1.4 Million Washington Unemployment Data Stolen By Hackers

Almost everyone is this planet Earth is affected by the 'COVID-19' coronavirus pandemic, in one way or the other, directly or indirectly.

And most of them, are affected in bad ways.

For unemployment claimants already struggling to pay bills and deal with delays in benefit payments, residents of Washington have another thing to worry, as a massive data breach involving the state auditor’s office has left more than a million Washingtonians’ personal information stolen by hackers.

State Auditor Pat McCarthy said the records were exposed during a December 2020 breach of Accellion, a software provider the auditor’s office used to transfer large files.

The data breach involved claimants’ names, Social Security numbers and/or driver’s license or state identification number, bank information, and place of employment, the auditor’s office said.

The compromised data had been collected as part of the auditor’s investigations into how the state Employment Security Department (ESD) lost $600 million to fraudulent unemployment claims.

Office of the Washington State Auditor - Pat McCarthy.

The auditor’s office said that the breach affects personal information of people who filed for unemployment claims with ESD between January 1, 2020 and December 10, 2020, and included a total of 1.6 million claims.

According to ESD's website, those claims represent at least 1.47 million individuals,

The auditor’s office emphasized that the breach did not originate with ESD.

“I know this is one more worry for Washingtonians who have already faced unemployment in a year scarred by both job loss and a pandemic. I am sorry to share this news and add to their burdens,” McCarthy said in a statement.

This raises fears of identity theft and fraud.

What's more, with personal information leaking from the breach, fraudsters can also have the data they need to take whatever money is in that account and electronically transfer it to an account they control.

The state auditor has set up a web page for people who think their personal information could have been exposed in the data breach.

[block:block=87]

According to Accellion’s chief marketing officer Joel York, the data breach involved the company’s decades-old “legacy product,” known as FTA, which the company has been encouraging customers to stop using.

“It just wasn’t designed for these types of threats,” York explained.

York also said that his company has been telling users for years to upgrade to Accellion’s newer product, known as kiteworks.

By the time of the breach, it is said that the auditor’s office was in the process of moving to that product.

When McCarthy was asked why her office relied on an old Accellion product that is less secure to deal with sensitive information, she said that the sate paid an annual subscription fee for the service for the past 13 years and relied on it for all this time to be safe.

“We believed that we were getting a secure system and we expected that — and the citizens of Washington state should expect that as well,” said McCarthy.

Following this data breach became known to Accellion, the Palo Alto, California-based company quickly patched the FTA vulnerability.

York added that not only auditor’s office was hacked, as 50 of Accellion's other customers were also attacked.