This article is from the source 'bbc' and was first published or seen on . It last changed over 40 days ago and won't be checked again for changes.

You can find the current article at its original source at http://www.bbc.co.uk/news/technology-30896805

The article has changed 3 times. There is an RSS feed of changes available.

Version 0 Version 1
Shoe retailer Office warned on data breach Shoe retailer Office warned on data breach
(about 4 hours later)
The Information Commissioner's Office (ICO) has warned High Street and online shoe retailer Office to clean up its act after a data breach exposed more than one million customer details.The Information Commissioner's Office (ICO) has warned High Street and online shoe retailer Office to clean up its act after a data breach exposed more than one million customer details.
The breach in May left the personal data of customers exposed, although no financial information was compromised.The breach in May left the personal data of customers exposed, although no financial information was compromised.
Office has promised to ensure the issues that led to the data breach are resolved.Office has promised to ensure the issues that led to the data breach are resolved.
But it raises questions about how and why retailers store data.But it raises questions about how and why retailers store data.
In May, the ICO was informed that a member of the public had hacked into an unencrypted historical Office database that was being stored on a server outside the core infrastructure of the retailer's current website.In May, the ICO was informed that a member of the public had hacked into an unencrypted historical Office database that was being stored on a server outside the core infrastructure of the retailer's current website.
From there, the individual gained access to the personal data of more than one million Office customers, including contact details and website passwords.From there, the individual gained access to the personal data of more than one million Office customers, including contact details and website passwords.
Same passwordSame password
"The breach has highlighted two hugely important areas of data protection - the unnecessary storage of older personal data and the lack of security to protect data," said ICO enforcement group manager Sally-Anne Poole."The breach has highlighted two hugely important areas of data protection - the unnecessary storage of older personal data and the lack of security to protect data," said ICO enforcement group manager Sally-Anne Poole.
"All data is vulnerable even when in the process of being deleted, and Office should have had stringent measures in place regardless of the server or system used."All data is vulnerable even when in the process of being deleted, and Office should have had stringent measures in place regardless of the server or system used.
"The need and purpose for retaining personal data should also be assessed regularly, to ensure the information is not being kept for longer than required.""The need and purpose for retaining personal data should also be assessed regularly, to ensure the information is not being kept for longer than required."
There is no evidence that the information accessed has been further disclosed or otherwise used.There is no evidence that the information accessed has been further disclosed or otherwise used.
But the hack highlights the potential problems involved in having the same password for all online accounts.But the hack highlights the potential problems involved in having the same password for all online accounts.
"This one incident could potentially have given the hacker access to numerous accounts that the clients held with other organisations, as passwords were included on the database in question," said Ms Poole."This one incident could potentially have given the hacker access to numerous accounts that the clients held with other organisations, as passwords were included on the database in question," said Ms Poole.
"It's important to use a unique, strong password for each separate account; preferably a combination of numbers and letters - not a name or dictionary word.""It's important to use a unique, strong password for each separate account; preferably a combination of numbers and letters - not a name or dictionary word."
Brian McCluskey, chief executive of Office Holdings, has agreed to a series of measures including:Brian McCluskey, chief executive of Office Holdings, has agreed to a series of measures including:
In response to the enquiry he said "Office took this breach extremely seriously as our customers are our number one priority and our e-commence offering is an important part of our trading platform."