Case Library / Physical Social Engineering (Tailgating & Baiting) / TD Bank Lost Unencrypted Backup Tapes - Multistate and Massachusetts AG Settlements

TD Bank Lost Unencrypted Backup Tapes - Multistate and Massachusetts AG Settlements

Two unencrypted TD Bank backup tapes carrying data on 260,000 customers vanished in transit between Massachusetts offices in 2012; a roughly seven-month notification delay led to a $850,000 multistate AG settlement and a separate $825,000 Massachusetts settlement mandating encryption of all backup media going forward.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In late March 2012, TD Bank, N.A. lost two unencrypted computer backup tapes that had been placed in a locked canvas bag on a secure loading dock at its Haverhill, Massachusetts office for pickup by a third-party courier and transport to the bank's Springfield, Massachusetts office. The bag never arrived at its destination and was never recovered. The tapes held 1.4 million files (about 1,800 different file types) accumulated over 8 to 10 years of backups, containing personal information, including names, addresses, Social Security numbers, account numbers, dates of birth, driver's license numbers, and in some records debit/credit card numbers, for 260,000 TD Bank customers nationwide. TD Bank confirmed the incident to federal regulators on May 16, 2012, but did not notify the Massachusetts Attorney General until October 5, 2012 and did not begin notifying affected customers until on or about October 12, 2012, roughly seven months after the loss. Because the data was unencrypted, the incident triggered state data-breach-notification laws even though TD Bank found no evidence the tapes were ever accessed or the data misused. Nine state attorneys general, led by New York's Eric Schneiderman, investigated for about 18 months and reached an $850,000 multistate settlement announced October 15, 2014. Massachusetts, which had the largest number of affected residents (over 90,000), separately settled for $825,000 (announced/filed December 8, 2014, via an Assurance of Discontinuance). Both settlements required TD Bank to encrypt backup media going forward and overhaul its data-handling and vendor-security practices; TD Bank admitted no wrongdoing.

How the Attack Worked

TD Bank employees placed a locked canvas bag containing two unencrypted computer server backup tapes on a secure loading dock at the bank's Haverhill, Massachusetts office for pickup by a third-party transportation service provider, intended for delivery to TD Bank's Springfield, Massachusetts office. The bag never arrived and was never recovered; TD Bank was later unable to establish where the tapes went or who had custody of them after they left the dock. The tapes held 1.4 million files across roughly 1,800 file types, accumulated over 8 to 10 years of backups, containing varying combinations of customer names, addresses, Social Security numbers, account numbers, dates of birth, driver's license numbers, and in some records debit/credit card numbers. Because the tapes were unencrypted, their loss constituted a reportable data-security incident by default rather than a contained physical-loss event. TD Bank did not confirm and report the incident to federal regulators until May 16, 2012, roughly seven weeks to two months after the loss, and did not notify the Massachusetts Attorney General until October 5, 2012, with customer notifications beginning around October 12, 2012, a gap of roughly seven months from the loss to public notification that regulators cited as a core violation of state breach-notification timing requirements.

The Lure & the Tell

Not applicable in the classic social-engineering sense: no target was deceived by an attacker. The "reveal" was internal: TD Bank's own tracking/audit process eventually determined the bag of tapes had not reached its destination, and the bank could not reconstruct chain of custody with the courier to determine where or with whom the tapes ended up. No unauthorized party ever came forward or was identified as having possessed the tapes; the incident was treated as a presumptive breach solely because the data was unencrypted and irretrievable, not because misuse was observed.

Outcome

TD Bank became the subject of parallel state regulatory actions rather than any known instance of customer fraud. Nine state attorneys general (Connecticut, Florida, Maine, Maryland, New Jersey, New York, North Carolina, Pennsylvania, Vermont), led by New York AG Eric Schneiderman, investigated for about a year and a half and reached an $850,000 multistate Assurance of Voluntary Compliance announced October 15, 2014, requiring encrypted transport of backup tapes, armored transport for any remaining unencrypted legacy tapes, bi-annual security-policy reviews, and additional employee training. Separately, Massachusetts (whose residents bore the largest share of impact, over 90,000) reached its own $825,000 settlement (filed December 8, 2014) via an Assurance of Discontinuance, requiring TD Bank to encrypt backup-tape personal information "to the extent technically feasible," strengthen vendor-security contract terms, review its Written Information Security Program, and give prompt notice of any future incidents. TD Bank denied wrongdoing and represented that it had no evidence the tapes were ever accessed or misused.

Why It Matters

This case illustrates that "social engineering" and even "cyberattack" framing don't cover the largest category of real-world breach exposure for many organizations: mundane physical handling of unencrypted media. No hacker, no phishing email, no pretext call, just an unencrypted backup tape handed to a courier that never arrived. Regulators treated the mere loss of unencrypted PII as a reportable breach regardless of whether misuse was ever proven, and penalized the notification delay as harshly as the loss itself. For a security-awareness audience the lesson is that "confirm the data was actually misused before notifying" is not a defensible internal policy: states expect notification on loss of unencrypted PII, not on proof of fraud. It also shows regulators will pursue two independent settlements (a multistate coalition AND an individual hard-hit state) for the same underlying incident when the harm concentration justifies it.

Defenses

Post-incident remediation imposed by regulators: (1) no backup tapes transported unless encrypted, with armored/secured transport required for any legacy unencrypted tapes still in use; (2) bi-annual review of internal policies on collection, storage, and transfer of customers' personal information; (3) additional employee training on data-handling procedures; (4) contractual requirement that third-party service providers maintain appropriate security measures; (5) prompt breach-notification obligations for future incidents (Massachusetts required "as soon as practicable" notice going forward); (6) Massachusetts-specific requirement to encrypt personal information on backup tapes "to the extent technically feasible" and to review/update TD Bank's Written Information Security Program (WISP). General lesson for defenders: unencrypted physical media (tapes, drives) in transit is a chain-of-custody risk equivalent to a breach the moment custody cannot be verified; encryption-at-rest for backup media, tracked/bonded courier chain-of-custody, and pre-set notification-timeline SLAs (not "confirm fraud first, notify later") close this gap.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Unencrypted-by-Default Backup Accumulation: TD Bank's backup process accumulated 1.4 million files across 1,800 file types over 8 to 10 years without a policy requiring encryption of data at rest on removable backup tapes, consistent with the Massachusetts AG's finding that the bank's own then-existing Written Information Security Program required encryption but was not implemented at the Haverhill office; the result was years of legacy customer PII stored in a form readable by anyone who obtained the physical tape.
Countering Stage 1: Enterprise backup policy should mandate encryption of all backup media as a default, non-optional control applied at creation time, independent of how or whether the tapes are later transported; this was the single highest-leverage fix in the case and the first substantive requirement in both the multistate and Massachusetts settlements (no unencrypted tape leaves the premises; legacy unencrypted tapes require armored transport).
2
Unverified Physical Handoff to a Third-Party Courier: A bank employee placed a locked canvas bag containing the two tapes on a secure loading dock for pickup by a third-party transportation service provider, a routine inter-branch logistics pattern in which custody transferred from an internal employee to an external vendor without an in-person confirmed handoff or a scanned chain-of-custody record at pickup.
Countering Stage 2: Requiring transportation/courier vendors to scan or otherwise confirm receipt of custody at the point of pickup, before the internal employee walks away, converts an unverified dock drop into an auditable transfer with a documented start point for the chain of custody.
3
Custody Break in Transit: The bag never arrived at the Springfield office and was never recovered; TD Bank was subsequently unable to determine who had custody of the tapes after they left the loading dock, indicating the courier relationship lacked an enforced tracking or delivery-confirmation mechanism that could pinpoint where the loss occurred.
Countering Stage 3: Contractual security requirements for transportation vendors, including mandatory tracking, delivery confirmation, and liability terms, close the "silent handoff" gap; this is essentially what regulators imposed after the fact by requiring TD Bank to review and formally document its Transportation Service Providers' security practices and WISPs.
4
Delayed Internal Detection: TD Bank did not confirm to itself and report to federal regulators that the tapes were missing and unencrypted until May 16, 2012, roughly seven weeks to two months after the loss, indicating no automated reconciliation process flagged the tapes' non-arrival promptly after the expected delivery window closed.
Countering Stage 4: Automated reconciliation between "tapes shipped" and "tapes received" logs at both ends of a transfer, with an alert on any unconfirmed delivery within a defined SLA (for example 24 to 48 hours), surfaces a missing shipment within days rather than the roughly seven weeks it actually took TD Bank to confirm the loss.
5
Delayed Regulatory and Customer Notification: Even after confirming the loss internally on May 16, 2012, TD Bank did not notify the Massachusetts Attorney General until October 5, 2012 and did not begin notifying affected customers until on or about October 12, 2012, a roughly seven-month gap that regulators specifically cited as violating the "as soon as practicable and without unreasonable delay" breach-notification timing standard.
Countering Stage 5: Pre-built breach-notification runbooks that trigger on "loss of unencrypted PII" as the notification threshold, rather than waiting on "confirmed misuse of PII," remove the internal discretion that turned a physical loss into a separate, sanctionable notification-timing violation; this is the specific fix both the multistate and Massachusetts settlements codified going forward.
6
Exposure and Objective Completion: With custody of the unencrypted tapes unaccountable from the loading dock onward, the personal information of 260,000 customers was functionally exposed regardless of whether any confirmed misuse ever occurred, which triggered mandatory multistate breach-notification obligations and, ultimately, $1.675M in combined multistate and Massachusetts AG settlements plus mandated encryption and vendor-oversight reforms.
Countering Stage 6: Once unencrypted PII leaves verified custody, the exposure itself cannot be undone, so the only remaining control is minimizing blast radius, both by encrypting at the source (Stage 1) so a lost tape carries no readable data, and by promptly offering affected customers compensating protections; TD Bank did the latter after the fact via free credit monitoring (ITAC Sentinel Plus) and a zero-liability card policy referenced in its customer notification letter.
Quick Facts
Victim
TD Bank, N.A. and its customers (260,000 affected nationwide, including over 90,000 in Massachusetts and 31,407 in New York)
Location
Loss occurred in transit between TD Bank's Haverhill and Springfield, Massachusetts offices; affected customers were located nationwide, with the largest state impacts in Massachusetts (over 90,000 residents) and New York (31,407 residents).
Date
Loss: late March 2012. Confirmed/reported to federal regulators: May 16, 2012. Notice to Massachusetts AG: October 5, 2012. Customer notification began: on or about October 12, 2012. Multistate settlement announced: October 15, 2014. Massachusetts settlement filed: December 8, 2014.
Impact
Combined $1.675M in regulatory settlements, no confirmed direct fraud losses. Multistate Assurance of Voluntary Compliance (Oct 15, 2014, led by NY AG Eric Schneiderman, joined by CT, FL, ME, MD, NJ, NC, PA, VT, 9 states total): $850,000, of which New York's share was $114,106.11. Separate Massachusetts AG settlement (Dec 8, 2014): $825,000 total value, consisting of $625,000 cash ($325,000 civil penalties, $75,000 attorneys' fees/costs, and $225,000 to the AG's local consumer aid fund) plus a $200,000 credit TD Bank received for security upgrades it had already implemented. TD Bank stated it had no evidence the tapes fell into unauthorized hands and no evidence of resulting fraud; it did not admit wrongdoing in the Massachusetts filing.
Status
Confirmed
Case Type
Real-World Incident
Sector
Financial Services & Insurance
Related

Related Cases

Saudi Aramco "Badge Surfer" Claim in the 2012 Shamoon Attack - A Security-Awareness Narrative Without Primary-Source Corroboration

A widely circulated security-awareness case study (NINJIO) claims a tailgating "badge surfer" photographed passwords exposed by a clean-desk-policy failure to…

Incident 2012Read →

Shred-It and Iron Mountain Pay $1.1 Million to Settle GSA Shredding False Claims Act Whistleblower Suit (2013)

A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain, and Cintas billed federal agencies for GSA-spec…

Incident 2013Read →

Robertson, Smith & Kempson Estate Agent Refuse Sack Data Exposure (2013-2014)

A Metropolitan Police officer spotted customers' passports and tax-credit paperwork clearly visible through transparent bin bags left on the street…

Incident 2013Read →