Daily Breeze (Torrance)

Report: State gun data breach was unintentio­nal

- By Adam Beam

SACRAMENTO » California's Department of Justice mistakenly posted the names, addresses and birthdays of nearly 200,000 gun owners on the internet because officials didn't follow policies or understand how to operate their website, according to an investigat­ion released Wednesday.

The investigat­ion, conducted by an outside law firm hired by the California Department of Justice, found that personal informatio­n for 192,000 people was downloaded 2,734 times by 507 unique IP addresses during a roughly 12-hour period in late June. All of those people had applied for a permit to carry a concealed gun.

The data was exposed just days after the U.S. Supreme Court ruled that people have a right to carry guns in public. The decision invalidate­d a California law that said people must give a reason for wanting to carry a concealed weapon, such as a threat to their safety. Lawmakers then tried to pass new restrictio­ns for concealed carry permits, but failed.

Investigat­ors said they “did not uncover any evidence that the timing of the (data breach) was driven by a nefarious intent or was personally or politicall­y motivated in any way.” Instead, they said state officials planned to publish what they thought was anonymous data “to meet anticipate­d heightened public interest in firearms-related data” following the court ruling.

An intentiona­l breach of personal informatio­n carries more stiff fines and penalties under California law, according to Chuck Michel, an attorney and president of the California Rifle & Pistol Associatio­n. Michel said his group is preparing a class action lawsuit against the state. He noted the leaked data likely included informatio­n from people in sensitive positions — including judges, law enforcemen­t personnel and domestic violence victims — who had sought gun permits.

“There is a lot of gaps and unanswered questions, perhaps deliberate­ly so, and some spin on this whole notion of whether this was an intentiona­l release or not,” he said. “This is not the end of the inquiry.”

The Department of Justice contracted with the Morrison Foerster law firm to investigat­e the data exposure. The firm said it had “the mandate and autonomy to conduct an independen­t investigat­ion that followed the facts and evidence wherever they led.”

Officials at the California Department of Justice did not know about the breach until someone sent Attorney General Rob Bonta a private message on Twitter that included screenshot­s of the personal informatio­n that was available to download from the state's website, the investigat­ion said.

State officials at first thought the report was a hoax. Two unnamed employees — identified only as “Data Analyst 1” and “Research Center Director” — investigat­ed and mistakenly assured everyone that no personal informatio­n was publicly available.

Meanwhile, the website crashed because so many people were trying to download the data. Another group of state officials worked to bring the website back online, unaware of the breach. They got the website working again at about 9:30 p.m.

Newspapers in English

Newspapers from United States