Texas Comptrollers' Office Posted Millions of Texans' Personal Info Online

By

While news that a retailer or financial services company has had a data breach that put private consumer information at risk is pretty much a monthly occurrence these days, it would seem that the government isn't immune from data loss, either. In this case, however, it's not about theft, but about human error. The comptroller for the State of Texas this week began notifying millions of people that their personal data – including names, addresses and social security numbers – had been posted to a public server, where it was available for as long as a year, in some cases, reported Information Week.

“I deeply regret the exposure of the personal information that occurred and am angry that it happened,” said Texas comptroller Susan Combs in a statement. “I want to reassure people that the information was sealed off from any public access immediately after the mistake was discovered and was then moved to a secure location. We take information security very seriously and this type of exposure will not happen again.”

A criminal investigation has been launched by both the Texas state attorney general and the FBI. A state spokesperson told The Dallas Morning News that an unspecified number of people were fired after the breach was discovered on March 31, 2011. The breach was reportedly discovered less than two weeks ago when other folders were being scanned in the server.

The 3.5 million breached records include 1.2 million records, posted in January 2010, of education employees and retirees from the Teacher Retirement System of Texas. In addition, 2 million records from the Texas Workforce Commission (TWC), which provides unemployment benefits to Texas residents, were posted in April 2010. Finally, 281,000 records from the Employees Retirement System of Texas, involving state employees and retirees, were posted in May 2010, said InformationWeek.

Data breaches, both accidental and criminal, are becoming more common as more personal information goes online. According to an InformationWeek article from July of last year, the Identity Theft Resource Center (ITRC) recorded 341 individual data breaches during the first six months of 2010, but hundreds more went unreported, said the organization. In addition, for 46 percent of breaches, the number of records potentially affected weren't disclosed, and for 38 percent, no cause was disclosed. The ITRC said that some states now harbor a “protected breach list” that is not made public at all, or is only accessible by exercising the Freedom of Information Act.


Tracey Schelmetic is a contributing editor for TechZone360. To read more of Tracey's articles, please visit her columnist page.

Edited by Janice McDuffee
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

TechZone360 Contributor

SHARE THIS ARTICLE
Related Articles

Your Post-Quantum Readiness Starts at Y2Q Summit

By: TMCnet News    5/27/2026

Y2Q Summit is an executive conference focused on helping enterprises prepare for the coming era of quantum computing disruption, cybersecurity transfo…

Read More

Why Award Marketing Should Be Part of Every B2B Tech Company's Growth Strategy

By: Erik Linask    5/20/2026

Award marketing matters for B2B tech companies because industry recognition can strengthen trust, support sales and partner relationships, improve con…

Read More

Why Email Is Still the Most Underrated Layer of Modern Software Infrastructure

By: Contributing Writer    5/15/2026

Take, for example, the following scenario. A user requests a password reset, waits a few seconds, refreshes their inbox and nothing arrives. They try …

Read More

Jitterbit's Visionary Status Signals a Shift in the iPaaS Market

By: Contributing Writer    4/7/2026

As enterprise ecosystems grow more complex, integration has become less of a backend IT function and more of a strategic driver of business performanc…

Read More

Cyber Extortion over hoax Breach: Lessons from a Fabricated story about IDMERIT

By: Contributing Writer    3/3/2026

Cybercriminals are increasingly staging fake data breaches to launch extortion attempts against KYC-AML companies. Recently, hackers devised a new met…

Read More