Removable media device stolen from Educational Credit Management Corp.'s (ECMC) headquarters contained Social Security numbers, names, addresses, dates of birth of people who had received federal student loans
A removable media device containing personal data on 3.3 million people was stolen from the Minnesota headquarters of federal student loan guarantor Educational Credit Management Corp. (ECMC) last week -- and the data should never have been copied onto the device in the first place.
ECMC, which handles and insures more than $11 billion worth of student loans for the U.S. Department of Education, discovered on March 23 that the device had been stolen. The firm is currently in the process of sending letters to all of the affected loan recipients, some of whom date back to as long as 15 years ago. Their names, addresses, Social Security numbers, and dates of birth were on the stolen device, but no bank account or financial data, according to ECMC.
David Hawn, chief business development officer for ECMC, said in an interview that storing such sensitive data on a removable device was a "very clear violation of our company policies and protocols." He would not specify whether the device was a USB stick, hard drive, or other type of device due to the sensitive nature of the ongoing investigation by law enforcement. Hawn also was not able to reveal whether the data was encrypted, either.
"This situation was unfortunate in that it had a human element to it...It really was a disappointment to all of us that this had occurred," Hawn says, and the company is in the process of doing a full-blown review of its internal security policies and plans to "make changes."
"We unfortunately learned about this the hard way, and we are working diligently to shore that up," he says. "Our systems security infrastructure is very robust, and in fact since this incident occurred, by way of precaution we have hired an external agency to perform various penetration tests on our firewalls -- all the testing has been negative."
Hawn says it doesn't appear the thief or thieves were targeting specific information in the crime. "There's nothing to suggest that they were aware of what they were taking," Hawn says.
And thus far, ECMC says there's been no evidence of any abuse of the data. The company is offering the affected victims free credit monitoring and reporting with Experian.
ECMC's problem isn't unique: Ipswitch File Transfer will release a study tomorrow that shows that 90 percent of IT and security professionals use thumb drives or external devices to move data. Few companies bother encrypting data on those devices, either, says Frank Kenney, vice president of global strategy at Ipswitch. "Encryption generally doesn't happen. It's rare," Kenney says.
"We were shocked by how many people are using [these devices] to share or move large files," Kenney says.
The data potentially exposed includes existing, ongoing, and older, inactive federal student loans as well, ECMC's Hawn says. "It did include, for archival purposes, a number of records" that date back to 15 years ago, he says.
ECMC serves as the guarantor for loans in Oregon, Virginia, and Connecticut, but borrowers in all states could be affected by the breach, according to one published report.
Potential victims of the breach can go to this page set up by ECMC to get more information on whether they are affected, and if so, what to do. darkreading.com
Showing posts with label Cybercrime. Show all posts
Showing posts with label Cybercrime. Show all posts
Tuesday, March 30, 2010
JC Penney tried to block publication of data breach
IDG News Service - Retailer JC Penney fought to keep its name secret during court proceedings related to the largest breach of credit card data on record, according to documents unsealed on Monday.
JC Penney was among the retailers targeted by Albert Gonzalez's ring of hackers, which managed to steal more than 130 million credit card numbers from payment processor Heartland Payment Systems and others. Gonzalez was sentenced to 20 years in prison on Friday in U.S. District Court for the District of Massachusetts.
In December, JC Penney -- referred to as "Company A" in court documents -- argued in a filing that the attacks occurred more than two years ago, and that disclosure would cause "confusion and alarm."
However, it was already suspected JC Penney was one of the retailers after the Web site StorefrontBacktalk was the first outlet to accurately report in August 2009 that JC Penney was among the retailers targeted by Gonzalez's group.
New Jersey, where the Gonzalez case started, agreed to keep JC Penney's identity secret but the case was moved to Massachusetts where authorities decided otherwise, prompting JC Penney's motion.
Disclosing Company A's identity "may discourage other victims of cybercrimes to report the criminal activity or cooperate with enforcement officials for fear of the retribution and reputational damage that may arise from a policy of disclosure as espoused by the government in this case," wrote JC Penney attorney Michael D. Ricciuti.
In a Jan. 12 filing, U.S. prosecutors argued for disclosure. "Most people want to know when their credit or debit card numbers have been put at risk, not simply if, and after, they have clearly been stolen," the government wrote. "The presumption of disclosure has an additional significant benefit, though, besides the right of the card holder to know when he has been exposed to risk."
The U.S. Secret Service had told JC Penney that its computer system had been broken into. The retailer's system had "unquestionably failed," but the government said the Secret Service did not have evident that payment card numbers were stolen, U.S. prosecutors wrote.
Another retailer, The Wet Seal, said in a statement issued Monday that it had also been targeted by Gonzalez's gang around May 2008. The Wet Seal has been referred to as "Company B" in court documents.
"We found no evidence to indicate that any customer credit or debit card data or other personally identifiable information was taken," the company said.
Other retailers affected by the breach included TJX, 7-Eleven, Hannaford Brothers, Dave & Busters, BJ's Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW. computerworld.com
JC Penney was among the retailers targeted by Albert Gonzalez's ring of hackers, which managed to steal more than 130 million credit card numbers from payment processor Heartland Payment Systems and others. Gonzalez was sentenced to 20 years in prison on Friday in U.S. District Court for the District of Massachusetts.
In December, JC Penney -- referred to as "Company A" in court documents -- argued in a filing that the attacks occurred more than two years ago, and that disclosure would cause "confusion and alarm."
However, it was already suspected JC Penney was one of the retailers after the Web site StorefrontBacktalk was the first outlet to accurately report in August 2009 that JC Penney was among the retailers targeted by Gonzalez's group.
New Jersey, where the Gonzalez case started, agreed to keep JC Penney's identity secret but the case was moved to Massachusetts where authorities decided otherwise, prompting JC Penney's motion.
Disclosing Company A's identity "may discourage other victims of cybercrimes to report the criminal activity or cooperate with enforcement officials for fear of the retribution and reputational damage that may arise from a policy of disclosure as espoused by the government in this case," wrote JC Penney attorney Michael D. Ricciuti.
In a Jan. 12 filing, U.S. prosecutors argued for disclosure. "Most people want to know when their credit or debit card numbers have been put at risk, not simply if, and after, they have clearly been stolen," the government wrote. "The presumption of disclosure has an additional significant benefit, though, besides the right of the card holder to know when he has been exposed to risk."
The U.S. Secret Service had told JC Penney that its computer system had been broken into. The retailer's system had "unquestionably failed," but the government said the Secret Service did not have evident that payment card numbers were stolen, U.S. prosecutors wrote.
Another retailer, The Wet Seal, said in a statement issued Monday that it had also been targeted by Gonzalez's gang around May 2008. The Wet Seal has been referred to as "Company B" in court documents.
"We found no evidence to indicate that any customer credit or debit card data or other personally identifiable information was taken," the company said.
Other retailers affected by the breach included TJX, 7-Eleven, Hannaford Brothers, Dave & Busters, BJ's Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW. computerworld.com
The 10 Riskiest Cities for Cybercrime
The threat of falling victim to cyber-crime is so ubiquitous today, and some of America's biggest cities are even more prone than elsewhere in the country, according to a well known producer of cyber-security software.
Norton from Symantec, a popular antivirus provider, teamed up with the research organization Sperling BestPlaces to discern which cities were the riskiest hot spots for cyber-security, publishing the results March 22 in The Norton Top 10 Riskiest Online Cities report. The 50 cities identified in the report make up a laundry list of the most famous places in the country.
The top 10 listed are:
•Seattle
•Boston
•Washington, D.C.
•San Francisco
•Raleigh, N.C.
•Atlanta
•Minneapolis
•Denver
•Austin, Texas
•Portland, Ore.
Other notable cities in the remaining 40 include Honolulu (11), Las Vegas (13), San Diego (14), New York (24), Los Angeles (30), Houston (32), Phoenix (34) and Chicago (35). Rankings were determined from Symantec data on cyber-crime, third-party data on online behavior and demographic data from Sperling.
These cities have been ranked based on the numbers of malicious attacks received; potential malware infections; spam zombies; bot-infected machines; and places that offer free Wi-Fi, per capita. They were also ranked based on the prevalence of Internet use; computer use, based on consumer expenditures for hardware and software; and risky online activity, like purchasing via the Internet, e-mail and accessing financial information.
Seattle ranked in the top 10 of all categories, which is how it wound up as No.1 riskiest city in the survey.
"When you look at the data, they are way ahead on all these measures, so you've got a concentration of heavy usage of technology engaging in the kinds of activities that we know increase your risk of being a victim of cyber-crime," said Marian Merritt, Norton Internet Safety Advocate.
But Merritt said people who don't live in one of the riskiest cities shouldn't ignore basic Internet safety procedures.
"Even if your city's not on the list, you as a citizen could be the kind of person who still engages in all the things that would have made your city rank higher," she said. "Even if you live in a rural environment but you're somebody who's constantly on the Internet and you have high-speed connections when you do online banking, you'll be encountering more risk than other people."
A city's concentration of busy Internet users had a lot to do with where it wound up on the list. Detroit came in at No. 50 because people there apparently don't have the Web-centric capabilities and usage patterns in the same high numbers compared to a city like San Francisco, which came in at No. 4.
"[Detroit is] the 50th -- the lowest ranking for cyber-crime. They're also low with access to the Internet. They're not spending as much on computer equipment. There's a whole bunch of factors that made them fall to the bottom," Merritt said.
She added that a city's digital safety environment might be something the municipal government would want to consider in projects to expand wireless capabilities to underserved communities.
"There's a responsibility to make sure that people who get new access to technology or services like broadband understand that there are risks and how to mitigate them," she said. govtech.com
Norton from Symantec, a popular antivirus provider, teamed up with the research organization Sperling BestPlaces to discern which cities were the riskiest hot spots for cyber-security, publishing the results March 22 in The Norton Top 10 Riskiest Online Cities report. The 50 cities identified in the report make up a laundry list of the most famous places in the country.
The top 10 listed are:
•Seattle
•Boston
•Washington, D.C.
•San Francisco
•Raleigh, N.C.
•Atlanta
•Minneapolis
•Denver
•Austin, Texas
•Portland, Ore.
Other notable cities in the remaining 40 include Honolulu (11), Las Vegas (13), San Diego (14), New York (24), Los Angeles (30), Houston (32), Phoenix (34) and Chicago (35). Rankings were determined from Symantec data on cyber-crime, third-party data on online behavior and demographic data from Sperling.
These cities have been ranked based on the numbers of malicious attacks received; potential malware infections; spam zombies; bot-infected machines; and places that offer free Wi-Fi, per capita. They were also ranked based on the prevalence of Internet use; computer use, based on consumer expenditures for hardware and software; and risky online activity, like purchasing via the Internet, e-mail and accessing financial information.
Seattle ranked in the top 10 of all categories, which is how it wound up as No.1 riskiest city in the survey.
"When you look at the data, they are way ahead on all these measures, so you've got a concentration of heavy usage of technology engaging in the kinds of activities that we know increase your risk of being a victim of cyber-crime," said Marian Merritt, Norton Internet Safety Advocate.
But Merritt said people who don't live in one of the riskiest cities shouldn't ignore basic Internet safety procedures.
"Even if your city's not on the list, you as a citizen could be the kind of person who still engages in all the things that would have made your city rank higher," she said. "Even if you live in a rural environment but you're somebody who's constantly on the Internet and you have high-speed connections when you do online banking, you'll be encountering more risk than other people."
A city's concentration of busy Internet users had a lot to do with where it wound up on the list. Detroit came in at No. 50 because people there apparently don't have the Web-centric capabilities and usage patterns in the same high numbers compared to a city like San Francisco, which came in at No. 4.
"[Detroit is] the 50th -- the lowest ranking for cyber-crime. They're also low with access to the Internet. They're not spending as much on computer equipment. There's a whole bunch of factors that made them fall to the bottom," Merritt said.
She added that a city's digital safety environment might be something the municipal government would want to consider in projects to expand wireless capabilities to underserved communities.
"There's a responsibility to make sure that people who get new access to technology or services like broadband understand that there are risks and how to mitigate them," she said. govtech.com
Monday, March 29, 2010
TJX Hacker Sentencing Signals the Need for Customer e-Banking Security Vigilance says Trusteer CEO
London, United Kingdom - 29th March, 2010 - The severity of the 20 years prison sentence handed down to convicted TJX hacker Albert Gonzalez for running his own multi-million-dollar card hacking scam sends a very positive message that crime - and cybercrime in particularly - really does not pay in the long run, says Trusteer.
And, says Mickey Boodaei, the firm's CEO, the case rams home the message that bank card and account owners need to protect their cards and online assets if they are to avoid waking up to the horror of finding no money in their bank accounts
"As the truth slowly emerges, however, it should now be apparent to the man and woman on the street that banking cybercrime - which is actually just another type of money fraud - is a very real threat to you, me and almost any bank or payment card user," said Boodaei, whose firm Trusteer, provide browser security and fraud prevention services that protect the customers of many UK banks.
But, the Trusteer CEO went on to say, threats can be mitigated by effective IT security technology and this is exactly what banks and allied financial institutions the world over are doing behind the scenes, to protect their customers' money.
But the widespread nature of electronic crime - with criminals being lured by the big money they can generate from their frauds - is such that implementing the security is now a team effort between the banks and their customers.
Banks require the right tools and processes to investigate incidents and provide law enforcement official with accurate information which could lead to arrests and Trusteer recently launched “Flashlight” a remote fraud investigation and mitigation service identifies the attack source on a customer’s machine, gathers samples, and can reverse engineer the mechanism used by the malware to commit fraud. Findings enable banks and other organizations to prevent future losses, block subsequent attacks, and takedown command/control servers and provide forensic evidence required for arrest and prosecution.
You wouldn't, he explained, walk into a coffee bar or pub, order a drink and leave your wallet on the table, and it's exactly the same with electronic assets in the shape of online banking credentials.
Trusteer, Boodaei says, is doing its bit by supplying banks such as HSBC, RBS/Natwest and the Santander Group, with its Rapport browser plug-in security software, which helps to stop sophisticated e-banking frauds such as man-in-the-middle and password-sniffing attacks.
"The TJX/Gonzalez case shows that organisations such as the FBI are doing their bit as well, but criminals would always look for the weakest link in the chain to steal customers’ money. Right now the weakest link is the customer’s computer which can be targeted by sophisticated malware and phishing attacks. To protect against this customers should install the best possible IT security software and systems on their computers, before going online to their e-banking services," he said.
"Internet users need to sit up and take notice of cases like this one. There are much smaller frauds going on all the time, each of which can result in your bank account being hit for six. E-banking customers need to use all the security technology they can muster to avoid their own accounts being drained," he added. contactcenterworld.com
And, says Mickey Boodaei, the firm's CEO, the case rams home the message that bank card and account owners need to protect their cards and online assets if they are to avoid waking up to the horror of finding no money in their bank accounts
"As the truth slowly emerges, however, it should now be apparent to the man and woman on the street that banking cybercrime - which is actually just another type of money fraud - is a very real threat to you, me and almost any bank or payment card user," said Boodaei, whose firm Trusteer, provide browser security and fraud prevention services that protect the customers of many UK banks.
But, the Trusteer CEO went on to say, threats can be mitigated by effective IT security technology and this is exactly what banks and allied financial institutions the world over are doing behind the scenes, to protect their customers' money.
But the widespread nature of electronic crime - with criminals being lured by the big money they can generate from their frauds - is such that implementing the security is now a team effort between the banks and their customers.
Banks require the right tools and processes to investigate incidents and provide law enforcement official with accurate information which could lead to arrests and Trusteer recently launched “Flashlight” a remote fraud investigation and mitigation service identifies the attack source on a customer’s machine, gathers samples, and can reverse engineer the mechanism used by the malware to commit fraud. Findings enable banks and other organizations to prevent future losses, block subsequent attacks, and takedown command/control servers and provide forensic evidence required for arrest and prosecution.
You wouldn't, he explained, walk into a coffee bar or pub, order a drink and leave your wallet on the table, and it's exactly the same with electronic assets in the shape of online banking credentials.
Trusteer, Boodaei says, is doing its bit by supplying banks such as HSBC, RBS/Natwest and the Santander Group, with its Rapport browser plug-in security software, which helps to stop sophisticated e-banking frauds such as man-in-the-middle and password-sniffing attacks.
"The TJX/Gonzalez case shows that organisations such as the FBI are doing their bit as well, but criminals would always look for the weakest link in the chain to steal customers’ money. Right now the weakest link is the customer’s computer which can be targeted by sophisticated malware and phishing attacks. To protect against this customers should install the best possible IT security software and systems on their computers, before going online to their e-banking services," he said.
"Internet users need to sit up and take notice of cases like this one. There are much smaller frauds going on all the time, each of which can result in your bank account being hit for six. E-banking customers need to use all the security technology they can muster to avoid their own accounts being drained," he added. contactcenterworld.com
Sunday, March 28, 2010
Cyber Crime Is A Real Threat Says FBI
Cybercrime is growing says FBI and it is a great threat for the nation. FBI warns the security in the United States as it is eating at data and cash.
Robert Mueller, chief of Federal Bureau of Investigation addressed to RSA Conference of computer security professionals on Thursday in San Francisco, "The risks are right at our doorsteps and in some cases they are in the house."
He also added, "Working together we can find the people taking shots at us and stop those attacks."
Robert Mueller said that cyber-attack will have the similar impact as a well-placed bomb in the country.
"In the past 10 years, Al-Qaeda's online presence has become as potent as its in-world presence," he said.
He also continued that the cyber-terrosism threat is very real for the states and it is also rapidly expanding.
Mueller said, "Terrorists have shown a clear interest in hacking skills and combining real attacks with cyber attacks." dailynews365.com
Tags: Cybercrime, FBI
Subscribe to:
Posts (Atom)





