Cybersecurity, Privacy, & AI

Trending Now
VA IT Official to Contractors: Bring Your AI Game or Get Axed • Chinese Hackers Target Medical, Military, and AI Research in North America • Executive Order on Artificial Intelligence Expands Cybersecurity, Federal Oversight • Lawmakers Leery About Trump Administration’s Anthropic Order • US Officials See Iran Cyber Threat Persisting Despite Preliminary Deal

GSA Took 800 Days to Notify Some Data Breach Victims

An inspector general audit revealed a number of incidents in which the General Services Administration failed to respond promptly and appropriately to data breaches. In one case, GSA took more than 800 days to notify a handful of people that it had accidentally exposed their personal information. In another, the agency took six months just to determine that a data breach had occurred, and another two months for the people affected to be notified.

The focus of the report is the GSA’s response to a September 2015 breach in which an unencrypted file with personal information about roughly 8,200 people was shared with an external auditor.

The agency first failed to notify any of these people before its 30-day deadline following notification of DHS. In January 2017, it was discovered that 26 victims still had not been notified. Contact information for 20 of them was found, but not used until December 2017. No contact information was found for the final six.

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–Saturday — Subscribe here.