Data breach on top of normally bad identity governance

There is this disturbing article from the Boston Globe about the SSN for 450,000 licensees being released. So what’s disturbing about this is not the SSN breach. Although that was unfortunate, it looks like the damage was contained. What’s really disturbing was that it happened while the state was selling the names and addresses of all licensees to marketing companies and one time they accidentally included the SSN numbers as well.

That’s right. If you want to cut hair in Mass, not only do you have to pay for a license, the state then makes even more money by selling your personal information to a marketing company to spam you with.

Does anyone know how widespread this practice is in other states?

