The Inquirer-Home

Parcelforce causes privacy brouhaha

Sending out all your private data
Fri Jun 19 2009, 15:21

IN YET ANOTHER blow to people's personal data, UK website Parcelforce has been called out for exposing postcodes, parcel specifics, people's names, addresses and signatures on its website.

The BBC ‘received' a shock when it discovered a glitch in the system that gave users access to a scammers paradise of information when using the site's "track and trace" feature. Inputting a reference number allegedly pulled up all sorts of odds and sods unrelated to the actual package denoted by the code, including already delivered parcels which had been signed for, along with their proof of delivery documents.

Proof of delivery forms tipped up with people's names and postcodes as well as their signatures, delivering quite an unpleasant possibility of identity theft and fraud.

Parcelforce, a subsidiary of the Royal Mail Group, swiftly dispatched an apology, saying the problem had started sometime "after work" (noon? 5pm?) on Wednesday [while employees were probably down the pub getting parcel faced - Ed], and wasn't noticed until early (10pm?) on Thursday morning.

Meanwhile, the Information Commissioner's Office (ICO) was none too pleased by the parcel farce, saying in a statement that it would be "contacting Parcelforce to establish how this security breach occurred and to find out what steps it will be taking to ensure that such a breach cannot happen again."

Let's just hope no one goes postal over this. µ

Share this:

Comments
Not unusual

This seems to be a common problem, especially among the smaller tracking systems. On several occasions I've received an email to let me track my parcel and by simply varying the tracking number by a few digits either side have been able to display other delivery details. Generally not as much as reported by the Beeb but worrying nevertheless..

posted by : peterg22, 22 June 2009 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Authorities in several countries raided Megaupload recently, shut down all of its services, seized hundreds of servers and arrested several of its executives on criminal charges.

Do you think the move was justified?