Showing posts with label whistleblower. Show all posts
Showing posts with label whistleblower. Show all posts

Thursday, May 29, 2008

TJX shoots the messenger reporting potential identity theft issues!


(Picture courtesy of b d solis at Flickr)

One would assume after compromising an estimated 94 million people's information, a company would become a model of information security for the rest of us to aspire to. Sadly, if the following story is true, this is NOT the case at TJX.

Ran into this disturbing example of a messenger getting shot for trying to report sloppy security on Sans Newsbites:

TJX Companies has fired an employee from a Lawrence, Kansas TJ Maxx store for making posts to a forum about the company's lax security practices, even after the notable breach. The employee, Nick Benson, said in several posts that except for a period of time following the breach disclosure when a strong password policy was enforced, the employee password at his store's server was set to blank. In addition, at one point a store server was running in administrator mode. When Benson began work at TJX, his password was the same as his user name. TJX says Benson was fired for disclosing confidential company information. -http://www.theregister.co.uk/2008/05/23/tjx_fires_whistleblower/print.html-http://computerworld.co.nz/news.nsf/scrt/3A2C5453A05F8C31CC257454006CE111

Reading a little further by linking to the article written by Dan Goodin in the Register, I discovered that the act of posting in forums came about AFTER the employee tried to resolve the problem, internally:

Other security issues included a store server that was running in administrator mode, making it far more susceptible to attackers. He said he brought the security issues to the attention of a district loss prevention manager name Allen in late 2006, and repeatedly discussed them with store managers. Except for a stretch when IT managers temporarily tightened password policies, the problems went unfixed.

After posting on the forum (http://sla.ckers.org/forum/read.php?13,15148,page=1), the boss of one of the people Benson reported the matter to summoned him into the office and terminated him.

I suppose we could all argue that posting this information in a public forum is dangerous. Saying that, Benson did try to report the matter through his internal chain of command and nothing was done?

Maybe it is because the people, he reported it to aren't IT savvy enough to realize how vulnerable TJX's systems are when they are left unprotected like this?

Even if a hacker didn't compromise the system, it is feasible that a dishonest employee could gather quite of bit of information and sell it? Carder forums -- where personal and financial details are bartered over cyberspace -- are well known and not very hard to find.

Please note, I wrote IF a hacker didn't compromise the system. I'm just pointing out stealing information wouldn't take a very sophisticated hacking job given the opportunities described in this instance.

They might even post (anonymously), how easily they got the information in hacker forums. Sadly if Mr. Benson had been more anonymous, he would probably still be employed. I guess it doesn't pay to be honest in cases like these?

My post just before this was about another revelation (pun intended) that not all data breaches are being reported. I tied this post into two stories. One was about the lack of reporting, and other one was recent reports about Finjan finding crimeservers via simple searches that contain a lot of information that could be used to commit a host of financial crimes.

Interestingly enough, the crimeservers (available to anyone on the Internet) weren't "password protected," either.

So far as Mr. Benson is concerned, I wonder if TJX was required to maintain a confidential hot-line and if he ever reported the matter there? Although, I'm not a lawyer, I also have to wonder if federal laws protecting "whistleblowers" apply here. More information on whistleblower laws can be seen on whistleblower.com.

It's a crying shame that the powers that be at TJX didn't value the fact that an employee was trying to show them where they might receive a lot more unfavorable public exposure by compromising their customer information.

I'll close with a supportive comment from the editor at SANS:

[Editor's Note (Schultz): Once again TJX is proving itself to be a villain. Interestingly, I still sometimes shop at a TJ Maxx or Marshalls store, but I always pay cash--I would never use a credit card because of TJX's huge security deficiencies. And if Nick Benson reads this comment, I would encourage him to contact me, because I will do everything in my power to help him find another job. ]

PS: I would like to add that I'm pretty sure there are companies out there that would value an employee, who brought matters like these to their attention. They might save them millions of dollars in the end when you consider the cost of recovering from a data breach.

As a disclaimer, TJX's side of the story is unknown, but according to the Register article when they were asked they would not comment on the matter.

Sunday, February 10, 2008

Does healthcare fraud tie into organized crime, illegal immigration and .... corporations?

Read a pretty interesting article about how identity theft is being used (more and more frequently) to commit healthcare fraud. The article also alleges that organized crime is exploiting this activity to their financial advantage.

Since organized criminals normally are hard to get a "quote" from, we'll have to speculate about how much they are involved in this phenomenon.

The article written by Jim McKay appeared in govtech.com and quoted a section chief (Sharon Ormsby) from the FBI:

At least 3 percent of U.S. health-care costs (about $60 billion) can be attributed to fraud, according to the National Health Care Anti-Fraud Association. Of that, 1 percent is attributed to medical ID theft - an ominous figure when the numbers are triangulated, according to Sharon Ormsby, section chief for the financial crimes section of the FBI.

"If you figure by 2012, national health-care expenditure costs for the country will be approximately $3 trillion, you look at the fact that the National Health Care Anti-Fraud Association conservatively estimates health-care fraud to be 3 percent to 5 percent of that expenditure amount," she said. "That's a significant amount of fraud, so we do have a strong interest in it."

Another interesting article related to the subject of healthcare fraud showed up in the news in the past few days, also. CBS News did a story about a "whistleblower," who turned in his superiors -- in this instance a hospital -- for fraudulently billing government healthcare programs.

Unlike the govtech.com article -- which only suggests a dollar loss -- the CBS piece estimates the cost of healthcare fraud at about $11 billion a year.

Sharyl Attkisson, a CBS correspondent covered this story and it points to more commentary about government waste in general on the Couric (Katie) and Co. blog.

Please note the whistleblower in this instance received $3 million for turning in his employer.

With the baby boom generation headed for retirement and reports of hospitals going under because they provide free healthcare for illegal immigrants, there is a lot of camouflage for healthcare fraud to hide in.

The fact that a hospital was in on the fraud shouldn't surprise a lot of people, either. If you are following the 2008 election, the subject of legitimate companies gouging the healthcare system for profit isn't a new topic.

There is little doubt that the subject of healthcare costs is a hot topic and will continue to be for a long time to come.

Govtech.com article, here.

Here is a story, I did in May that covers the ties between healthcare fraud, organized crime and illegal immigration:

Medicare Fraud arrests might expose ties to medical identity theft and organized crime