A computer containing the personal details of one million customers of the Royal Bank of Scotland and Natwest has been sold on eBay.
The person who bought the computer raised the alarm after paying just £35 for it from an ex-employee of archiving firm Graphic Data.
Data including account numbers, telephone numbers and answers to security questions – such as mothers' maiden names – were on the computer's hard drive.
It is also thought that customers' signatures and details of credit card applications were on the PC.
"Graphic Data has confirmed to us that one of their machines appears to have been inappropriately sold via a third party," the Royal Bank of Scotland, which owns Natwest, said in a statement.
"As a result, historical data relating to credit card applications from some of our customers and data from other banks were not removed. We take this issue extremely seriously and are working to resolve this regrettable loss with Graphic Data as a matter of urgency," the statement continued.
eBay also expressed concern in a statement.
"Clearly such details should never have been included in the hard-drive of the computer offered for sale on eBay. We will of course work with Graphic Data to establish how it came to be available for sale on our site," the statement said.
Under the Data Protection Act, banks and other organisations have an obligation to keep personal information secure.
Welcome to Web User magazine's online home, where you'll find
news, reviews and a buzzing forum.
For the best websites, practical advice and the latest music and film downloads every fortnight, get Web User,
the UK’s best selling internet magazine.