Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Adding Insult to Injury: Government Agency Security Incidents Expose Unemployed Personal Data

By Scot Ganow, Jennifer Brumby & Ashley Crossland on June 3, 2020
Email this postTweet this postLike this postShare this post on LinkedIn

Losing a job and struggling with finances have added significant stress to those trying to stay safe during the COVID-19 pandemic. It is no secret that for weeks, state departments administering unemployment compensation have been under fire due to massive backlogs of unprocessed claims. Adding to claimants’ frustrations are a number of security incidents affecting several states’ agencies. We previously reported that the Small Business Administration experienced a breach compromising personal data for thousands of applications for financial assistance. Now we are seeing state level entities experiencing security compromises.

Pandemic Unemployment Assistance (PUA) is unemployment compensation available to self-employed and “gig” workers. In the past several weeks, thousands of workers in several states who applied for PUA received notice that their personal information was possibly exposed to other users. The personal information exposed included social security numbers, addresses, names, and the amount workers were receiving in benefits. Fortunately, at least at this time, there is no evidence personal information was misused and the alerts from the states were preventative.

  • Ohio. According to Ohio’s Department of Job and Family Services (ODJFS), 24 people had access to other users’ information. In Ohio, Deloitte Consulting is under contract with ODJFS to develop the system to administer the PUA program. ODJFS stated Deloitte fixed the issue within one hour of the unauthorized access being identified. ODJFS contacted the individuals who had accidental access to the system data. The state told applicants that Deloitte would offer free Experian Identity Works protection services for the next 12 months.
  • Illinois. After a significant delay, the Illinois’ PUA system launched last week, and 50,000 PUA claims have since been processed. A preliminary analysis performed by the Illinois Department of Employee Security (IDES) found at least one claimant was able to inadvertently access other users’ information, but the results of a full-scale investigation are pending. IDES intends to explore further remediation with Deloitte Consulting upon completion of the investigation.
  • Colorado. Six claimants reportedly accessed other users’ applications from May 2, 2020, through May 15, 2020. The 72,000 people in the state’s PUA system were reportedly offered 12 months of free credit monitoring.
  • Florida. The Florida Department of Economic Opportunity announced 98 claimants were affected by a “data security incident.” The state also offered identity protection services at no charge to affected individuals. The agency discovered the breach within one hour and has not received any reports of malicious activity related to the breach.
  • Arkansas. On May 16, 2020, Arkansas announced it was shutting down its gig worker unemployment program after it apparently was accessed illegally.
  • Washington. This past month a fraud ring attacked Washington State’s unemployment system, which had to shut down all unemployment payments for a two-day period.
  • New York. In April, New York’s unemployment insurance system accidentally leaked personal information.

Such news is hardly uncommon. We have already written on the ways mistakes and the actions of bad actors are affecting the security of personal data. However, this news is particularly painful and tragic as we see individuals already struggling with the hardships of unemployment now having to deal with the added stress and steps required to protect their personal data against misuse.

Times of crisis understandably distract us from the things that routinely keep us safe and operational. Consumers and businesses, alike, need to remain vigilant when it comes to safeguarding personal information, now more than ever. Consumers should take charge of their personal data, whenever possible. Consumers should regularly review accounts for any irregular activity and report such activity immediately. Credit accounts should be frozen to protect against unauthorized access. The process is simple and inexpensive, and often free.

Businesses should regularly audit system activity for irregular activity and take steps to actively upgrade and improve security, especially as new threats emerge. Companies should exercise diligence any time they update company systems with new software to ensure such software does not introduce security vulnerabilities. The bad guys are looking for just one door to be opened, even momentarily. Again, when companies are faced with keeping the lights on and employees employed, it can be understandable that data privacy and security might take a back seat. However, as we have found out, failing to keep privacy and security in focus can only make tough times even worse.

Photo of Scot Ganow Scot Ganow

Scot is a partner at Taft and is chair of the firm’s Privacy, Security, and Artificial Intelligence Practice.  As a former chief privacy officer leveraging more than 10 years of management and compliance experience in Fortune 500 companies prior to law school, Scot…

Scot is a partner at Taft and is chair of the firm’s Privacy, Security, and Artificial Intelligence Practice.  As a former chief privacy officer leveraging more than 10 years of management and compliance experience in Fortune 500 companies prior to law school, Scot brings a diverse business background to his practice at Taft.  Scot represents clients in a variety of sectors, including consumer reporting, construction, healthcare, broadband services, and manufacturing.

Read more about Scot GanowEmailScot's Linkedin Profile
Show more Show less
Photo of Jennifer Brumby Jennifer Brumby

Jennifer represents clients throughout Ohio in both federal and state courts in litigation matters related to employment agreements, personnel policies and workers’ compensation. With previous experience working in-house as a human resources manager and attorney in the public sector, Jennifer has direct experience…

Jennifer represents clients throughout Ohio in both federal and state courts in litigation matters related to employment agreements, personnel policies and workers’ compensation. With previous experience working in-house as a human resources manager and attorney in the public sector, Jennifer has direct experience working with clients on labor and employment issues such as recruitment, performance evaluations, disciplinary actions, benefits programs, collective bargaining matters and ensuring employee procedures and policies are in compliance with state and federal laws.

Read more about Jennifer BrumbyEmail
Show more Show less
  • Posted in:
    Employment & Labor, Privacy and Cybersecurity
  • Blog:
    Taft Privacy & Data Security Insights
  • Organization:
    Taft Stettinius & Hollister LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo