You are here: silicon.com > Financial Services > News

Halifax mortgage data stolen

A rare case where technology could have been the solution, not the problem?

Tags: halifax, nationwide, bank, data

By Will Sturgeon

Published: 27 March 2007 11:00 GMT

UK high street bank Halifax has admitted stolen documents from one of its employees contained data on 13,000 mortgage customers.

The documents were in a briefcase stolen from the locked car of an employee last week and the bank yesterday started writing to affected customers, after first reporting the breach to the Financial Services Authority (FSA) and the police.

Around 1,800 of the 13,000 customer records exposed by the theft included name, address, mortgage account number and account balance. The remainder included name, mortgage account number and approval status.

According to a spokesman for Halifax: "It would be almost impossible for any fraud to be committed with the information on the printout."

However, the bank, part of the HBOS Group, has promised: "No customer will be left out of pocket in the very unlikely event of fraudulent activity on their account following this unfortunate theft."

The theft further highlights the risk of taking data outside the organisation - whether in a digital or hard copy format. In this instance the employee was intending to use the data during meetings with mortgage intermediaries.

Proponents of encryption have argued any sensitive data should travel in an encrypted format from point to point and a spokesman for encryption experts PGP said he found the decision to cart around printouts of 13,000 customer records - protected by "nothing more than a briefcase lock" - a strange one.

He said: "When people set up a security policy there are many steps to it and one of them will be the physical aspect in terms of what form you carry data in. Nowadays with the ability to manage this information much more easily on removable media with encryption whether that is on a USB or a hard drive or whatever makes sense, why would you take this as a hard copy?"

Shane O'Riordan, general manager of group communications at Halifax, said lessons have been learned, adding: "We are reviewing our procedures as a matter of urgency."

However, the PGP spokesman said Halifax should be praised for "doing the decent thing and notifying people" - despite no requirement on UK companies to do so.

Earlier this year the Nationwide building society was fined nearly £1m by the FSA after the theft of a laptop exposed customer data.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

silicon.com Financial Services
Get the latest financial services news straight to your inbox. Sign up for the FS newsletter today!


  • Jobs
Compliance Monitoring Manager - London - Up to 65k - TRL7488

This is a key position within the clients Compliance strategy and will ensure that they can demonstrate compliance with the requirements of the ...

New Business Sales Executive - IT Managed Services - London

Apply now to with a CV in Word Format or call for a strictly confidential discussion. New Business Executives to help continually carry the business ...

Business Process Consultant

Experience of leading a team of people (i.e.subject matter experts and business analysts).Desirable experience: Experience of UK Financial Services ...

Nick Beecham and Belinda Doshi
No more tax breaks for offshoring?
Financial services firms must prepare now for 2010 legal changes

Tim Ferguson
On a new Voyager, tackling fraud and the intellectual challenge
Interview: Nationwide IT director, Peter Stafford

Nick Heath
David Lister on smart grids and why he left RBS
Interview: National Grid CIO

Andy Jones
Why banks will push ahead with offshoring
Comment: Even if they don't want to

Catherine Stagg-Macey
Legacy IT holding back insurers
Comment: Economic crisis means finance giants must step lively

Julian Goldsmith
The City fund manager with no IT department
Q&A: How asset management is embracing the cloud...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.




Quick Sitemap Links: