Texas Comptroller takes blame for major breach

Breach that exposed social security numbers of 3.5 million Texans has already led to firing of two IT execs

Days after firing two IT managers after a data breach exposed the Social Security numbers and other personal data of over 3.5 million Texans, Texas Comptroller Susan Combs took personal responsibility for the incident.

In a statement issued by her office on Thursday, Combs apologized for the debacle and said her office would cover the cost of identity monitoring and restoration services for anyone affected by the breach.

The free credit monitoring services are available starting today.

"I am deeply sorry this incident occurred and I take full responsibility for it," Combs said in the statement. "This incident has affected the lives of Texans that I have dedicated my life to serving, and I am determined to restore their faith in the Comptroller's office."

Earlier this month, Combs' office disclosed that Social Security numbers, driver's license numbers, and names and addresses of more than 3.5 million Texas residents had been inadvertently exposed on a publicly accessible Web site for nearly a year.

The exposed data was included in files sent to the State Comptroller's office by the Teacher Retirement System (TRS) of Texas, the Texas Workforce Commission and the Employees Retirement System of Texas (ERS) for use in a property verification system. The data was mistakenly sent unencrypted to the Comptroller's office.

Following the discovery of the breach, the heads of information security and of innovation and technology at the Comtroller's office were fired, and consulting firm Deloitte and Gartner was hired to review its security measures and recommend changes.

Combs also said that her office will be implementing a series of additional measures -- including the installation of new data leak prevention software and an enhanced file transfer system featuring robust encryption capabilities -- to mitigate the chances of a similar incident.

The Comptroller's office will also be adding staff, including a new chief privacy officer, and reorganizing internal reporting structures to strengthen security, she said. The chief privacy officer will work with the office's CTO, information security officer and internal auditor to shore up privacy practices, Combs added.

The breach has already cost the Comptroller's office more than $1.8 million and could end up costing a a whole lot more, according to reports.

So far, the state has spent $1.2 million on sending out notification letters, close to $300,000 for Gartner and Deloitte's services and another $393,000 to set up a call center for handling queries from those affected by the breach, according to The Austin American-Statesman's statesman.com Web site.

In addition, the Web site noted that the identity monitoring service being offered by Combs' office could cost up to $21 million if everybody enrolled in it. Combs has stated that she will bear the cost of identity restoration services from her own campaign funds, the publication noted.

Combs' office did not respond to a request to confirm the estimated costs listed on statesman.com.

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan , or subscribe to Jaikumar's RSS feed . His e-mail address is jvijayan@computerworld.com.

Read more about security in Computerworld's Security Topic Center.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags privacy

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Jaikumar Vijayan

Jaikumar Vijayan

Computerworld (US)
Show Comments

Cool Tech

Bang and Olufsen Beosound Stage - Dolby Atmos Soundbar

Learn more >

Toys for Boys

ASUS ROG, ACRONYM partner for Special Edition Zephyrus G14

Learn more >

Nakamichi Delta 100 3-Way Hi Fi Speaker System

Learn more >

Sony WF-1000XM3 Wireless Noise Cancelling Headphones

Learn more >

Family Friendly

Mario Kart Live: Home Circuit for Nintendo Switch

Learn more >

Philips Sonicare Diamond Clean 9000 Toothbrush

Learn more >

Stocking Stuffer

SunnyBunny Snowflakes 20 LED Solar Powered Fairy String

Learn more >

Teac 7 inch Swivel Screen Portable DVD Player

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?