Slashdot Mirror


Computer With UK Bank Customer Data Sold On eBay

Walpurgiss tips a BBC News story about a man in Oxford who paid $140 for a computer on eBay, and was shocked to find on it bank records of several million customers of the Royal Bank of Scotland, its subsidiary Natwest, and one other bank. "Mr. Chapman said anyone with a basic knowledge of computer software would have been able to find the data fairly simply. 'The information was in back-up CDs and in ISO files so it would have been possibly quite easy to find...,' he said."

1 of 184 comments (clear)

  1. Re:Defending the indefensible? by rapiddescent · · Score: 5, Informative

    as another tech contractor who has worked in the past at 113DS, FR and GF - I know what you mean about getting dev access or access to one of the gigantic machine rooms. I would say that RBS core systems and its brands (natwest, coutts, Ulster(s)) are extremely secure to the point of not being able to do any work. Even the due process to make a change to a production system is amazing with full-time boards spending all day evaluating every change.

    from what I read on finextra.com, it looks like this box was owned by a supplier firm and subsequently was stolen by an employee of the supplier firm and sold on ebay. Also, the box had not been used since 2005 - perhaps an old server in the cupboard (of the supplier Graphic data) that an employee thought they could sell on ebay. I am struggling to see how this would have happened as a badged RBS server at one of the EDI datacentres. They run a tight ship.

    one thing for sure, Graphic Data can kiss goodbye to their contract with RBS - one thing I know abut RBS is that they are very worried about security breaches - especially public ones like this.