December 21, 2016 By Mark Samuels 2 min read

An information leak at finance firm Ameriprise exposed sensitive financial data and highlighted the importance of password protection.

Chris Vickery of the MacKeeper security research team explained how he discovered the Ameriprise leak in a blog post. After he uncovered the data, Vickery notified Ameriprise. The firm responded by locking down the sensitive financial information.

The leak demonstrated the need for executives to implore workers to back up confidential data securely. If backups are taking place on external drives or across networks, the storage device must be password protected.

Ameriprise Leak Highlights Password Security

The information, which included Social Security numbers, bank account information and financial planning data, was discovered on a backup device in the home of an Ameriprise advisor. The drive was set to coordinate backups with the employee’s main drive in the office.

However, Vickery discovered that the devices were not password protected, meaning outside actors could intercept customer data. He unearthed the database on specialist search engine Shodan and found that Ameriprise had removed both devices and begun investigating them in an IT laboratory. The databases included sensitive business documents and customer details.

Prioritizing Security

It is difficult to understand why data was being held on a backup without password protection, according to ZDNet. It is also hard to be sure whether the Ameriprise leak is an exceptional incident or a more common concern across the organization. The firm responded by stating that it prioritizes security to maintain compliance with tough governance across the financial sector and that the data leak was an isolated case.

According to Vickery, however, an employee at the firm told him that taking the storage offline was partly a precautionary measure. The firm may have pulled the devices fearing that additional backups might exist.

Best Practices for IT Decision-Makers

Ameriprise internal workers and franchise employees must now sign a policy document that covers the safeguarding of customer information. Advisors are warned that data sent across networks in an unencrypted manner could lead to security problems.

But the Ameriprise leak highlighted how errant employee activity can lead to serious consequences, even when firms put best practices in place. Internal employees account for 43 percent of data loss, according to an Intel Security report. As a result, IT decision-makers must implement high-quality education programs that train employees to use security tools effectively. Password protection should be a cornerstone, and its importance repeatedly asserted to all employees.

More from

CISA releases landmark cyber incident reporting proposal

2 min read - Due to ongoing cyberattacks and threats, critical infrastructure organizations have been on high alert. Now, the Cybersecurity and Infrastructure Security Agency (CISA) has introduced a draft of landmark regulation outlining how organizations will be required to report cyber incidents to the federal government.The 447-page Notice of Proposed Rulemaking (NPRM) has been released and is open for public feedback through the Federal Register. CISA was required to develop this report by the Cyber Incident Reporting for Critical Infrastructure Act of 2022…

Ransomware payouts hit all-time high, but that’s not the whole story

3 min read - Ransomware payments hit an all-time high of $1.1 billion in 2023, following a steep drop in total payouts in 2022. Some factors that may have contributed to the decline in 2022 were the Ukraine conflict, fewer victims paying ransoms and cyber group takedowns by legal authorities.In 2023, however, ransomware payouts came roaring back to set a new all-time record. During 2023, nefarious actors targeted high-profile institutions and critical infrastructure, including hospitals, schools and government agencies.Still, it’s not all roses for…

What should an AI ethics governance framework look like?

4 min read - While the race to achieve generative AI intensifies, the ethical debate surrounding the technology also continues to heat up. And the stakes keep getting higher.As per Gartner, “Organizations are responsible for ensuring that AI projects they develop, deploy or use do not have negative ethical consequences.” Meanwhile, 79% of executives say AI ethics is important to their enterprise-wide AI approach, but less than 25% have operationalized ethics governance principles.AI is also high on the list of United States government concerns.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today