Tuesday, June 03, 2008

Data breach tied to identity theft

A common response to reports of data breaches is that "that's just the number of people whose data was exposed--there's no reason to believe that the data will be used fraudulently."

ComputerWorld has an article by Robert McMillan reporting on one case where there definitely is reason to suspect fraudulent use.
A data breach at United Healthcare Services Inc. has led to a rash of identity-theft crimes at the University of California, Irvine.

To date, 155 graduate and medical students at the school have been hit by the scam, in which criminals file false tax returns in the victim's name and then collect their tax refunds. The breach affects 1,132 graduate students who were enrolled with the university's graduate student health insurance program in the 2006-07 school year, said Cathy Lawhon, the university's media relations director...

Based in Minnetonka, Minn., UnitedHealthcare is one of the largest health care service providers in the U.S. A company spokeswoman confirmed that some university students' personal information "may have been accessed without authorization," but she could not comment on the source of the breach.
I have frequently posted on this topic. Let's hope there aren't many more such stories to come. The next victim could be you! (Or, even worse, me. :-)

Labels: , , ,

1 comments

Friday, February 15, 2008

"Just one multi-million-dollar corporate data breach away from waking up"

Very scary paper by David Dagon, Niels Provos, Christopher P. Lee, and Wenke Lee.

Good summary of its implications by Kelly Jackson Higgins in Dark Reading.
The industry is just one multi-million-dollar corporate data breach away from waking up to the serious and often-silent threat of corrupted DNS resolution servers, says DNS inventor Paul Mockapetris.

Mockapetris--who is also chief scientist and chairman of the board for network naming and address vendor Nominum--says the recent research on corrupted DNS resolution servers by researchers at Georgia Tech and Google demonstrates yet another way the bad guys are attacking DNS to infect users. (See Hacking a New DNS Attack .)

Researchers David Dagon, Chris Lee, and Wenke Lee of Georgia Tech, and Google's Niels Provos, dubbed the new threat "DNS resolution path corruption,” where malicious DNS servers provide false information in order to send users to malicious sites. The researchers officially presented their findings today at the Network and Distributed System Security Symposium (NDSS) in San Diego.

In their study of DNS resolution, they found around 17 million open-recursive DNS servers on the Net, and discovered that about .4 percent, or 68,000 of them, are performing malicious operations by answering DNS queries with false information that sends them to malicious sites. About 2 percent are returning suspicious results, they reported.

“This report demonstrates that people are getting lured out to dark alleyways of the Internet. The actual damage isn’t documented here, but it will be” somewhere when someone loses the first $10 million to $100 million to this type of attack, Mockapetris says.
Surely the Department of Homeland Security is working feverishly to block this threat to the very core of the Internet? Don't bet on it.

Labels: , ,

0 comments

Monday, August 07, 2006

At least AOL apologizes for its massive privacy breach

A Reuters story by Kenneth Li covers the privacy breach and AOL's apology:
NEW YORK (Reuters) - AOL on Monday apologized for releasing information on about 20 million keyword searches in a move that ignited a firestorm of criticism about privacy rights on the Internet.

AOL, the online unit of media conglomerate Time Warner Inc., said it launched an internal investigation into how a research division of the company mistakenly released the data on its Web site about 10 days ago.

AOL released search information on about 20 million searches done from its software by about 658,000 anonymous AOL users over a three-month period, representing about one-third-of-1-percent of searches conducted over that time.

The disclosure, which AOL said was not cleared through official channels, came months after Google Inc. won kudos from privacy pundits for refusing to comply with U.S. government requests for search data on its users.

"This was a screw up, and we're angry and upset about it," said Andrew Weinstein, an AOL spokesman. "It was an innocent-enough attempt to reach out to the academic community with new research tools, but it was obviously not appropriately vetted, and if it had been, it would have been stopped in an instant."

Although user information was not disclosed, keyword searches have included users who search their own names...

One legal expert said the disclosure probably did not violate the company's own privacy policy as the data did not include personally identifiable information.

"This is more of a business snafu than anything else," Jason Epstein, head of the business and technology group at law firm Baker, Donelson, Bearman, Caldwell & Berkowitz PC said.
As with almost anything released on the Web, enough copies were made to other sites that AOL's removal of the file will not unspill the water.

Labels: ,

1 comments

Wednesday, June 22, 2005

Are Class Actions the Only Solution?

An article in the Washington Post discusses the reasons why 2005 is "the year of the data breach." Mostly just a re-hash of previously-discussed information, but there's an interesting suggestion at the very end.
Thomas F. Holt Jr., an attorney who represents companies involved in breach cases, said he expects things to change when large class-action suits begin to get filed against firms for improperly protecting information.

"When that game is afoot ... companies will begin to redouble their security efforts and reexamine a lot of assumptions they have regarding the gathering and storing of sensitive data," Holt said.

Labels: ,

0 comments

Thursday, May 05, 2005

The Five Most Shocking Things about the ChoicePoint Debacle

A good article in CSO Magazine is forceful, and focuses on the implications for corporate security officers.

"At first, the ChoicePoint security breach seemed not only ordinary but almost insignificant. That same month, February, saw stories that had bigger numbers (Bank of America, 1.2 million names and Social Security numbers) and more sex appeal (T-Mobile, Paris Hilton) than the predictable details of the ChoicePoint case. Thousands of victims, compromised Social Security numbers, an arrest on charges of identity theft. Yada yada yada.
But somewhere along the way, the ChoicePoint saga became the spark that caused an explosion.
Maybe it was the fact that this wasn't a hack. Personal information of nearly 145,000 people wasn't stolen from ChoicePoint. In fact, the company sold the information to inadequately vetted bogus businesses--this when the company itself helps other businesses verify creds.
Maybe it was that the people whose information was compromised weren't customers of ChoicePoint, just accidental citizens of the vast databases of the Alpharetta, Ga.-based information broker.
Maybe it was the way that ChoicePoint behaved after the breach: from an initial, bumbling response that smacked of marketing, to a changing story about what had happened and how the company was responding, to the revelation that top executives had sold millions of dollars worth of stock between the time the fraud was discovered and when it was announced to the public.
Or maybe it was this last twisted bit of irony: ChoicePoint chairman and CEO Derek V. Smith had recently written two books about how individuals can protect themselves in the information age.
You can't make this stuff up."

Labels: , , ,

0 comments

Wednesday, March 09, 2005

Consumer Data Stolen from Reed Elsevier U.S. Unit

A Reuters story in the Washington Post indicates that ChoicePoint has company.

"Hackers have gained access to sensitive personal information of about 32,000 U.S. citizens on databases owned by publisher Reed Elsevier, the second company to reveal a major breach in the past month. Anglo-Dutch Reed Elsevier said the breach at its Seisint unit was found after a customer's billing complaint in the last week led to the discovery that an identity and password had been misappropriated. The information accessed included names, addresses, social security and driver's license numbers, but not credit history, medical records or financial information."

Labels:

0 comments

Friday, February 25, 2005

ChoicePoint's treatment of the public

An article in the San Francisco Chronicle sums it up in the lead:
"All you really need to know about data broker ChoicePoint is contained in letters the company is sending to thousands of consumers nationwide, including about 34,000 in California, affected by a huge security breach. The letters refer to 'crimes committed against ChoicePoint' and 'fraud against the company.' As to the fact that the names, addresses and Social Security numbers of nearly 145,000 people were released over a year's time to scammers operating behind fictitious businesses, ChoicePoint says it understands 'the inconvenience this incident may cause.'

"There."

Unless the author of the letter has been a victim of identity theft, as I have, I seriously doubt that they do understand the inconvenience they are causing.

Added: Just to rub a little salt in the wound, CNN reports that "The chairman and the president of ChoicePoint -- under fire for allowing phony businesses to buy access last fall to their database of personal information on consumers -- have between them sold almost 500,000 shares of company stock for a profit of $17.6 million since November, according to Securities and Exchange Commission filings... The trades began about three months before the company disclosed the breach."

Labels: , ,

0 comments

Friday, January 04, 2008

The Top 10 Data Breaches of 2007

Interesting compilation at CSO.com, "The Resource for Security Executives."

Each breach is rated for
  • Victims
  • Class Action Outrage Scale (1 to 10 Lawyers)
  • D'oh! Factor (1 to 5 Homers)

Labels: , , , ,

0 comments

Wednesday, December 13, 2006

Third strike for Boeing privacy

A Wall Street Journal story reveals yet another privacy breach at Boeing. Apparently they still haven't learned that unencrypted information on laptops is vulnerable.
A Boeing Co. laptop containing the names and Social Security numbers of 382,000 workers and retirees has been stolen, putting the employees at risk for identity theft and credit-card fraud. The theft was the third such offense in the past 13 months.

"It's very disturbing to us when things like this happen, and there are certain steps you can take right away ... but we realize we need to go above and beyond those," said Tim Neale, a spokesman for Chicago-based Boeing.

The laptop was stolen earlier this month when an employee left it unattended, Mr. Neale said. He wouldn't reveal where the theft happened, but said no proprietary, customer or supplier data was on the computer. Files on the computer also contained home addresses, phone numbers and birth dates. Some of the files listed salary information.

The employees affected by the theft, who are mostly retirees, haven't yet been notified. Mr. Neale said the company is waiting until it has an infrastructure in place to handle the onslaught of questions it will likely receive.

A Boeing laptop containing information on roughly 160,000 current and former employees was stolen in November 2005. Then, in April, a laptop containing information on 3,600 employees and retirees was stolen...

Labels: ,

1 comments

Tuesday, March 18, 2008

Supermarket chain exposed
4 million card numbers.

According to this story in the New York Times, the Hannaford Brothers supermarket chain has reported a security breach that potentially exposed 4.2. million credit and debit card numbers. However, only 1,800 cases of resulting fraud have been identified so far.

Stay tuned.

This is a problem that won't go away until all companies processing financial information are put on the hook for all resulting losses, and are made to realize that they are on the hook. (Sarbanes-Oxley for the shopping and working public.) As with so many other things, public outrage is losing its force from sheer repetition of the offence.

Labels: , , , ,

0 comments

Monday, March 17, 2008

UK ISPs to sell users' private browsing information

This shocking post by Mike Scott in RISKS DIGEST deserves the widest possible publicity--and condemnation of the plan.
Three major UK ISPs apparently are in advanced talks with a company called Phorm, intending to let Phorm monitor all unsecured web traffic to and from their users. The expressed intent is to offer an "improved browsing experience" through better targeted web advertising, and anti-phishing protection - thereby "improving" one's internet security. One, BT, has already trialed the system...

Phorm claim the data is summarized and anonymized; regular readers of RISKS will I'm sure be aware that true anonymization is exceedingly difficult--and in fact this scheme would give ready access to identities should anyone take the trouble. Quite apart from being a breach of trust by the ISPs involved, it appears to drive a coach, horses and a whole army through protection offered by assorted UK legislation, including the Data Protection Act, Computer Misuse Act, Regulation of Regulatory Powers Act, etc, etc. It will if nothing else provide a central point for cracking to obtain information about these ISPs' users.
Edited on 4/9/08 to add: Phorm is also seeking deals with US ISPs. For more technical detail on what Phorm is doing and why it is pernicious, see "Phorm's All-seeing Parasite Cookie."

Labels: , ,

0 comments

Wednesday, March 26, 2008

Security, Economics, and the Internal Market

Ross Anderson, Rainer Böhme, Richard Clayton, and Tyler Moore have just published a 114-page study commissioned by the European Network and Information Security Agency (ENISA). The executive summary contains 15 recommendations for the European Union, most of which are just as appropriate for the United States.
We recommend that the EU introduce a comprehensive security-breach notification law.

We recommend that the Commission (or the European Central Bank) regulate to ensure the publication of robust loss statistics for electronic crime.

We recommend that ENISA collect and publish data about the quantity of spam and other bad traffic emitted by European ISPs.

We recommend that the European Union introduce a statutory scale of damages against ISPs that do not respond promptly to requests for the removal of compromised machines, coupled with a right for users to have disconnected machines reconnected if they assume full liability.

We recommend that the EU develop and enforce standards for network-connected equipment to be secure by default.

We recommend that the EU adopt a combination of early responsible vulnerability disclosure and vendor liability for unpatched software to speed the patch-development cycle.

We recommend security patches be offered for free, and that patches be kept separate from feature updates.

The European Union should harmonise procedures for the resolution of disputes between customers and payment service providers over electronic transactions.

We recommend that the European Commission prepare a proposal for a Directive establishing coherent regime of proportionate and effective sanctions against abusive online marketers.

ENISA should conduct research, coordinated with other affected stakeholders and the European Commission, to study what changes are needed to consumer-protection law as commerce moves online.

We recommend that ENISA should advise the competition authorities whenever diversity has security implications.

We recommend that ENISA sponsor research to better understand the effects of Internet exchange point (IXP) failures. We also recommend they work with telecomms regulators to insist on best practice in IXP peering resilience.

We recommend that the European Commission put immediate pressure on the 15 EU Member States that have yet to ratify the Council of Europe Convention on Cybercrime.

We recommend the establishment of an EU-wide body charged with facilitating international co-operation on cyber crime, using NATO as a model.

We recommend that ENISA champion the interests of the information security sector within the European Commission to ensure that regulations introduced for other purposes do not inadvertently harm security researchers and firms.
Thanks to Bruce Schneier for the pointer.

Labels: , , ,

0 comments

Thursday, July 06, 2006

Spaf on the VA Breach

I have belatedly seen the testimony by Prof. Eugene Spafford to the House Committee on Veterans’ Affairs Hearing on "The Academic and Legal Implications of VA’s Data Loss." As always, Spaf was crisp, insightful, and thought-provoking.
For decades, professionals in the field of information security have been warning about the dangers of weak security, careless handling of data, lax enforcement of policies, and insufficient funding for both law enforcement and research. Our warnings and cautions have largely been dismissed as unfounded or too expensive to address. Unfortunately, we are seeing the results of that lack of attention with incidents such as what happened at the VA. In addition we have seen new levels of sophisticated computer viruses and spyware, increasing cyber activity by organized crime, and significant failures of security across a wide variety of public sector entities and government agencies, including the Department of Defense...

There are many reports describing these threats, including reports from the PITAC, the GAO, the National Academies, the Department of Justice, and many commercial entities. From these reports the following general trends may be derived:
* The number of reported attacks of various kinds is increasing annually;
* Attacks are becoming more sophisticated and more efficient;
* Few perpetrators are ever caught and prosecuted;
* An unknown (but probably large) number of attacks, frauds and violations are not detected with current defenses;
* A large number of detected attacks are not reported to appropriate authorities;
* The problem is international in scope, both in origin of attacks and in location of victims;
* The majority of the attacks are enabled by faulty software, poor configuration, and operator error.

Undoubtedly the magnitude of the problems are greater than have been reported, and more has occurred than has been detected. Regrettably, I believe the situation is going to get worse because the problems have been ignored and neglected for too long to be quickly remedied.

Labels: ,

0 comments

Thursday, May 25, 2006

Gossip has its uses

According to an AP story by Hope Yen, the massive loss of personal information from the Veterans Affairs department came to the attention of higher management almost by accident.
The theft of personal data for 26.5 million veterans came to the attention of the Veterans Affairs inspector general only through office gossip, he told Congress Thursday.

In four hours of testimony, IG George Opfer said the department failed to heed years of warnings about lax security and noted that the employee who lost the data when his house was burglarized had been improperly taking the material home for three years.

"We were on borrowed time," Opfer told Senate and House panels investigating the breach.

Earlier, VA Secretary Jim Nicholson said he was "mad as hell" that he wasn't told about the burglary until May 16 — nearly two weeks after it happened. He then told the FBI on May 17, leading to a public announcement May 22.

Labels: ,

0 comments

Sunday, September 04, 2005

Everybody knew but the Bush team

A story in Wired documents why Hurricane Katrina and its aftermath should not have been a surprise to those in charge of emergency management.
Virtually everything that has happened in New Orleans since Hurricane Katrina struck was predicted by experts and in computer models, so emergency management specialists wonder why authorities were so unprepared.

"The scenario of a major hurricane hitting New Orleans was well anticipated, predicted and drilled around," said Clare Rubin, an emergency management consultant who also teaches at the Institute for Crisis, Disaster and Risk Management at George Washington University.

Computer models developed at Louisiana State University and other institutions made detailed projections of what would happen if water flowed over the levees protecting the city or if they failed.

In July 2004, more than 40 federal, state, local and volunteer organizations practiced this very scenario in a five-day simulation code-named "Hurricane Pam," where they had to deal with an imaginary storm that destroyed over half a million buildings in New Orleans and forced the evacuation of a million residents.

At the end of the exercise Ron Castleman, regional director for the Federal Emergency Management Agency declared: "We made great progress this week in our preparedness efforts.

"Disaster response teams developed action plans in critical areas such as search and rescue, medical care, sheltering, temporary housing, school restoration and debris management. These plans are essential for quick response to a hurricane but will also help in other emergencies," he said.

In light of that, said disaster expert Bill Waugh of Georgia State University, "It's inexplicable how unprepared for the flooding they were." He said a slow decline over several years in funding for emergency management was partly to blame.

In comments on Thursday, President Bush said, "I don't think anybody anticipated the breach of the levees."

But LSU engineer Joseph Suhayda and others have warned for years that defenses could fail. In 2002, the New Orleans Times Picayune published a five-part series on "The Big One," examining what might happen if they did.

Labels: , ,

0 comments

Wednesday, May 25, 2005

"Emergent Chaos" on fraud-by-impersonation

A good post by Adam Shostack. Here's a small excerpt:

The trickle of breach announcements that started with Choicepoint has grown to a stream. Soon, it will be a deluge, and it will change many things.

First, it will change the way credit is granted. Today, with a name and social security number, I may be able to get credit. If I add to that an address, phone number, or date of birth, I'm set. Some enterprising lawyer is going to look at the number of news articles around the fraud, the number of people whose personal information has leaked, and find a court that will agree that using only data that's been leaked like that is careless, and that the costs need to be shifted from the consumer onto the bank.

What will replace it will likely be a scoring based system, based on odds that you are you. Some people will suggest that a national ID card would help here, but they're wrong. Any single factor that is used to loan money will be attacked, because that's where the money is.

Labels:

0 comments

Wednesday, March 02, 2005

ChoicePoint Had Theft Case Before

A San Francisco Chronicle story indicates that ChoicePoint's recent security blunder was not the first.

"Two Nigerian-born siblings were arrested in 2002 on charges of tapping into ChoicePoint Inc.'s vast database of personal information, a security breach similar to one announced by the data warehouser last month, a newspaper reported Wednesday. A company spokesman said he did not know if the problem was made public. Bibiana Benson, 39, and her brother, Adedayo Benson, 38, gained access to at least 7,000 people and used their identities to buy at least $1 million in merchandise, the Los Angeles Times reported, citing court documents."

Labels: ,

0 comments

Monday, February 21, 2005

Hacking attacks rarely made public, experts say

A Computerworld article by Andy Sullivan from Reuters indicates that hacking attacks are rarely made public.

"A security breach that placed consumers at risk for identity theft grabbed headlines this week, but most hacking incidents go unreported to police or the public, experts said yesterday. Afraid of negative publicity, most companies that suffer intrusions take a tight-lipped approach that leaves consumers unaware that their identities may have been compromised, they said. At the same time, businesses are becoming more willing to discuss security issues with their competitors behind the scenes in an effort to head off online threats -- an approach experts that said has helped reduce the impact of computer worms and viruses. Still, a 2004 FBI cybercrime survey found that only 20% of companies report computer intrusions to the police -- and half don't report them to anybody."

Labels: , ,

0 comments

Friday, February 04, 2005

FBI Shuts Down Email System

According to an AP story: "The FBI said Friday it has shut down an e-mail system that it uses to communicate with the public because of a possible security breach. The bureau is investigating whether someone hacked into the www.fbi.gov e-mail system, which is run by a private company, officials said."

Labels:

0 comments