DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Famous Dave’s employee data stolen (update 2)

Posted on April 30, 2010 by Dissent

Here we go again…. another seemingly avoidable data theft.

A Minnetonka-based employee of Famous Dave’s left some baggage in the car of a companion, including a work-related laptop computer containing a report with unencrypted employee information. As Famous Dave’s reported to the New Hampshire Attorney General’s Office by letter on April 16, the laptop was part of what was stolen from the car on March 21. The theft was reported to the police promptly.

An internal investigation to determine what information was on the laptop indicated that it contained names and Social Security numbers for employees who worked for the company on or after November 1, 2009 and a few who left the employment of the company in 2008 and before November 1, 2009. The report contained personal information for 2 residents of New Hampshire as well as former employees of the North Country group of restaurants located in the following New Jersey and New York locations: Brick Township, Hamilton (Mays Landing), Metuchen, Mountainside, New Brunswick, Smithtown, and Westbury. The total number of employees affected by the breach was not reported.

The company offered its employees free credit monitoring services.

The firm’s letter to the Attorney General did not indicate whether the employee had violated company policy by having unencrypted data on a laptop and/or by leaving the laptop in an unattended vehicle. Which brings me to another pesky point: should a company be allowed to claim that they have all kinds of safeguards in place but that they can’t guarantee protection against criminal conduct if the data were not even encrypted and had been left in a car?

I don’t know what the situation was with this case, but I’m getting tired of seeing claims of rigorous safeguards when a laptop with unencrypted personal or financial information is stolen from an unattended vehicle, aren’t you? I called Famous Dave’s to inquire as to whether the employee had complied with existing policies, but have not received a return call as of the time of this publication.

Update 1: This breach was reported to the NYS Consumer Protection Board on April 19, according to their log. At the time, Famous Dave’s indicated that 702 NYS residents were affected.

Update 2: This breach was reported to Maryland on April 16, and the report indicates that 695 Maryland residents were affected.


Related:

  • Snowflake Loses Two More Bids to Dismiss Data Breach Plaintiffs
  • US company with access to biggest telecom firms uncovers breach by nation-state hackers
  • UK: FCA fines former employee of Virgin Media O2 for data protection breach
  • The 4TB time bomb: when EY's cloud went public (and what it taught us)
  • Another plastic surgery practice fell prey to a cyberattack that acquired patient photos and info
  • NY: Gloversville hit by ransomware attack, paid ransom
Category: Breach IncidentsBusiness SectorTheftU.S.

Post navigation

← Scottrade sues hacker
Guernsey: Data protection law amended to include prison time →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says
  • The Case for Making EdTech Companies Liable Under FERPA
  • NHS providers reviewing stolen Synnovis data published by cyber criminals

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.