South Carolina taxpayer server hacked, 3.6 million Social Security numbers compromised
October 26th, 2012
07:56 PM ET

The Social Security numbers of millions of South Carolinians, as well as credit and debit card information for hundreds of thousands, have been hacked in what the state's governor described Friday as an international cyberattack.

"This is not a good day for South Carolina," Gov. Nikki Haley told reporters.

The governor explained that a "server that warehouses all our taxpayer information was breached and taxpayer information was stolen."

The state's Department of Revenue explained in a press release that it first learned of a possible breach on October 10, after which the state contracted information security firm Mandiant to conduct an investigation.

The "hole" in the system was closed October 20. Over the next several days, state authorities determined that more than 3.6 million Social Security numbers may have been affected. So, too, were 387,000 credit card numbers - though only 16,000 of those were unencrypted.

On Friday, state officials laid out efforts to determine what happened and protect the personal information of taxpayers. While noting that not everyone had their information breached, Haley urged everyone who filed a tax return in South Carolina from 1998 through now to take advantage of credit protection services being offered by the state.

"While we now have it protected, we want to make sure that everybody understands that our state will respond with a big, large-scale plan that is somewhat unprecedented to take care of this problem," the governor said.

    As long as we have a governments more focused on fleecing the middle class (the rich NEVER pay taxes) for spending money on handouts. illegals, and welfare instead of spending the monies to benefit the middle class including protecting their dwindling wealth, this will continue.

    And the TP wants to deregulate everything....Like the contaminated spinal injections...They will regulate themselves...yea right...

    • AGeek

      The obligation on the state is to *encrypt* the data so it's not sitting there like ripe cherries, waiting to be picked.

      October 28, 2012 at 9:15 am | Report abuse |
  7. rswon

    Do you actually WORK in IT. I doubt it. I work in a group that manages about $5 million dollars worth of servers, Linux, Solaris, Mac and Windows. Guess what? They ALL have vulnerabilities. We are constantly pushing out updates.

    October 27, 2012 at 11:03 am | Report abuse |
    • sanchanim

      So unless the hackers were able to decrypt the information they only really had immediate access to about 16,000 numbers.
      I am interested on how they were able to access what should be an internal system, for the most part. It is good that most of the data was encrypted, as that is your last level of protection. You can certainly limit port access, IP subnet access, and use two factor authentication.
      I would hope that other states would work with South Carolina and begin to implement stronger security policies. A lot of post mortem will need to be completed on this to find out exactly what happened, and how to prevent others from falling to the same type of attack.
      Nothing is totally safe, but IT security is risk mitigation. In this instance they mitigation was not strong enough. My only hope is that they will share their findings with others to strengthen the systems for all states as a whole.

      October 27, 2012 at 3:22 pm | Report abuse |
    • CBA in SC

      Actually, if you can believe it, the SSN's were **not** encrypted! That's what has me mad more than anything about his whole situation.

      October 27, 2012 at 8:18 pm | Report abuse |
    • nonliterit

      then you should at least encrypt all the life altering info we willing allow you, our employees, to hold for us. If you want to espouse the high tech equipment that is "so much more efficient" and promised, swore to, was safeguarded. So all you high tech guys cant guarentee crap. why do you call yourselves professionals. The equiipment is useless if you cannot safeguard the financial info of your employers. Go back to hardcopies and files til you sort it out. Until you do, you are snake oil salesmen.

      October 27, 2012 at 3:50 pm | Report abuse |
  14. Equitable Response

    Credit monitoring services is a reasonable response from a bank not from the state. How about efforts to change those SSNs stolen. Working with Credit Card Companies to issue new Credit Card numbers. Maybe it's just me but If I just stole thousands of SSNs I would sit on them for 5-10 years until the people thought it all passed and then exploit them.

    How about a real solutions like:
    * encryption
    * social security number reform to uphold the law that it not be used for anything other than social security. i.e. a unique state tax id

    The response for the governments failure to adequately protect the tax information is stupid.

    Government says you must pay us or you will be fined. Continued failure to pay may result in charges and jail time. So the citizens comply. However, we will keep this on a server without having all the information encrypted. After the information is hacked the declaration is that the state is "that our state will respond with a big, large-scale plan that is somewhat unprecedented to take care of this problem" and just how is that large-scale plan going to be paid for? Oh, right more taxes.

    October 27, 2012 at 11:43 am | Report abuse |
