Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceCybersecurity NewsBanking/Finance/Insurance

SBA Loan Application Data Breach: What You Can Do

By Larkin Reynolds
data breach
April 27, 2020

On April 21, the Small Business Administration (SBA) revealed that around 8,000 small business loan applicants had their potentially sensitive information exposed in a data leak affecting the website being used to host the online application. The affected site was the service collecting applications for the Economic Injury Disaster Loans (EIDL) program, meaning that any applicant who submitted information prior to March 25, 2020, could have been affected.  

What We Know

From what’s been announced publicly, it doesn’t sound like there were bad actors at play, but rather this was likely a configuration error that permitted some applicants to view the information submitted by other businesses that had previously submitted an application. This means that there’s somewhat less of a risk that the data would be misused. In other words, the business owner applicants are slightly less likely than the average cybercriminal to attempt to misuse any data that they could have obtained. But, if the information was available to public users, then it’s possible it was open to cybercriminals as well through other channels. Also, with tax-filing deadlines extended this year, there is a longer window for a fraudster to take advantage of the compromise.  

A few types of information are likely of concern here, the first of which is individual taxpayer information. Many eligible companies are sole proprietorships or pass-through LLCs, many using their social security numbers as their taxpayer identification number. Further, every applicant had to provide a social security number to even begin the application (see the main EIDL application page).  

What can you do? Here are a few steps to minimize your exposure.

  • Compare dates to determine if your information could have been available via the compromised site prior to March 26, 2020 (the date the SBA discovered the leak; they immediately took down the site to resolve the issue).
  • Take a few steps to protect yourself from tax fraud. Even a name and an individual social security number together can lead to tax fraud.
    • One of the main types of misuse of social security number data involves filing a fraudulent return to get the 2019 tax refund. Colorado taxpayers and residents of many other states are eligible for an IP PIN from the IRS to prevent any fraudulent filings.
  • The IP PIN program isn’t eligible for everyone by default. Currently, Coloradans are eligible as of the 2020 filing season if they filed last year as CO resident. The same goes for New Yorkers and Californians.
  • The SBA announced it was providing ID theft protection monitoring to affected businesses, so take advantage of it. It is a valuable tool to have and also helps build good business habits 
  • Consider placing a credit freeze on personal credit accounts, which will prevent bad actors from applying for credit in your name. You can also contact any one of the three major credit bureaus to place a fraud alert. A fraud alert on credit records is not as secure as a freeze, but a fraud alert is free. 
    • However, if you are concerned that placing a freeze will affect your access to capital through credit that you will need during this time, it’s best to monitor your bank statements.  
  • Use this event as a wake-up call. Implement multi-factor authentication on all accounts when available. Check that your own business isn’t vulnerable to a similar sort of leak.

 

KEYWORDS: cyber security data breach financial service security small business security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Larkin reynolds

Larkin Reynolds is a technology-focused advisor, helping small and large business clients navigate complex transactions and the maze of laws relating to privacy and data security.  She can be reached at larkin.reynolds@moyewhite.com or (303) 295-9808.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Data Breach Directions: What to Do After an Attack

    See More
  • smartphone-app-development-freepik.jpg

    Why mobile app developers need to prioritize user data privacy and security — and what they can do to ensure it

    See More
  • half open laptop

    What data loss prevention can do to protect your most valuable asset

    See More

Related Products

See More Products
  • 150 things.jpg

    Physical Security: 150 Things You Should Know 2nd Edition

  • CPTED.jpg

    CPTED and Traditional Security Countermeasures: 150 Things You Should Know

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing