Customers affected by WDFW vendor license sales data breach will be notified
Published 2:03 pm Thursday, September 8, 2016
Buyers of Washington state hunting and fishing licenses whose personal information may have been compromised by a data breach will be notified and will receive identity protection services, officials of the Washington Department of Fish and Wildlife (WDFW) said Sept. 6.
ACTIVE Network, the department’s online hunting and fishing license sales vendor, has agreed to mail information as soon as possible to an estimated 1.5 million WDFW customers who created “customer profiles” in the license system before July 2006, said Peter Vernie, WDFW Licensing Division manager.
Personal information for approximately 2.4 million license buyers may have been compromised in the breach which caused the department to suspend all hunting and fishing license sales from Aug. 22 to 29.
Vernie said vendor also has agreed to provide a customer call center and identity protection services to those whose data was potentially compromised.
Vulnerable information for Washington customers includes names, addresses, dates of birth, and the last four digits of their Social Security numbers. Some customers’ driver’s license numbers also were accessed, but there is no indication that credit card or other financial data was exposed, WDFW officials said.
About two weeks ago, fish and wildlife agencies in Washington, Idaho, and Oregon, received messages from a person who claimed to have accessed customer data in the three states’ systems, which are all operated by ACTIVE Network. The WDFW investigated, along with the state Office of Cyber Security and federal law enforcement agencies, and confirmed that Washington’s system vulnerability had been exploited to access personal information provided by customers who bought licenses before mid-2006.
Information added to those accounts since then is also vulnerable, investigators reported. They do not believe personal data is at risk for customers who made their first license purchase after June 2006.
A statement today from ACTIVE Network said within 15 hours of learning of the incident, the vendor conducted a “full security sweep” of the system and released an update designed to address the reported threat. The company said it also arranged for a review by an independent, highly regarded cybersecurity firm.
WDFW halted online license sales on Aug. 22 and suspended all license transactions the following day, while information technology specialists investigated the incident and the system’s security.
The department restored sales through its network of about 600 retail vendors on Saturday, Aug. 27, and resumed telephone sales through its customer service center on Monday, Aug. 29. Vendor and telephone sales account for more than 80 percent of total license sales.
The investigation into the data breach is ongoing, and online license sales remain suspended.
Additional information, including advice for people who are concerned about the security of their personal data, is available on WDFW’s website at http://wdfw.wa.gov/licensing/wild_system.
