Social Security numbers, banking information left unprotected on Arkansas PUA website [View all]
A computer programmer applying for unemployment on Arkansass Pandemic Unemployment Assistance program discovered a vulnerability in the system that exposed the Social Security numbers, bank account and routing numbers and other sensitive information of some 30,000 applicants. Anyone with basic computer knowledge could have accessed personal information for malicious purposes.
Alarmed, the computer programmer called the Arkansas Division of Workforce Services Friday morning and was told by an operator that there was no one available who could talk to him. He then tried someone at the Arkansas State Police Criminal Investigation Division, who told the programmer he would find the person he needed to talk with to fix the situation. The programmer later called the Arkansas Times for advice on whom to call. The Times alerted the Division of Workforce Services to the issue at 4:30 p.m. Soon after a message appeared on the website that said, The site is currently under maintenance.
We take the security and privacy of our applicants data very seriously, Zoë Calkins, communications director for the Division of Workforce Services, said in an email. As soon as we learned of this incident, we immediately took our systems offline to deny outside access to the network. We have engaged independent computer forensic experts to conduct an investigation and determine how this occurred and what, if any, data is at risk. We are committed to completing a full forensic review and will take all appropriate action in response to our findings.
The states rollout of Pandemic Unemployment Assistance, a new federal aid program for self-employed or contract workers whose earnings have been affected by COVID-19, has been marked by blunder and delay. The state launched the PUA application portal April 16, weeks later than many other states. Its now one of only 13 states that have yet to pay out benefits to applicants. Some 5,700 applicants who signed up during what the state called a test period were forced to resubmit information after a system error caused their supporting documentation to be deleted.
Snip
https://arktimes.com/arkansas-blog/2020/05/15/social-security-numbers-banking-information-left-unprotected-on-arkansas-pua-website