friend
  • Senior Member
  • ***
  • Posts: 6,254
  • Floyd Rose is my homeboy
    • My Book
Who do you report a major PII breach to - Also, don't use eFax!
« on: February 04, 2014, 01:49:56 AM »
So, the efax number i got apparently belonged to someone else before. In the "inbox", there are several faxes from a few months ago. Including some woman's tax data, a voided check, address, etc.

She runs a local business. I've already reached out to her so we can get together and resolve this. My question is, who do you report this kind of thing to, other than the guilty company?

I don't know if a crime has been committed, so I'm not sure if it would be the Police. Is there some kind of consumer agency that handles privacy breaches?


Fitz

---------------
I have reached a conclusion regarding every member of this forum.
I no longer respect any of you. I hope the following offends you as much as this thread has offended me:
You are all awful people. I mean this *expletive deleted*ing seriously.

-MicroBalrog

Tallpine

  • friends
  • Senior Member
  • ***
  • Posts: 23,172
  • Grumpy Old Grandpa
Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #1 on: February 04, 2014, 11:18:48 AM »
So when are you going to get my taxes done  ???   :mad:
Freedom is a heavy load, a great and strange burden for the spirit to undertake. It is not easy. It is not a gift given, but a choice made, and the choice may be a hard one. The road goes upward toward the light; but the laden traveller may never reach the end of it.  - Ursula Le Guin

HankB

  • friend
  • Senior Member
  • ***
  • Posts: 16,689
Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #2 on: February 04, 2014, 11:19:02 AM »
It's the woman whose privacy has been breached, so the onus is really on her to straighten this out - you're being a good guy by informing her of this data breach.

BUT . . . if you ever give up your eFax number and it gets issued to someone else, YOU might find that data meant for you is ending up elsewhere, and then it will be your data that's at risk of compromise.

I'd say keep in touch with the woman and see how she handles it, and talk to the eFax company about this problem; if it's not resolved to your satisfaction, some news organizations have consumer arms, and in the wake of data breaches at Target, Nieman-Marcus, etc., they may be eager to jump on this; bad publicity may force a solution.
Trump won in 2016. Democrats haven't been so offended since Republicans came along and freed their slaves.
Sometimes I wonder if the world is being run by smart people who are putting us on, or by imbeciles who really mean it. - Mark Twain
Government is a broker in pillage, and every election is a sort of advance auction in stolen goods. - H.L. Mencken
Patriotism is supporting your country all the time, and your government when it deserves it. - Mark Twain

Boomhauer

  • Former Moderator, fired for embezzlement and abuse of power
  • friends
  • Senior Member
  • ***
  • Posts: 14,355
Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #3 on: February 04, 2014, 11:24:10 AM »
Did she clean out her inbox before she stopped using eFax?

Did she stop people from sending her stuff to that number once she stopped using eFax?

No? Then it's not anyone's fault but hers. Not eFax's fault.


Now if she cleared out the inbox and then that stuff got put back in the inbox by eFax's screwup, then that's a breach.



Quote from: Ben
Holy hell. It's like giving a loaded gun to a chimpanzee...

Quote from: bluestarlizzard
the last thing you need is rabies. You're already angry enough as it is.

OTOH, there wouldn't be a tweeker left in Georgia...

Quote from: Balog
BLOOD FOR THE BLOOD GOD! SKULLS FOR THE SKULL THRONE! AND THROW SOME STEAK ON THE GRILL!

MillCreek

  • Skippy The Wonder Dog
  • friend
  • Senior Member
  • ***
  • Posts: 20,015
  • APS Risk Manager
Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #4 on: February 04, 2014, 11:33:10 AM »
I have a similar problem with a GMail account.  I use my real name as the address for one of the accounts, and I have had that account for years.  I have been astonished to see the number of people all across the world who have the same name as me and are using that as a GMail account address.  I have found out that there is a math professor in Texas, a judge in Connecticut, an Anglican minister in England, a truck driver in Kansas, an IT person in England and others too numerous to count, all with the same first and last name.

If I get junk mail for one of them, I just delete it.  For example the IT person in England signed up for match.com, and I get daily matches for 20-25 year old women within 100 miles of London.  I delete those because my wife won't let me fly to England to meet some of them.  But on occasion, I do get personal, medical, business or financial information directed to someone else.  My approach is to reply to the sender, point out that I am a healthcare risk manager north of Seattle, and although I would be happy to help them with any patient safety or malpractice issues, I am not the actual person they are looking for, and I have deleted the email and any attachments.  I probably get the most contacts for the judge in Connecticut, since I get a couple of emails per month asking if I can officiate at a wedding ceremony.  

I sometimes wonder if anyone else is getting email intended for me.

PS: I forgot to mention: my favorite is the person in Australia who signed up for some Oz equivalent of Adult FriendFinder down there.  I think he is in his mid-20's and I periodically get these private messages from these middle-aged Oz women looking for hookups with younger men.  Some of them have nude photos attached, and I can say that Oz women sure tend to be tanned, usually all over.
« Last Edit: February 04, 2014, 11:37:09 AM by MillCreek »
_____________
Regards,
MillCreek
Snohomish County, WA  USA


Quote from: Angel Eyes on August 09, 2018, 01:56:15 AM
You are one lousy risk manager.

Hawkmoon

  • friend
  • Senior Member
  • ***
  • Posts: 27,331
Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #5 on: February 04, 2014, 12:09:39 PM »
I probably get the most contacts for the judge in Connecticut, since I get a couple of emails per month asking if I can officiate at a wedding ceremony.

Heh, heh.

Not a judge. Since I am a justice of the peace in my state, I periodically get offers to join some national justice of the peace organization. In Connecticut, justices of the peace are not judges. The only two things they can do are take affidavits ... and perform weddings. It seems there are many of them who make a living doing nothing but performing weddings. That's probably who you're getting e-mails for.
- - - - - - - - - - - - -
100% Politically Incorrect by Design

Fitz

  • Face-melter
  • friend
  • Senior Member
  • ***
  • Posts: 6,254
  • Floyd Rose is my homeboy
    • My Book
Re: Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #6 on: February 04, 2014, 12:24:22 PM »
Did she clean out her inbox before she stopped using eFax?

Did she stop people from sending her stuff to that number once she stopped using eFax?

No? Then it's not anyone's fault but hers. Not eFax's fault.


Now if she cleared out the inbox and then that stuff got put back in the inbox by eFax's screwup, then that's a breach.



Not exactly. When an account is deprovisioned it should be wiped. Nothing for her has arrived since I got the account, its all old. There shouldn't have been anything in the inbox when the account was provisioned for me
Fitz

---------------
I have reached a conclusion regarding every member of this forum.
I no longer respect any of you. I hope the following offends you as much as this thread has offended me:
You are all awful people. I mean this *expletive deleted*ing seriously.

-MicroBalrog

vaskidmark

  • National Anthem Snob
  • friends
  • Senior Member
  • ***
  • Posts: 12,799
  • WTF?
Re: Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #7 on: February 04, 2014, 05:46:55 PM »


Not exactly. When an account is deprovisioned it should be wiped. Nothing for her has arrived since I got the account, its all old. There shouldn't have been anything in the inbox when the account was provisioned for me

Using that word indicates a deep and abiding belief in the Easter Fairy, the Tooth Bunny, and rainbow chemtrails.  Please add those facts to your profile.

stay safe.
If cowardly and dishonorable men sometimes shoot unarmed men with army pistols or guns, the evil must be prevented by the penitentiary and gallows, and not by a general deprivation of a constitutional privilege.

Hey you kids!! Get off my lawn!!!

They keep making this eternal vigilance thing harder and harder.  Protecting the 2nd amendment is like playing PACMAN - there's no pause button so you can go to the bathroom.

HankB

  • friend
  • Senior Member
  • ***
  • Posts: 16,689
Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #8 on: February 04, 2014, 06:05:24 PM »
I have a similar problem with a GMail account.  I use my real name as the address for one of the accounts, and I have had that account for years.  I have been astonished to see the number of people all across the world who have the same name as me and are using that as a GMail account address . . .
Can they actually ACCESS it, or do you have the only password?
Trump won in 2016. Democrats haven't been so offended since Republicans came along and freed their slaves.
Sometimes I wonder if the world is being run by smart people who are putting us on, or by imbeciles who really mean it. - Mark Twain
Government is a broker in pillage, and every election is a sort of advance auction in stolen goods. - H.L. Mencken
Patriotism is supporting your country all the time, and your government when it deserves it. - Mark Twain

Fitz

  • Face-melter
  • friend
  • Senior Member
  • ***
  • Posts: 6,254
  • Floyd Rose is my homeboy
    • My Book
Re: Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #9 on: February 04, 2014, 06:18:39 PM »
Using that word indicates a deep and abiding belief in the Easter Fairy, the Tooth Bunny, and rainbow chemtrails.  Please add those facts to your profile.

stay safe.

Yeah, so if it is NOT done when an account is provisioned, that's a potentially MAJOR security problem. Hence me asking about reporting it.
Fitz

---------------
I have reached a conclusion regarding every member of this forum.
I no longer respect any of you. I hope the following offends you as much as this thread has offended me:
You are all awful people. I mean this *expletive deleted*ing seriously.

-MicroBalrog

BlueStarLizzard

  • Queen of the Cislords
  • friend
  • Senior Member
  • ***
  • Posts: 15,039
  • Oh please, nobody died last time...
Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #10 on: February 04, 2014, 06:25:44 PM »
I have a similar problem with a GMail account.  I use my real name as the address for one of the accounts, and I have had that account for years.  I have been astonished to see the number of people all across the world who have the same name as me and are using that as a GMail account address.  I have found out that there is a math professor in Texas, a judge in Connecticut, an Anglican minister in England, a truck driver in Kansas, an IT person in England and others too numerous to count, all with the same first and last name.

If I get junk mail for one of them, I just delete it.  For example the IT person in England signed up for match.com, and I get daily matches for 20-25 year old women within 100 miles of London.  I delete those because my wife won't let me fly to England to meet some of them.  But on occasion, I do get personal, medical, business or financial information directed to someone else.  My approach is to reply to the sender, point out that I am a healthcare risk manager north of Seattle, and although I would be happy to help them with any patient safety or malpractice issues, I am not the actual person they are looking for, and I have deleted the email and any attachments.  I probably get the most contacts for the judge in Connecticut, since I get a couple of emails per month asking if I can officiate at a wedding ceremony.  

I sometimes wonder if anyone else is getting email intended for me.

PS: I forgot to mention: my favorite is the person in Australia who signed up for some Oz equivalent of Adult FriendFinder down there.  I think he is in his mid-20's and I periodically get these private messages from these middle-aged Oz women looking for hookups with younger men.  Some of them have nude photos attached, and I can say that Oz women sure tend to be tanned, usually all over.

Well, if your wife won't let you go to london, why not ask if you can go to Oz?
"Okay, um, I'm lost. Uh, I'm angry, and I'm armed, so if you two have something that you need to work out --" -Malcolm Reynolds

MillCreek

  • Skippy The Wonder Dog
  • friend
  • Senior Member
  • ***
  • Posts: 20,015
  • APS Risk Manager
Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #11 on: February 04, 2014, 07:26:05 PM »
Can they actually ACCESS it, or do you have the only password?

They cannot access it, no.  Although I do get the occasional automatic email from Google saying that a password reset has been requested, so I know that someone is trying to capture the account.
« Last Edit: February 04, 2014, 07:30:09 PM by MillCreek »
_____________
Regards,
MillCreek
Snohomish County, WA  USA


Quote from: Angel Eyes on August 09, 2018, 01:56:15 AM
You are one lousy risk manager.

Scout26

  • I'm a leaf on the wind.
  • friend
  • Senior Member
  • ***
  • Posts: 25,997
  • I spent a week in that town one night....
Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #12 on: February 05, 2014, 12:57:48 AM »
I would simply notify eFax and the Lady whose info you accidentally received.

As long as no one tried to use her info to obtain goods and/or services in her name, then no laws were broken.


Eh, so hit happens.  However, you are advised to be cautious as to what you use the account for.
Some days even my lucky rocketship underpants won't help.


Bring me my Broadsword and a clear understanding.
Get up to the roundhouse on the cliff-top standing.
Take women and children and bed them down.
Bless with a hard heart those that stand with me.
Bless the women and children who firm our hands.
Put our backs to the north wind.
Hold fast by the river.
Sweet memories to drive us on,
for the motherland.

Fitz

  • Face-melter
  • friend
  • Senior Member
  • ***
  • Posts: 6,254
  • Floyd Rose is my homeboy
    • My Book
Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #13 on: February 05, 2014, 01:26:01 AM »
I would simply notify eFax and the Lady whose info you accidentally received.

As long as no one tried to use her info to obtain goods and/or services in her name, then no laws were broken.


Eh, so hit happens.  However, you are advised to be cautious as to what you use the account for.

I'm cancelling it. Only time I ever need to send a fax is when it's something important to the VA or whatnot. Aint' taking chances.
Fitz

---------------
I have reached a conclusion regarding every member of this forum.
I no longer respect any of you. I hope the following offends you as much as this thread has offended me:
You are all awful people. I mean this *expletive deleted*ing seriously.

-MicroBalrog

MechAg94

  • friend
  • Senior Member
  • ***
  • Posts: 33,842
Re: Who do you report a major PII breach to - Also, don't use eFax!
« Reply #14 on: February 05, 2014, 09:07:02 AM »
I have a similar problem with a GMail account.  I use my real name as the address for one of the accounts, and I have had that account for years.  I have been astonished to see the number of people all across the world who have the same name as me and are using that as a GMail account address.  I have found out that there is a math professor in Texas, a judge in Connecticut, an Anglican minister in England, a truck driver in Kansas, an IT person in England and others too numerous to count, all with the same first and last name.

If I get junk mail for one of them, I just delete it.  For example the IT person in England signed up for match.com, and I get daily matches for 20-25 year old women within 100 miles of London.  I delete those because my wife won't let me fly to England to meet some of them.  But on occasion, I do get personal, medical, business or financial information directed to someone else.  My approach is to reply to the sender, point out that I am a healthcare risk manager north of Seattle, and although I would be happy to help them with any patient safety or malpractice issues, I am not the actual person they are looking for, and I have deleted the email and any attachments.  I probably get the most contacts for the judge in Connecticut, since I get a couple of emails per month asking if I can officiate at a wedding ceremony.  

I sometimes wonder if anyone else is getting email intended for me.

PS: I forgot to mention: my favorite is the person in Australia who signed up for some Oz equivalent of Adult FriendFinder down there.  I think he is in his mid-20's and I periodically get these private messages from these middle-aged Oz women looking for hookups with younger men.  Some of them have nude photos attached, and I can say that Oz women sure tend to be tanned, usually all over.
I wonder if some of those people use numbers in their email name,but people forget to include them.   
“It is much more important to kill bad bills than to pass good ones.”  ― Calvin Coolidge