HMRC loses personal data for 25 million people in the post
UK HM Revenue & Customs has lost two CDs carrying names, addresses and bank details for the entire UK child benefit database
LONDON – The chairman of the UK’s HM Revenue & Customs (HMRC), Paul Gray, resigned yesterday (November 20) after it was announced HMRC had lost the names, addresses, bank sort codes and account numbers for 25 million people.
Chancellor of the exchequer Alastair Darling – already under fire over his £24 billion Northern Rock rescue – admitted to parliament yesterday that the loss occurred over a month ago and that the government had known about the disks lost in the post since November 10.
It emerged that a junior employee sent the entire child benefit database on two CDs to the National Audit Office against all security protocol – they were then lost in the post.
UK police are making inquiries at HMRC, which does not believe the details have fallen into the hands of identity thieves. A single set of personal address and bank details could sell for £10 to £50 on the black market.
Gray – until his resignation one of the UK’s best-paid civil servants – might not have prevented political repercussions with his decision to take personal responsibility.
The impact of such lapses of security has been highlighted in recent years with high profile losses from a number of organisations, mainly in the US: “America has seen major security breaches in both the public and private sector,” says Jonathan Armstrong, partner at international law firm Eversheds. “Last year the US Department of Veterans Affairs, a government agency which deals with the payment of benefits to current and former servicemen in the US, lost data on 26.5 million people. Store group TJX, who own TK Maxx stores in the UK also lost the bank data of more than 90 million customers. Breaches involving the loss of audit data are also not uncommon - again in the US audit firms have been involved in incidents with the loss of over 240,000 records in a single breach.”
“The effect on the banking system should also not be underestimated,” he adds. “Some of the banks whose customers were involved in the TJX breach have started proceedings to recover their losses which they put at between $68 and $83 million. It is common in the US (where a different credit system exists) to pay for credit monitoring for all of those affected in addition to the actual losses suffered.”
HMRC was created in 2005, when the Inland Revenue and Customs and Excise institutions were merged to create the largest UK government department, cutting 25,000 jobs. “The HMRC breach will undoubtedly focus attention on the security procedures of the private sector as well as Government. Now is the time for businesses to update their response plans,” says Armstrong.
The news came as a study by CA and research consultancy YouGov highlighted growing fears in the UK about identity theft and the inadequate security of consumer details.
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@risk.net to find out more.
You are currently unable to copy this content. Please contact info@risk.net to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@risk.net
More on Regulation
Credit spread risk: the cryptic peril on bank balance sheets
Some bankers fear EU regulatory push on CSRBB has done little to improve risk management
Credit spread risk approach differs among EU banks, survey finds
KPMG survey of more than 90 banks reveals disagreement on how to treat liabilities and loans
Bowman’s Fed may limp on by after cuts
New vice-chair seeks efficiency, but staff clear-out could hamper functions, say former regulators
Review of 2025: It’s the end of the world, and it feels fine
Markets proved resilient as Trump redefined US policies – but questions are piling up about 2026 and beyond
Hong Kong derivatives regime could drive more offshore booking
Industry warns new capital requirements for securities firms are higher than other jurisdictions
Will Iosco’s guidance solve pre-hedging puzzle?
Buy-siders doubt consent requirement will remove long-standing concerns
Responsible AI is about payoffs as much as principles
How one firm cut loan processing times and improved fraud detection without compromising on governance
Could one-off loan losses at US regional banks become systemic?
Investors bet Zions, Western Alliance are isolated problems, but credit risk managers are nervous