On Friday, the FBI arrested a former Countrywide employee and his accomplice for stealing and selling personal information (including social security numbers) obtained from people applying for mortgages. According to news sources, the number of people compromised was about 2 million.
The Countrywide inside man was identified as Rene L. Rebollo Jr., who worked at Countrywide's sub prime lending division, Full Spectrum Lending. Also arrested was Wahid Siddiqi, who was the alleged information reseller in the caper. Both arrests took place in Southern California.
The criminal complaint alleges that Rebollo downloaded 20,000 names a week for about two years. The batches of 20,000 were sold for about $500 to Siddiqi. This amounts to about 25 cents a person compromised.
According to a spokeswoman at Countrywide, the investigation shows that 19,000 peoples information has been actually used.
Beth Givens, of the Privacy Rights Clearing House was quoted in a story about this in the LA Times and aptly pointed out Rebollo sold the information at well below known black market prices. Although the prices for stolen information -- which is sometimes sold in underground Internet forums has dropped in recent years -- a name that has a matching social security number is worth well more than 25 cents a pop.
The official spin is that this information was used for leads to sell real estate, but my speculation is that how would anyone know for sure? According to the news reports, the information was being sold to companies. The FBI posing as a company was able to buy records for Siddiqi.
If it was sold to companies, who knows who they might have sold it to, or if they have any dishonest employees selling it, elsewhere?
This made me wonder if any of the companies buying the information will be publicly disclosed? In a similar case at Certegy -- where another dishonest employee was caught and convicted for selling stolen information to "companies" -- the companies involved were never made public or charged with any crime (to my knowledge). Court records indicated a co-conspirator in this case, but again (to my knowledge) no one has ever revealed exactly who this mysterious co-conspirator was?
Givens also pointed out that names, which include a social security number and perhaps financial data, can be used to commit what is known as new account fraud. New account fraud is where an identity thief poses as their victim and opens new lines of credit. Once this is done the first time, the thief (sometimes thieves) continue to open lines of credit until the victim's credit report makes them look like a deadbeat.
My guess is that the affected people will be offered some sort of credit monitoring/identity theft protection. While this prevents some forms of identity theft, it doesn't necessarily protect from all the ways a stolen identity can be used. Some examples of when it might not show up on a credit report are cases of medical benefit fraud, employment fraud, government benefit fraud, some forms of check fraud and last, but not least, when it is used to commit crimes of other than a financial nature.
Recently, the Privacy Rights Clearinghouse, issued a well written fact sheet pointing out that existing credit monitoring/identity theft protection services do not protect a person from all forms of identity theft. I highly recommend that anyone -- who thinks their identity has been compromised -- read this fact sheet before buying or relying on the free protection offered in the aftermath of a known data compromise.
If and when -- employers are required to react to workers using social security numbers that do not match -- the millions of illegal immigrants already over here are going to have to use real social security numbers and a matching name to remain employed, or obtain employment. While the federal law on this has been tied up in federal court, some States have already enacted similar legislation. This type of identity theft normally doesn't appear on a credit report and is often discovered when a person files their tax return, or gets their social security earning statement and notices employment listed they never had.
A statistic that might support this is the IRS revealing that identity theft used to file tax returns has grown 644 percent in recent years. The two main reasons cited for this were people using them to obtain employment or to file a fraudulent tax return to obtain a phony refund, normally using what is known as the earned income credit.
Stories of large scale data breaches seem to surface, frequently. Despite this, there are a lot more that no one ever finds out about. Recent evidence revealed by Finjan, a computer security outfit, supports the contention that we really don't know how much stolen information there is out there, or how it is being used. Finjan has been discovering what they term as crime servers on the Internet, which contain all kinds of stolen information. This information included compromised patient data, bank customer data and even sensitive e-mail communications. At least some of this information wasn't even password protected on the crime server.
This particular data breach at Countrywide will probably fade into the mist fairly quickly. It does show that any and all security measures can and will be defeated when a person who has access is the point of compromise. The sad fact is that despite a lot of efforts -- until the issues that fuel (enable) this problem are addressed -- we will continue to see personal and financial information stolen.
We have made personal and financial information worth a lot of money and there are a lot of people buying and selling it. Some of them even have legitimate or semi-legitimate status. The more this occurs means the information is going to be electronically transmitted (sold) and then stored in a lot of different places. As long as this keeps happening, it's probably impossible to protect all of it.
Showing posts with label Certegy data breach. Show all posts
Showing posts with label Certegy data breach. Show all posts
Saturday, August 02, 2008
Saturday, May 03, 2008
Does the proposed class action settlement in the Certegy data breach case lack teeth?
I happened to notice, I was getting a lot of hits on some posts about the Certegy data breach and discovered that there is a proposed settlement in the class action law suit against them.
Tim Wilson at Dark Reading pointed out that this settlement amounts to Certegy paying less than $1 per victim and wrote:
Of note, I would imagine the plantiff's lawyers made A LOT more than $1 each for orchestrating this event. In all fairness, given the precedent set by similar actions might mean there isn't a very "deep pocket" on this type of action.
At $1 million for monitoring divided by 8.4 million potential victims, if any of them want the free monitoring, they better move quickly.
So far as the $4 million being set aside to make victims whole, I wonder how hard it is going to be for them to prove (as required by this settlement) that Certegy was the point-of-compromise in their case? The general rule of thumb is that identity thieves, even if they are caught (rare), probably aren't 100 percent sure where the information came from themselves. There is so much stolen information out there, it's being traded over the Internet.
The sad truth is that with all the data breaches out there, it might be hard to prove exactly where an identity theft victim's information was compromised.
So far as the criminal prosecution of the employee, one William Sullivan, who sold off 8.5 million people's records, I did a post in November about how he was able to make a plea bargain and get a reduced sentence in this case. There was a mention of a data broker being a co-conspirator, but they never seemed to be named (at least in public).
Personally, I've always had mixed feelings about law suits that result when data breaches occur. There is an argument that at least some (my opinion) of the organizations being breached are victims in the overall equation, also.
Saying that, if this class action and the one for TJX have set the legal precedent on this type of action, they are unlikely to serve as much of a deterrent against data breaches, or all the identity theft that results from them. Furthermore, the criminal prosecution of William Sullivan in his case is unlikely to be much of a deterrent, either.
In fact these results are probably going to do little to inspire organizations to protect their information better and for some, will probably be viewed as a cost of doing business.
I guess it's time to go back to the drawing board to figure out a way to effectively address information/identity theft and data breaches?
Here are the original posts, I did on this matter, which contain some angry commentary from more than one victim:
Not to worry, check processing company (Certegy) believes the 2.3 million stolen records will not be used for fraud!
Certegy reveals their data breach is a lot larger than originally reported
Class action law suit filed against Certegy for data breach
Tim Wilson at Dark Reading pointed out that this settlement amounts to Certegy paying less than $1 per victim and wrote:
Certegy Check Services is proposing to settle a class action lawsuit of last year's security breach on behalf of 8.4 million victims for about $4 million.He also surmised in his article that:
According to a report in the St. Petersburg (Fla.) Times, Certegy will also offer free credit monitoring services to some victims and reimbursement of credit monitoring expenses totaling $1 million on a first-come-first-served basis.
While plaintiffs' lawyers hailed the offer as a victory, critics said the relatively small settlement will not help the cause of identity protection. The massive TJX breach also resulted in a relatively small settlement for the victims, netting about $6.5 million for customers.
Of note, I would imagine the plantiff's lawyers made A LOT more than $1 each for orchestrating this event. In all fairness, given the precedent set by similar actions might mean there isn't a very "deep pocket" on this type of action.
At $1 million for monitoring divided by 8.4 million potential victims, if any of them want the free monitoring, they better move quickly.
So far as the $4 million being set aside to make victims whole, I wonder how hard it is going to be for them to prove (as required by this settlement) that Certegy was the point-of-compromise in their case? The general rule of thumb is that identity thieves, even if they are caught (rare), probably aren't 100 percent sure where the information came from themselves. There is so much stolen information out there, it's being traded over the Internet.
The sad truth is that with all the data breaches out there, it might be hard to prove exactly where an identity theft victim's information was compromised.
So far as the criminal prosecution of the employee, one William Sullivan, who sold off 8.5 million people's records, I did a post in November about how he was able to make a plea bargain and get a reduced sentence in this case. There was a mention of a data broker being a co-conspirator, but they never seemed to be named (at least in public).
Personally, I've always had mixed feelings about law suits that result when data breaches occur. There is an argument that at least some (my opinion) of the organizations being breached are victims in the overall equation, also.
Saying that, if this class action and the one for TJX have set the legal precedent on this type of action, they are unlikely to serve as much of a deterrent against data breaches, or all the identity theft that results from them. Furthermore, the criminal prosecution of William Sullivan in his case is unlikely to be much of a deterrent, either.
In fact these results are probably going to do little to inspire organizations to protect their information better and for some, will probably be viewed as a cost of doing business.
I guess it's time to go back to the drawing board to figure out a way to effectively address information/identity theft and data breaches?
Here are the original posts, I did on this matter, which contain some angry commentary from more than one victim:
Not to worry, check processing company (Certegy) believes the 2.3 million stolen records will not be used for fraud!
Certegy reveals their data breach is a lot larger than originally reported
Class action law suit filed against Certegy for data breach
Wednesday, March 19, 2008
Security vendor removes Hannaford as a client on their site after data breach is revealed!
I ran into an interesting development in the Hannaford data breach on geeksaresexy.net. Allegedly, their IT security vendor of choice (Rapid7) decided to disavow all knowledge of their relationship with Hannaford right after the breach was made public.
From the blog post on geeksaresexy.net:
Atttition.org is one of the trusted sources on data breaches, so I decided to see what they had found:
Attrition.org did an excellent job showing (complete with compelling screenshots) how Rapid7 removed all the information on the Internet showing they were Hannaford's cyber-guardians.
To see all the evidence, which is convincingly presented on Attrition.org, I've provided a link:
Abandon Ship! Data Loss Ahoy!
As of this writing, Rapid7 has replaced the information on their site showing Hannaford as a client.
I decided to run a query on Google News and discovered that so far the Boston Globe is one of the few mainstream e-rags reporting this so far.
The Boston Globe was able to get a comment from the marketing VP at Rapid7. Here is the "official explanation" from the article:
The Boston Globe was unable to get a comment from Hannaford about this matter.
I guess I'll have to leave it to the reader's imagination what the true intention in all of this was?
From the blog post on geeksaresexy.net:
Instead, Rapid7 scrubbed all mentions of Hannaford from their client list. Rapid7 obviously didn’t want to be associated with one of the largest data loss incidents in history, and they certainly didn’t want to sully the name of their flagship appliance, the “neXpose” which is a vulnerability scanning device.
This information is from Attrition.Org, an online security community that has been around since the predawn of the dot-com boom. They have an outstanding article, with screenshots here, where they are much less kind to Rapid7 in light of their cowardly actions.
Atttition.org is one of the trusted sources on data breaches, so I decided to see what they had found:
You are a security vendor. You sell the mightiest security doohickey the world has ever seen. It does it all, including "...ensuring your network is safe from hackers..." and amazingly it "...scans for Web site and database vulnerabilities that hackers can use to capture credit card information without you being aware". Since your doohickey does what no others have ever successfully managed to do, you can tout your client list proudly, and pimp your customer implementations liberally.
Attrition.org did an excellent job showing (complete with compelling screenshots) how Rapid7 removed all the information on the Internet showing they were Hannaford's cyber-guardians.
To see all the evidence, which is convincingly presented on Attrition.org, I've provided a link:
Abandon Ship! Data Loss Ahoy!
As of this writing, Rapid7 has replaced the information on their site showing Hannaford as a client.
I decided to run a query on Google News and discovered that so far the Boston Globe is one of the few mainstream e-rags reporting this so far.
The Boston Globe was able to get a comment from the marketing VP at Rapid7. Here is the "official explanation" from the article:
Was it damage control? Embarrassment about being linked to the breach? An admission that its software failed?
A Rapid7 executive says none of the above.
David Precopio, the company's vice president of marketing, said Hannaford asked Rapid7 to remove its name from the site once the data breach was made public. But after some sharp-eyed observers spotted the deletion (including the security website attrition.org) Precopio said Rapid7 asked Hannaford to let it repost the company’s name.
The Boston Globe was unable to get a comment from Hannaford about this matter.
I guess I'll have to leave it to the reader's imagination what the true intention in all of this was?
Monday, December 10, 2007
SIRAS offers guarantee that it will reduce retail crime
The reason SIRAS' product registration and smart return service perked my interest is because it protects people's privacy and is an effective means of reducing losses.
SIRAS tracks an inanimate object (merchandise) instead of a customer's personal information.
Now they are now offering a "guarantee" the technology will add dollars to a organization's bottom line by reducing fraudulent returns.
In their own words from the press release regarding this matter:
In case you haven't had to refund any merchandise in a long time, most retailers require you to give them your personal statistics before they approve your return.
This information is all maintained in a database, where it might be exposed to a hacker, or probably more frequently, dishonest employee. Information is worth a lot of money to anyone, who knows where to sell it.
A dishonest Certegy employee recently got caught selling 8.5 million people's information to an undisclosed data-broker. Since the mysterious data-broker still hasn't been identified -- despite being listed as a co-conspirator in court filings -- we really aren't sure where these records went?
Certegy provides check verification services for a lot of merchants.
Personal and financial information is marketed in carder forums (chat rooms) on the Internet. Anonymous payment methods, such as wire transfers, PayPal and eGold add to the problem. They make it relatively easy to buy and sell stolen information.
It also isn't unknown for criminal organizations to plant, or recruit employees to steal information from within an organization.
The press release quotes Peter Junger (SIRAS CEO) as saying, "And in all cases, regardless of ROI, clients retain all of the valuable POS data collected."
This POS data also serves another important purpose. If the merchandise is found in a fencing operation, or on an auction site, it can still be tracked to the point-of-compromise.
This opens up opportunities to recover stolen merchandise and makes it more dangerous for the criminals fencing it.
Mesa Police Department tested these capabilities with SIRAS and FOX News did a story on it, which can be seen, here.
The technology, when deployed properly with a point-of-sale system can also identity fraudulent means of tender used to purchase merchandise.
SIRAS technology can be deployed by a merchant, or at the factory, itself.
They already makes their database available to law enforcement free-of-charge.
With all the identity theft and counterfeit ID available, using SIRAS reduces the possibility that an innocent customer will be wrongfully identified as an "undesirable" in a refund database.
Saying that, who knows how much of the information in these databases is one-hundred percent accurate anymore? With retail crime becoming more and more organized, the possibility exists that it is NOT.
One of the systems targeted in the TJX data-breach was their refund database. The information in this database is probably worth more than simple financial information because it contains the elements necessary to assume a person's identity.
It's relatively easy to shut down a bank account, or credit card number. Once a person's statistics are compromised, they can be at risk of identity theft for a long time.
Data breaches are becoming more expensive. TJX claimed a loss of $118 million in their second quarter earnings. Estimates vary widely on exactly how expensive data-breaches will become, but everyone agrees the cost of them is going up.
SIRAS seems more effective in resolving property crimes because it tracks the property, itself. It also protects customer privacy and protects a merchant from becoming the victim of a data-breach.
I doubt that SIRAS would make this guarantee if they weren't absolutely certain of the results. If they were wrong, I doubt they would be in business very long.
Press release from SIRAS, here.
SIRAS tracks an inanimate object (merchandise) instead of a customer's personal information.
Now they are now offering a "guarantee" the technology will add dollars to a organization's bottom line by reducing fraudulent returns.
In their own words from the press release regarding this matter:
Electronic Product Registration, is putting its money where its mouth is with a unique Return On Investment (ROI) Guarantee for any company using SIRAS’s product registration and Smart Return service to manage their product returns and warrantees. The program, designed to eliminate any risk for companies interested in implementing SIRAS’s technology, guarantees that over the course of a year companies will save more money through deflected product returns than it spends in transaction fees.
In case you haven't had to refund any merchandise in a long time, most retailers require you to give them your personal statistics before they approve your return.
This information is all maintained in a database, where it might be exposed to a hacker, or probably more frequently, dishonest employee. Information is worth a lot of money to anyone, who knows where to sell it.
A dishonest Certegy employee recently got caught selling 8.5 million people's information to an undisclosed data-broker. Since the mysterious data-broker still hasn't been identified -- despite being listed as a co-conspirator in court filings -- we really aren't sure where these records went?
Certegy provides check verification services for a lot of merchants.
Personal and financial information is marketed in carder forums (chat rooms) on the Internet. Anonymous payment methods, such as wire transfers, PayPal and eGold add to the problem. They make it relatively easy to buy and sell stolen information.
It also isn't unknown for criminal organizations to plant, or recruit employees to steal information from within an organization.
The press release quotes Peter Junger (SIRAS CEO) as saying, "And in all cases, regardless of ROI, clients retain all of the valuable POS data collected."
This POS data also serves another important purpose. If the merchandise is found in a fencing operation, or on an auction site, it can still be tracked to the point-of-compromise.
This opens up opportunities to recover stolen merchandise and makes it more dangerous for the criminals fencing it.
Mesa Police Department tested these capabilities with SIRAS and FOX News did a story on it, which can be seen, here.
The technology, when deployed properly with a point-of-sale system can also identity fraudulent means of tender used to purchase merchandise.
SIRAS technology can be deployed by a merchant, or at the factory, itself.
They already makes their database available to law enforcement free-of-charge.
With all the identity theft and counterfeit ID available, using SIRAS reduces the possibility that an innocent customer will be wrongfully identified as an "undesirable" in a refund database.
Saying that, who knows how much of the information in these databases is one-hundred percent accurate anymore? With retail crime becoming more and more organized, the possibility exists that it is NOT.
One of the systems targeted in the TJX data-breach was their refund database. The information in this database is probably worth more than simple financial information because it contains the elements necessary to assume a person's identity.
It's relatively easy to shut down a bank account, or credit card number. Once a person's statistics are compromised, they can be at risk of identity theft for a long time.
Data breaches are becoming more expensive. TJX claimed a loss of $118 million in their second quarter earnings. Estimates vary widely on exactly how expensive data-breaches will become, but everyone agrees the cost of them is going up.
SIRAS seems more effective in resolving property crimes because it tracks the property, itself. It also protects customer privacy and protects a merchant from becoming the victim of a data-breach.
I doubt that SIRAS would make this guarantee if they weren't absolutely certain of the results. If they were wrong, I doubt they would be in business very long.
Press release from SIRAS, here.
Tuesday, November 27, 2007
Dishonest Certegy employee strikes plea agreement for selling 8.5 million people's information
Certegy wasn't the largest data breach reported this year, it only compromised a mere 8.5 million people.
What was troublesome -- for the people compromised at least -- was the fact that their personal and financial information was sold to entities that still haven't been disclosed. The financial information I'm referring to included checking, credit card and debit card account information.
Yesterday, it was announced that the dishonest Certegy employee involved, one William Sullivan agreed to plead guilty for what is what is being termed a "reduced sentence."
Marjorie Manning of the Jacksonville Business Journal wrote:
Here is a snippet from the article about the co-conspirator:
I did a few posts on the breach, shortly after it occurred and a lot of angry people left comments on them. Some of them seemed to disagree with the official statement that the information was never used.
Here are the posts:
Not to worry, check processing company (Certegy) believes the 2.3 million stolen records will not be used for fraud!
Certegy reveals their data breach is a lot larger than originally reported
Class action law suit filed against Certegy for data breach
In all fairness, it's hard to vet the comments I get on a post. That being said, I saw a lot of angry people leave some pretty interesting comments.
Couple this with the fact that the information broker (named as a co-conspirator) hasn't been named yet and the story leaves a lot of details, which remain a mystery.
The article doesn't seem to specify how many counts Sullivan is pleading guilty to. Hopefully once the sentence is announced, we aren't going to have a lot of victims (8.5 million of them) feeling like he got a slap on the wrist!
What was troublesome -- for the people compromised at least -- was the fact that their personal and financial information was sold to entities that still haven't been disclosed. The financial information I'm referring to included checking, credit card and debit card account information.
Yesterday, it was announced that the dishonest Certegy employee involved, one William Sullivan agreed to plead guilty for what is what is being termed a "reduced sentence."
Marjorie Manning of the Jacksonville Business Journal wrote:
Sullivan faces up to five years in prison and a fine of $250,000 on each count, although the U.S. Attorney's office will recommend a shorter sentence because of Sullivan's acceptance of responsibility, the plea agreement said.Even more amazing, many months into this, the data broker who bought the information from Sullivan is merely listed in the legal proceedings as a "co-conspirator."
Sullivan also will be required to make restitution to Fidelity, the filing said.
Sentencing was scheduled for Nov. 21, but Sullivan's attorney has asked the court for a delay because of the attorney's travel plans over the Thanksgiving holiday.
Fidelity has said that it has no evidence of the stolen information being used for anything other than marketing purposes, but the company faces several class action lawsuits alleging damage as a consequence of the theft.
Here is a snippet from the article about the co-conspirator:
The scheme was broader than initially disclosed July 3 by FIS. According to court documents, Sullivan agreed with the co-conspirator to steal the consumer information beginning in at least 2002, and Sullivan was paid more than $580,000 over the course of the conspiracy for the data.FIS (Fidelity National Information Services Inc.) is Certegy's parent company.
I did a few posts on the breach, shortly after it occurred and a lot of angry people left comments on them. Some of them seemed to disagree with the official statement that the information was never used.
Here are the posts:
Not to worry, check processing company (Certegy) believes the 2.3 million stolen records will not be used for fraud!
Certegy reveals their data breach is a lot larger than originally reported
Class action law suit filed against Certegy for data breach
In all fairness, it's hard to vet the comments I get on a post. That being said, I saw a lot of angry people leave some pretty interesting comments.
Couple this with the fact that the information broker (named as a co-conspirator) hasn't been named yet and the story leaves a lot of details, which remain a mystery.
The article doesn't seem to specify how many counts Sullivan is pleading guilty to. Hopefully once the sentence is announced, we aren't going to have a lot of victims (8.5 million of them) feeling like he got a slap on the wrist!
Saturday, September 15, 2007
Another 6.3 million people's information stolen at Ameritrade
According to the AP, Ameritrade is reporting that someone hacked into their systems and made off with 6.3 million people's information:
They might want to start monitoring their finances, carefully.
In addition to this, the stated need for confidentiality is coming from Ameritrade and not a law enforcement source involved in the investigation. The claim that a federal hearing might have forced disclosure might make some wonder about the credibility of what is being said, also.
The verbiage used in the Ameritrade press release states that social security numbers don't "appear" to have been taken is a little scary, also. Does this mean that they aren't sure?
Why would a hacker only take contact information, when social security and dates of birth were available in the same database, also?
My guess is that dates of birth and social security numbers would make the information more valuable to the hackers, who compromised the system.
The press release does state that account numbers and passwords were in a different database, and were not compromised.
Security and identity theft experts are speculating that the information taken could be used to phish for additional information, which then could be to commit identity theft. Phishing is where an e-mail from an official looking, but spoofed (impersonated) source tricks someone into giving up sensitive information.
Tricking people into giving up their information is also known as, social engineering.
Crimeware might also be used to steal the additional information. Once downloaded crimeware, steals information from a system automatically, normally using keylogging software. Crimeware can be picked up by clicking on the link of a phishy e-mail.
According to the Anti-Phishing Working Group, who studies this carefully has reported crimeware use is on the rise. One of the reasons for the rise in crimeware is that DIY (do-it-yourself) kits are being sold on the black market. This allows less sophisticated criminals to get into the game.
The CNet version of the story, quotes Graham Cluley (Sophos) as speculating how Ameritrade's system was probably compromised:
They are also providing additional information on their site about this unfortunate event for their customers.
The TJX data breach, which compromised over 45 million people, has caused a lot of uproar about how data breaches should be handled and who should pay for them.
Class action law suits are being brought forth and legislation is being introduced to determine, who pays for all the damage, when a data breach occurs.
This is becoming extremely costly for the companies being breached. The last report I saw about the cost incurred so far by TJX is $256 million. The sad thing is that I doubt this is the final figure.
Legislation in California is awaiting Arnold Schwarzenegger's signature, which will require retailers to reimburse financial institutions for the cost of fixing breached financial data. Interestingly enough -- in this data breach and the last major one, I've written about (Certegy) -- the data was not stolen from a retailer.
The Privacy Rights Clearinghouse, PogoWasRight and Attrition.org all compile information on data breaches, which happen so frequently, they are becoming almost "too routine" news events.
If anyone, who was has been affected by a data breach wants independent advice on what to do if you become an identity theft victim, the Privacy Rights Clearinghouse has a very informative page about this, here.
AP story by Josh Funk, here.
Online brokerage TD Ameritrade Holding Corp. said Friday one of its databases was hacked and contact information for its more than 6.3 million customers was stolen. A spokeswoman for the Omaha-based company said more sensitive information in the same database, including Social Security numbers and account numbers, does not appear to have been taken.Allegedly, Ameritrade has known about this for awhile and it might have been the threat of legal action, which prompted them to come forward now:
The company would not share many details of its investigation, including when the hack took place, because it is still looking into the theft and cooperating with investigators from the FBI, Securities and Exchange Commission, Financial Industry Regulatory Authority and local authorities.
But Ameritrade has known about the problem at least since late May when two of its customers sued the brokerage in federal court because they were receiving unwanted e-mail ads on accounts used only for Ameritrade.While maintaining confidentiality in an investigation is sometimes necessary, you would think that someone might want to warn the 6.3 million people, who were affected by this?
The data on Ameritrade's servers may have been vulnerable for an extended period of time dating back at least to last October, according to the lawsuit filed by lawyer Scott A. Kamber. The company said Friday the problem had recently been fixed.
The plaintiffs in the lawsuit had wanted the court to order Ameritrade to tell its customers about the data problem, but Ameritrade issued its release before a hearing could be held. The plaintiffs are also seeking damages and are trying to qualify as a class-action lawsuit.
"They preferred putting out a press release with their own language in it rather than have the court order them to put out a release with our language," Kamber said.
They might want to start monitoring their finances, carefully.
In addition to this, the stated need for confidentiality is coming from Ameritrade and not a law enforcement source involved in the investigation. The claim that a federal hearing might have forced disclosure might make some wonder about the credibility of what is being said, also.
The verbiage used in the Ameritrade press release states that social security numbers don't "appear" to have been taken is a little scary, also. Does this mean that they aren't sure?
Why would a hacker only take contact information, when social security and dates of birth were available in the same database, also?
My guess is that dates of birth and social security numbers would make the information more valuable to the hackers, who compromised the system.
The press release does state that account numbers and passwords were in a different database, and were not compromised.
Security and identity theft experts are speculating that the information taken could be used to phish for additional information, which then could be to commit identity theft. Phishing is where an e-mail from an official looking, but spoofed (impersonated) source tricks someone into giving up sensitive information.
Tricking people into giving up their information is also known as, social engineering.
Crimeware might also be used to steal the additional information. Once downloaded crimeware, steals information from a system automatically, normally using keylogging software. Crimeware can be picked up by clicking on the link of a phishy e-mail.
According to the Anti-Phishing Working Group, who studies this carefully has reported crimeware use is on the rise. One of the reasons for the rise in crimeware is that DIY (do-it-yourself) kits are being sold on the black market. This allows less sophisticated criminals to get into the game.
The CNet version of the story, quotes Graham Cluley (Sophos) as speculating how Ameritrade's system was probably compromised:
"There are only two different ways this could have happened. There was either a vulnerability with their Web site and it was hacked, or someone internally gained access with a Trojan horse."Ameritrade has hired ID Analytics, Inc. to monitor what is going on and determine if any identity theft occurs out of all of this.
They are also providing additional information on their site about this unfortunate event for their customers.
The TJX data breach, which compromised over 45 million people, has caused a lot of uproar about how data breaches should be handled and who should pay for them.
Class action law suits are being brought forth and legislation is being introduced to determine, who pays for all the damage, when a data breach occurs.
This is becoming extremely costly for the companies being breached. The last report I saw about the cost incurred so far by TJX is $256 million. The sad thing is that I doubt this is the final figure.
Legislation in California is awaiting Arnold Schwarzenegger's signature, which will require retailers to reimburse financial institutions for the cost of fixing breached financial data. Interestingly enough -- in this data breach and the last major one, I've written about (Certegy) -- the data was not stolen from a retailer.
The Privacy Rights Clearinghouse, PogoWasRight and Attrition.org all compile information on data breaches, which happen so frequently, they are becoming almost "too routine" news events.
If anyone, who was has been affected by a data breach wants independent advice on what to do if you become an identity theft victim, the Privacy Rights Clearinghouse has a very informative page about this, here.
AP story by Josh Funk, here.
Subscribe to:
Posts (Atom)
