Two unencrypted TD Bank backup tapes carrying data on 260,000 customers vanished in transit between Massachusetts offices in 2012; a roughly seven-month notification delay led to a $850,000 multistate AG settlement and a separate $825,000 Massachusetts settlement mandating encryption of all backup media going forward.
Reviewed by the Social Engineering Examples team.
In late March 2012, TD Bank, N.A. lost two unencrypted computer backup tapes that had been placed in a locked canvas bag on a secure loading dock at its Haverhill, Massachusetts office for pickup by a third-party courier and transport to the bank's Springfield, Massachusetts office. The bag never arrived at its destination and was never recovered. The tapes held 1.4 million files (about 1,800 different file types) accumulated over 8 to 10 years of backups, containing personal information, including names, addresses, Social Security numbers, account numbers, dates of birth, driver's license numbers, and in some records debit/credit card numbers, for 260,000 TD Bank customers nationwide. TD Bank confirmed the incident to federal regulators on May 16, 2012, but did not notify the Massachusetts Attorney General until October 5, 2012 and did not begin notifying affected customers until on or about October 12, 2012, roughly seven months after the loss. Because the data was unencrypted, the incident triggered state data-breach-notification laws even though TD Bank found no evidence the tapes were ever accessed or the data misused. Nine state attorneys general, led by New York's Eric Schneiderman, investigated for about 18 months and reached an $850,000 multistate settlement announced October 15, 2014. Massachusetts, which had the largest number of affected residents (over 90,000), separately settled for $825,000 (announced/filed December 8, 2014, via an Assurance of Discontinuance). Both settlements required TD Bank to encrypt backup media going forward and overhaul its data-handling and vendor-security practices; TD Bank admitted no wrongdoing.
TD Bank employees placed a locked canvas bag containing two unencrypted computer server backup tapes on a secure loading dock at the bank's Haverhill, Massachusetts office for pickup by a third-party transportation service provider, intended for delivery to TD Bank's Springfield, Massachusetts office. The bag never arrived and was never recovered; TD Bank was later unable to establish where the tapes went or who had custody of them after they left the dock. The tapes held 1.4 million files across roughly 1,800 file types, accumulated over 8 to 10 years of backups, containing varying combinations of customer names, addresses, Social Security numbers, account numbers, dates of birth, driver's license numbers, and in some records debit/credit card numbers. Because the tapes were unencrypted, their loss constituted a reportable data-security incident by default rather than a contained physical-loss event. TD Bank did not confirm and report the incident to federal regulators until May 16, 2012, roughly seven weeks to two months after the loss, and did not notify the Massachusetts Attorney General until October 5, 2012, with customer notifications beginning around October 12, 2012, a gap of roughly seven months from the loss to public notification that regulators cited as a core violation of state breach-notification timing requirements.
Not applicable in the classic social-engineering sense: no target was deceived by an attacker. The "reveal" was internal: TD Bank's own tracking/audit process eventually determined the bag of tapes had not reached its destination, and the bank could not reconstruct chain of custody with the courier to determine where or with whom the tapes ended up. No unauthorized party ever came forward or was identified as having possessed the tapes; the incident was treated as a presumptive breach solely because the data was unencrypted and irretrievable, not because misuse was observed.
TD Bank became the subject of parallel state regulatory actions rather than any known instance of customer fraud. Nine state attorneys general (Connecticut, Florida, Maine, Maryland, New Jersey, New York, North Carolina, Pennsylvania, Vermont), led by New York AG Eric Schneiderman, investigated for about a year and a half and reached an $850,000 multistate Assurance of Voluntary Compliance announced October 15, 2014, requiring encrypted transport of backup tapes, armored transport for any remaining unencrypted legacy tapes, bi-annual security-policy reviews, and additional employee training. Separately, Massachusetts (whose residents bore the largest share of impact, over 90,000) reached its own $825,000 settlement (filed December 8, 2014) via an Assurance of Discontinuance, requiring TD Bank to encrypt backup-tape personal information "to the extent technically feasible," strengthen vendor-security contract terms, review its Written Information Security Program, and give prompt notice of any future incidents. TD Bank denied wrongdoing and represented that it had no evidence the tapes were ever accessed or misused.
This case illustrates that "social engineering" and even "cyberattack" framing don't cover the largest category of real-world breach exposure for many organizations: mundane physical handling of unencrypted media. No hacker, no phishing email, no pretext call, just an unencrypted backup tape handed to a courier that never arrived. Regulators treated the mere loss of unencrypted PII as a reportable breach regardless of whether misuse was ever proven, and penalized the notification delay as harshly as the loss itself. For a security-awareness audience the lesson is that "confirm the data was actually misused before notifying" is not a defensible internal policy: states expect notification on loss of unencrypted PII, not on proof of fraud. It also shows regulators will pursue two independent settlements (a multistate coalition AND an individual hard-hit state) for the same underlying incident when the harm concentration justifies it.
Post-incident remediation imposed by regulators: (1) no backup tapes transported unless encrypted, with armored/secured transport required for any legacy unencrypted tapes still in use; (2) bi-annual review of internal policies on collection, storage, and transfer of customers' personal information; (3) additional employee training on data-handling procedures; (4) contractual requirement that third-party service providers maintain appropriate security measures; (5) prompt breach-notification obligations for future incidents (Massachusetts required "as soon as practicable" notice going forward); (6) Massachusetts-specific requirement to encrypt personal information on backup tapes "to the extent technically feasible" and to review/update TD Bank's Written Information Security Program (WISP). General lesson for defenders: unencrypted physical media (tapes, drives) in transit is a chain-of-custody risk equivalent to a breach the moment custody cannot be verified; encryption-at-rest for backup media, tracked/bonded courier chain-of-custody, and pre-set notification-timeline SLAs (not "confirm fraud first, notify later") close this gap.
A widely circulated security-awareness case study (NINJIO) claims a tailgating "badge surfer" photographed passwords exposed by a clean-desk-policy failure to…
A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain, and Cintas billed federal agencies for GSA-spec…
A Metropolitan Police officer spotted customers' passports and tax-credit paperwork clearly visible through transparent bin bags left on the street…