Skip to Content, Navigation, or Footer.
Tuesday, Aug. 4
The Indiana Daily Student

IU must take more action about security breach

Let us say from the start that we are not writing to complain about the lack of security at the Bursar's office at IU, under Susan Cote, that allowed our, and more than 3,000 other students', Social Security numbers to be stolen. The lax security with vital information is troubling, and will be dealt with by the media, administration and possibly attorneys. What we are concerned with is the irresponsible and unsympathetic way the University has handled the situation. \nFirst, nowhere in the letter that most of us received Feb. 24 did the University mention the date of the actual theft. The only reference to the incident is to "early February." We had to learn through the IDS that graduate student information was vulnerable from Feb. 5-6, and other students' information was vulnerable after Jan. 26. \nThe University should have immediately informed the general student body that a break-in had occurred and that everyone should check his or her credit and bank accounts just to be safe. Instead, we received a short letter last Saturday, meaning the first chance we had to rectify the Bursar's admitted mistake was Monday, Feb. 26, three weeks after the security breach. \nMoreover, the date our information first became vulnerable is a key piece of information for helping us avoid and detect erroneous credit card, bank and utility charges. The fact that the University did not include this in the letter is completely irresponsible and demonstrates extreme insensitivity to the plight of the students who now have to meticulously call national credit agencies, credit card companies, banks, etc. \nSecond, the letter sent to students was devoid of important information to help us avoid future fraud. The three most basic, although not only, threats of fraud to students are illegal access to existing credit cards, illicit generation of new credit accounts and unauthorized access to bank accounts. \nA number of safeguards to future fraud are possible, including placing fraud warnings on your credit accounts, changing your credit card numbers, and placing passwords on all bank accounts and/or changing account numbers. None of this information was given in the letter.\nThe short letter merely noted that, "at a minimum," banks and credit card companies should be contacted. While this is good advice, the government Web site for identity theft lists contacting the three national credit agencies as a first line of defense against fraud. At the very least, the University could have included the phone numbers for these three companies. It did not.\nThird, some students attempted to call the Bursar's office to inquire further about the incident. The representative said to at least two students the security breach was, "no big deal," and that the perpetrator was foreign and "would not know what the numbers meant." Mike Brunker of MSNBC reports that between VISA and MasterCard alone online credit card fraud costs customers $21 million a year. This figure does not include traditional transactions or even Internet fraud from the other major credit cards. Furthermore, while Internet fraud is increasingly becoming internationalized, to date there have been no prosecutions of overseas Internet thieves. We are sorry, staff at the Bursar's office, international identity thieves know what the numbers mean, they know how to use them, and they know how to get away with it.\nFinally, students who have been affected by this egregious violation of privacy have spent hours dealing with possible repercussions. Some students have spent more than five hours on the phone the last two days dealing with credit agencies, credit card companies and banks. If each student affected spent the same amount of time, that is over 150,000 hours students have spent attempting to avoid paying for the Bursar's offices mistakes.\nThe University promises in the "IU Code of Student Rights, Responsibilities, and Conduct" that, "a student has the right to have his or her education records maintained on a confidential basis by the University." It is clear that this promise was broken. Yet, what is worse, the University has not attempted to help students clean up the mess that the Bursar's office made. \nInstead of telling us not to worry and hoping for the best, the party at fault, the University, should be going out of its way to help us prevent any possibility of fraud. \nIf there is any lesson to be learned, the Bursar's office and the University should rethink their policy of using Social Security numbers as student identification numbers. This practice exponentially increases the risk of identity theft. Also, the Bursar's office should offer remuneration to students who must now pay for credit reports and Social Security traces. Thus far, the University has made no promise or offer of help. \nThe bottom line is that the University needs to take responsibility for its mistakes by responding with helpful, timely advice and resources to address the serious problems this violation of students' rights has created.

Get stories like this in your inbox
Subscribe