A handout photograph distributed by Syria's national news agency SANA on May 22,2013, show detained men, blindfolded and handcuffed, described by SANA as "terrorists fighters", a term commonly used to describe rebels fighting to topple President Bashar al-Assad, in Qusair, near Homs.    SANA/Handout via Reuters (SYRIA - Tags: CONFLICT CIVIL UNREST TPX IMAGES OF THE DAY) ATTENTION EDITORS - THIS IMAGE WAS PROVIDED BY A THIRD PARTY. FOR EDITORIAL USE ONLY. NOT FOR SALE FOR MARKETING OR ADVERTISING CAMPAIGNS. THIS PICTURE IS DISTRIBUTED EXACTLY AS RECEIVED BY REUTERS, AS A SERVICE TO CLIENTS

Reuters Photojournalism

Our day's top images, in-depth photo essays and offbeat slices of life. See the best of Reuters photography.  See more 

Photo

Devastated by Tornado

A huge tornado tears through an Oklahoma City suburb.  Slideshow 

Photo

Message of humility

A religious fraternity in Rio considers the election of Pope Francis, a confirmation of their beliefs in poverty and simplicity.  Slideshow 

Sponsored Links

Taxpayer data exposed in cyber attack on South Carolina agency

Related Topics

CHARLESTON, South Carolina | Sat Oct 27, 2012 9:10am EDT

CHARLESTON, South Carolina (Reuters) - As many as 3.6 million Social Security numbers and 387,000 credit and debit card numbers used by state taxpayers could have been exposed to a hacker in recent cyber attacks on the state Department of Revenue's computers, officials said on Friday.

The vast majority of the credit card numbers used by South Carolina taxpayers were encrypted, but about 16,000 were not, meaning the data was fully exposed, state police said.

None of the Social Security numbers were encrypted, said State Law Enforcement Division spokesman Thom Berry.

Berry said the hacker used a foreign Internet Protocol (IP) address to gain access to the data.

"This is not a good day for South Carolina," Governor Nikki Haley said at a news conference in the state capital of Columbia. "I want this person slammed against the wall," she said of the hacker.

"I want to get this person and make sure he can never do this to anybody or any state again," Haley said "I want that man just brutalized."

Officials said no public funds were accessed or put at risk. An investigation into the security breach is ongoing.

Investigators this month discovered two attempts to probe the Department of Revenue's system in early September, and later learned of an attempt made in late August, state officials said.

Two other intrusions occurred in mid-September, and the department determined the hacker had obtained data for the first time, according to a statement from the state.

Officials said the vulnerability in the system was closed on October 20 and the system is now believed to be secure.

Anyone who filed a South Carolina tax return since 1998 is being urged to find out whether their information was affected. The state will provide those affected with one year of credit monitoring and identity theft protection.

Earlier this year, police arrested a South Carolina state health agency employee they said had made off with almost 230,000 Medicaid recipients' personal information.

Also, the University of South Carolina said in August that a hacker had breached the personal information of as many as 34,000 people connected to its College of Education.

(Reporting by Harriet McLeod; Editing by Colleen Jenkins and Todd Eastham)

We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (1)
JamVee wrote:
I think that a partial answer to this issue is to make it mandatory that any private company or governmental entity, that collects any sort of exploitable, personal, data, should have to obtain a certification of some sort, that they are doing it properly, with sufficient security measures in place . . . Example – that number of SS numbers that were not encrypted by SC. – If most were encrypted, WHY not all of them?

Oct 27, 2012 11:12am EDT  --  Report as abuse
This discussion is now closed. We welcome comments on our articles for a limited period after their publication.