California DMV

California DMV Data Breach Allowed Social Security Information of Thousands to Be Improperly Accessed

The DMV, already besieged by other issues, says that 3,200 license holders had their data improperly exposed to federal agencies, including immigration authorities.

Facing problems ranging from long wait times to staffing and management issues, the California Department of Motor Vehicles announced Tuesday that it has also suffered a “data breach” that allowed federal agencies to improperly access Social Security information of 3,200 people in the state.

Immigration authorities were among the agencies who had access to the Social Security information, including if a person issued a license did not have a Social Security number, The Los Angeles Times reported. The information was disclosed through the Government Requested Code Account Program, which allows those agencies to access DMV information but only “for limited purposes under state and federal law,” according to CNN.

Seven agencies, including the Department of Homeland Security, the Internal Revenue Service and district attorneys in San Diego and Santa Clara Counties, accessed the information over the past four years.

After discovering the “breach” on Aug. 2, the DMV cut off access to the information. No hacking was involved, and private individuals were not given access to Social Security information, according to the DMV’s spokeswoman Anita Gore.

“Protection of personal information is important to DMV, and we have taken additional steps to correct this error, protect this information and reaffirm our serious commitment to protect the privacy rights of all license holders,” Gore told the Times. “That’s why DMV immediately began correcting the access error following a legal compliance review, ensured that no additional confidential information was disclosed to these entities, and has implemented several additional layers of review.”

The situation is further complicated by the fact that beginning in 2013, the DMV has issued driver licenses to people in the U.S. illegally who can provide proof of identity and California residency, according to the Times. At the time, government officials said that the information of license holders in the country illegally would not be shared with federal immigration authorities.

The DMV said that 83 of the license holders who had information accessed by federal agencies did not have proof of legal presence in the United States. Other Californians had their information accessed as part of tax and child support investigations.

In total, the San Diego and Santa Clary district attorney offices were responsible for improperly accessing the data of about 3,000 license holders. All people affected by the breach have been notified by the DMV.

Tim Erlin, the VP of product management and strategy at cybersecurity firm Tripwire, said that many breaches are not the result of malicious attacks, but a “consequence of misconfigurations.”

“In these cases, there’s no stereotypical ‘bad guy’ to arrest, but often a group of well-meaning, but overworked and under-skilled staff that either couldn’t keep up or just didn’t know any better,” Erlin said. “Finding and addressing misconfigurations can be automated, but you have to start with an understanding of how the systems should be configured in order to measure how they differ from that desired state.”

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Maximizing Your Security Budget This Year

    7 Ways You Can Secure a High-Traffic Commercial Security Gate  

    Your commercial security gate is one of your most powerful tools to keep thieves off your property. Without a security gate, your commercial perimeter security plan is all for nothing. Read Now

  • Surveillance Cameras Provide Peace of Mind for New Florida Homeowners

    Managing a large estate is never easy. Tack on 2 acres of property and keeping track of the comings and goings of family and visitors becomes nearly impossible. Needless to say, the new owner of a $10 million spec home in Florida was eager for a simple way to monitor and manage his 15,000-square-foot residence, 2,800-square-foot clubhouse and expansive outdoor areas. Read Now

  • Survey: 72% of CISOs Are Concerned Generative AI Solutions Could Result In Security Breach

    Metomic recently released its “2024 CISO Survey: Insights from the Security Leaders Keeping Critical Business Data Safe.” Metomic surveyed more than 400 Chief Information Security Officers (CISOs) from the U.S. and UK to gain deeper insights on the state of data security. The report includes survey findings on various cybersecurity issues, including security leaders’ top priorities and challenges, SaaS app usage across their organization, and biggest concerns with implementing generative AI solutions. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

Featured Cybersecurity

Webinars

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge. 3

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3