Nearly 100 organizations have been notified by the Federal Trade Commission that “sensitive data” about customers and employees has been taken from their computer networks and made available on peer-to-peer (P2P) file-sharing networks. The FTC said Monday that it has also opened “nonpublic investigations” of other companies whose information has been “exposed” on the P2P networks.
As part of its effort to help businesses deal with the security risks posed by this kind of breach and P2P technology, the FTC said it is making available new educational materials about the nature of the risks and how to manage them.
Failure ‘May Violate Laws’
The notices have gone to public entities, including schools and local governments, as well as private businesses. The contacted organizations are as small as eight employees and as large as publicly held corporations with tens of thousands of employees.
In part, the FTC letter said it was sent “because at least one computer file containing sensitive personal information from or about your customers and/or employees” has been shared on P2P networks. The letter also named one of the breached files from that organization.
The letter warned that “your failure to prevent such information from being shared to a P2P network may violate laws” enforced by the FTC, although it added that no determination of violation has yet been made.
In addition to notifying the organizations of security breaches, the notices urged them to “review their security practices” as well as those of their contractors and vendors. The FTC also recommended that companies and public organizations identify affected customers and employees and “consider whether to notify them that their information is available on P2P networks.”
‘An Open Market’
FTC Chairman Jon Leibowitz said the agency found “health-related information, financial records, and drivers’ license and social-security numbers” exposed. He added that “companies should take a hard look…