<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Laptop Security Blog &#187; Data Breach</title>
	<atom:link href="http://blog.absolute.com/category/data-breach/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.absolute.com</link>
	<description>Laptop Security blog by Absolute Software</description>
	<lastBuildDate>Fri, 20 Nov 2009 21:57:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Network Solutions Breach Is Handled Well</title>
		<link>http://blog.absolute.com/network-solutions-breach-is-handled-well/</link>
		<comments>http://blog.absolute.com/network-solutions-breach-is-handled-well/#comments</comments>
		<pubDate>Thu, 06 Aug 2009 00:18:26 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[breach report]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1468</guid>
		<description><![CDATA[Who Breached: Network Solutions
Number Affected: 500,000+
Information breached: Credit card information
How: hacked
As the result of a hacker penetrating their e-commerce system, Network Solutions has determined that approximately 573,938 credit card holders may have had their data transfered. The company detected that hackers had placed unauthorized code on servers for some e-commerce merchants&#8217; websites, and that this [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/../uploads/breach.jpg" alt="" width="135" height="150" /><strong>Who Breached: </strong>Network Solutions<br />
<strong>Number Affected: </strong>500,000+<br />
<strong>Information breached: </strong>Credit card information<br />
<strong>How: </strong>hacked</p>
<p>As the result of a hacker penetrating their e-commerce system, <a href="http://www.networksolutions.com/">Network Solutions</a> has determined that approximately 573,938 credit card holders may have had their data transfered. The company detected that <strong>hackers had placed unauthorized code </strong>on servers for some e-commerce merchants&#8217; websites, and that this code may have been used to transfer data on some transactions. The credit card data was encrypted and PCI-compliant, and it is currently unknown how the malicious code entered the system.</p>
<p>From their<a href="http://about.networksolutions.com/site/data-security-alert-problem-fix-and-customers-notified/"> news report</a>:</p>
<blockquote><p>The unauthorized code may have been used to transfer data on certain transactions for approximately 4,343 of our more than 10,000 merchant websites to servers outside the company. On July 13, 2009, we were informed by our outside forensic experts that the data being transferred may have included credit card information. The code may have captured transaction data from approximately 573,928 cardholders for certain periods this spring.</p></blockquote>
<p>Merchants and their customers are currently being notified. Network Solutions has additionally put together an <strong>informational website for their merchants at <a href="http://www.careandprotect.com/">careandprotect.com</a></strong>. Consumer information is also included there for reference. They have included a <a href="http://www.careandprotect.com/feedback/">blog</a> in the website to answer questions that have arisen in the last week.</p>
<p>The quick and forthright response by Network Solutions has been quite impressive. They seem very keen to answer questions and be public with their responses. In addition, they have offered to foot the bill for customer notification, rather than those costs falling to the merchants affected.</p>
<p><strong>Other notable data breaches from July:</strong></p>
<ul>
<li>HSBC Life, Lost Media, 180,000 affected (<a href="http://news.bbc.co.uk/1/hi/business/8162787.stm">read more</a>)</li>
<li>University of California San Diego Moores Cancer Center, Hack, 30,000 affected (<a href="http://www3.signonsandiego.com/stories/2009/jul/16/1m16breach001243-computers-breached-cancer-center/">read more</a>)</li>
<li>LexisNexis, possible organized crime, &gt;13,000 (<a href="http://www.pcworld.com/article/168311/lexisnexis_warns_of_breach_after_alleged_mafia_bust.html">read more</a>)</li>
<li>Alberta Health Services Edmonton, Virus, &gt;11,000 (<a href="http://www.cbc.ca/canada/edmonton/story/2009/07/09/edmonton-virus-ahs.html">read more</a>)</li>
</ul>
<p>Via <a href="http://datalossdb.org">datalossdb</a>, <a href="http://www.theregister.co.uk/2009/07/25/network_solutions_ecommerce_breach/">the register</a>,</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/network-solutions-breach-is-handled-well/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Heartland Breach is Costly</title>
		<link>http://blog.absolute.com/heartland-breach-is-costly/</link>
		<comments>http://blog.absolute.com/heartland-breach-is-costly/#comments</comments>
		<pubDate>Thu, 21 May 2009 15:53:27 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[breach costs]]></category>
		<category><![CDATA[breach statistics]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1371</guid>
		<description><![CDATA[Earlier this year, we posted about one of the largest data breaches to ever come to light: the Heartland Payment Systems breach that affected as many as 100 million people after their network was compromised. News this month indicates that the breach has cost the company $12.6 million in legal costs and fines from MasterCard [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right;" src="http://blog.absolute.com/wp/wp-content/uploads/j0411534.gif" alt="" width="192" height="192" />Earlier this year, we posted about one of the largest data breaches to ever come to light: the <a href="http://blog.absolute.com/payment-system-breach-may-expose-100-million/"><strong>Heartland Payment Systems breach</strong></a> that affected as many as 100 million people after their network was compromised. <a href="http://blogs.zdnet.com/security/?p=3352">News</a> this month indicates that the breach has cost the company <strong>$12.6 million</strong> in legal costs and fines from MasterCard and Visa.</p>
<p>In a <a href="http://seekingalpha.com/article/136164-heartland-payment-systems-inc-q1-2009-earnings-call-transcript?page=-1">conference call with investors</a>, Heartland&#8217;s CEO, Robert Carr, shared the financial damage that was the result of the Q1 breach. They say that of the $12.6 million charge, less than $1 million is related to fines by Visa, but more than 50% of the cost is associated with a fine from MasterCard. The company is <strong>contesting the fines, </strong>which allege a failure by Heartland to take appropriate action upon learning of the network compromise.</p>
<p>Carr has been frank about talking about the data breach, and <strong>lays some <a href="http://www.pcworld.com/businesscenter/blogs/stub/164637/heartland_comes_out_swinging_after_data_breach.html">blame</a> on the payment industry itself for not having stringent enough best practices</strong>. Though I think it&#8217;s great that Heartland is encouraging new best practices, those <strong>best practices are a baseline of efforts in any industry</strong>. Companies should always be considering their particular risk factors and taking any added measures necessary to mitigate those.</p>
<p>Heartland was recently re-certified as PCI DSS compliant by Visa, MasterCard and Discover. However, much damage has been done to their reputation and, fines aside, the costs of this breach have been severe.</p>
<p><em>Image: Clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/heartland-breach-is-costly/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>1 Million Affected After Laptop Stolen from Car</title>
		<link>http://blog.absolute.com/1-million-affected-after-laptop-stolen-from-car/</link>
		<comments>http://blog.absolute.com/1-million-affected-after-laptop-stolen-from-car/#comments</comments>
		<pubDate>Mon, 04 May 2009 16:37:23 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Laptop Security]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[breach report]]></category>
		<category><![CDATA[laptop theft]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1323</guid>
		<description><![CDATA[Who Breached: Oklahoma Department of Human Services
Number Affected: 1 Million+
Information breached: Social Security Numbers
How: laptop stolen from car
It&#8217;s been a while since I&#8217;ve done a major highlight of any recent data breaches. They keep happening, to be sure, but the details often start to look the same. However, this one caught my eye from it&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/../uploads/breach.jpg" alt="" width="135" height="150" /><strong>Who Breached: </strong>Oklahoma Department of Human Services<br />
<strong>Number Affected: </strong>1 Million+<br />
<strong>Information breached: </strong>Social Security Numbers<br />
<strong>How: </strong>laptop stolen from car</p>
<p>It&#8217;s been a while since I&#8217;ve done a major highlight of any recent data breaches. They keep happening, to be sure, but the details often start to look the same. However, this one caught my eye from it&#8217;s magnitude. The <a href="http://www.okdhs.org/">Oklahoma Department of Human Services</a> (OKDHS) is notifying more than <strong>1 million</strong> residents of the state that their data has been breached as the result of a <strong>stolen, unencrypted, laptop</strong>.</p>
<p>According to their <a href="http://www.okdhs.org/library/news/rel/2009/04/iso04232009.htm">press release</a>, a password-protected OKDHS laptop was stolen from an employee vehicle (<a href="http://blog.absolute.com/why-you-need-absolute-software-videos/">a far too common theft location</a>). The laptop contained names, Social Security Numbers, dates of birth and home addresses for clients who received Medicaid, Child Care assistance, and other program assistance. The laptop was stolen on April 3rd with a press release going out from OKDHS on April 23rd. Letters to affected clients started to go out in the same week.</p>
<p>OKDHS Director Howard H. Hendrick <a href="http://www.okdhs.org/library/news/rel/2009/04/iso04232009.htm">believes</a> the &#8220;risk of the data being accessed is low because the computer uses a password protected system,&#8221; which is only a <strong>very minor security protocol</strong>. There&#8217;s no guarantee the password was strong and, even with strong password-protection, systems with no additional security precautions pose a high risk for being easily accessed. It is believed that the employee was <strong>not violating any policy in place</strong>, indicating that the current information security policy does not deal with taking data home or with proper data asset handling.</p>
<p>According to the <a href="http://www.okdhs.org/protectyouridentity/default.htm">Security Incident FAQ</a>, OKDHS believes they have<strong> &#8220;numerous security measures&#8221; in place already</strong> to ensure client data is safeguarded, but plan to review all policy, procedures and training methods. Let&#8217;s hope this sheds some light through the entire organization about how much more can &#8211; and should &#8211; be done to protect sensitive information.</p>
<p>You can help prevent data breaches such as these, or recover from them more easily, with strong <strong>computer security policies, enforcement and training and software such as <a href="http://www.absolute.com/products-computrace-products.asp">Computrace</a> </strong>from Absolute, which offers many <a href="http://www.absolute.com/laptop-security-solutions.asp">layers</a> of security protection.</p>
<p>Via <a href="http://www.scmagazineus.com/Unencrypted-laptop-with-1-million-SSNs-stolen-from-state/article/131333/">SC Magazine</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/1-million-affected-after-laptop-stolen-from-car/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verizon 2009 Business Data Breach Report</title>
		<link>http://blog.absolute.com/verizon-2009-business-data-breach-report/</link>
		<comments>http://blog.absolute.com/verizon-2009-business-data-breach-report/#comments</comments>
		<pubDate>Thu, 23 Apr 2009 16:22:50 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Surveys & Reports]]></category>
		<category><![CDATA[breach report]]></category>
		<category><![CDATA[breach statistics]]></category>
		<category><![CDATA[report]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1295</guid>
		<description><![CDATA[Verizon has released its 2009 Business Data Breach Investigations Report, following similar reports earlier this year from the ITRC and Ponemon. The report indicates that 285 million records were breached in 2008. This figure is much higher than the 35.7 million records that the ITRC estimated based on notification letters.
Highlights from the study include:

91% of [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.verizonbusiness.com/products/security/risk/databreach/"><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/breach-report.jpg" alt="" width="215" height="180" /></a><a href="http://www.verizonbusiness.com/products/security/risk/databreach/">Verizon</a> has released its 2009 Business Data Breach Investigations Report, following similar reports earlier this year from the <a href="http://blog.absolute.com/2008-data-breaches-up-47/">ITRC</a> and <a href="http://blog.absolute.com/average-cost-per-breached-record-rises-to-202/">Ponemon</a>. The report indicates that <strong>285 million records were breached in 2008</strong>. This figure is much higher than the 35.7 million records that the <a href="http://blog.absolute.com/2008-data-breaches-up-47/">ITRC</a> estimated based on notification letters.</p>
<p><strong>Highlights from the study include:</strong></p>
<ul>
<li>91% of all compromised records were attributed to organized criminal groups</li>
<li>99.6% of records were compromised from servers and applications</li>
<li>74% resulted from external sources</li>
<li>20% resulted from insiders</li>
<li>69% were discovered by a 3rd party</li>
<li>67% were aided by significant errors</li>
<li>32% implicated business partners</li>
<li>95% of data breaches were rated as high difficulty requiring advanced skills, significant customization, and/or extensive resources</li>
</ul>
<p>The most successful breaches involved an attacker exploiting some mistake made by the victim, allowing them to hack into a network and collect data. Hacking and malware were the top single causes of breaches, both up from the figures for 2007.</p>
<p>Although <a href="http://www.csoonline.com/article/489644/Study_Mistakes_Not_Malicious_Insiders_to_Blame_for_Most_Breaches">much</a> of the <a href="http://www.informationweek.com/blog/main/archives/2009/04/verizon_breach.html">response</a> to this survey has been on the thread of insider threats being lower than expected, I have to argue that the data seems in line with previous data. Although there is an indication that <a href="http://blog.absolute.com/mitigating-risks-of-insider-data-theft/">insider threats will go up</a> for 2009, the 20% insider data breach figure quoted here is actually <em>higher</em> than the previously <a href="http://blog.absolute.com/2008-data-breaches-up-47/">estimated</a> 15.7%. I think fear of future insider threats has simply muddled our perspective of the past year.</p>
<p>The data about insiders, however, has been more revealing. On a per breach basis, <strong>insiders were responsible for more records lost, on average,</strong> per breach than other causes, such as external sources or partners.</p>
<p>The report suggests that <strong>mitigation efforts</strong> be focused on ensuring essential controls are met; finding, tracking &amp; assessing data; collecting and monitoring event logs; auditing user accounts and credentials; and testing and reviewing web applications.</p>
<p><strong>Download the breach report <a href="http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf">here</a> [PDF].</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/verizon-2009-business-data-breach-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Don&#8217;t Ignore Physical Data Management</title>
		<link>http://blog.absolute.com/dont-ignore-physical-data-management/</link>
		<comments>http://blog.absolute.com/dont-ignore-physical-data-management/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 19:41:02 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Business Security]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[Theft News]]></category>
		<category><![CDATA[Theft Prevention]]></category>
		<category><![CDATA[data security]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1204</guid>
		<description><![CDATA[Normally we hear about the massive data breaches that happen due to some loss of electronic data &#8211; whether it&#8217;s a lost data storage device or laptop or from hacking. However, we can&#8217;t forget that paper too is at risk for breaching data. This week there were 4 reports of data breaches the result of [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right;" src="http://blog.absolute.com/wp/../uploads/lockcn-2995.jpg" alt="" width="200" height="133" />Normally we hear about the massive data breaches that happen due to some loss of electronic data &#8211; whether it&#8217;s a lost data storage device or laptop or from hacking. However, we can&#8217;t forget that <strong>paper too is at risk for breaching data</strong>. This week there were <strong>4 reports of data breaches</strong> the result of incidents with paper.</p>
<ol>
<li>Dozens of files with Social Security Numbers for public housing residents were <strong>dumped on the street</strong> in New York. People were seen picking up the loose papers, raising concerns of identity theft. The New York Housing Authority has policies to shred documents for disposal, but that policy was overlooked. [<a href="http://www.nydailynews.com/ny_local/brooklyn/2009/03/19/2009-03-19_id_theft_feared_as_files_found_in_street.html">read more</a>]</li>
<li>Medical records were found <strong>discarded in a trash bin</strong> at a convenience store in Shreveport; Social Security Numbers were included. A Doctor has admitted to his mistake in improperly disposing of the files. [<a href="http://www.ktbs.com/news/Medical-records-discarded-in-trash-bin-27856/">read more</a>]</li>
<li>Files about seriously ill patients at a New York hospital were found 2 miles away on the <strong>pavement.</strong> The files contained name, age and medical history, breaching confidentiality though not risking identity theft. [<a href="http://www.thepress.co.uk/news/4218816.Medical_records_from_York_Hospital_found_in_street/">read more</a>]</li>
<li>A Dallas man found a box of medical records, including Social Security Numbers, the the parking lot at a storage business. The <strong>storage unit </strong>belonging to a doctor was <strong>broken into</strong> and the records left out. [<a href="http://www.msnbc.msn.com/id/29737855/">read more</a>]</li>
</ol>
<p>I think we can learn some important things from these breaches of trust and data. Most indicate a<strong> lack of awareness about the data and how it should be treated for storage and disposal.</strong> Policies to restrict how data moves about &#8211; whether paper or electronic &#8211; should be considered. The <a href="http://blog.absolute.com/document-retention-policy/">data retention policy</a> should define how information is disposed of, which can include policies on shredding or purging electronic devices. In terms of data storage for physical papers, standard consumer storage facilities may not have enough security; try looking for companies that specialize in business data storage.</p>
<p>As we shared in a <a href="http://blog.absolute.com/data-breaches-under-reported-by-factor-of-100/">report earlier this month</a>, data breaches at small companies often go unreported. There&#8217;s a great deal of education that needs to be done to small business owners &#8211; including those practicing in the medical fields &#8211; about how to securely handle confidential data in all stages of its life cycle.</p>
<p>Hat tip to <a href="http://www.databreaches.net">databreaches.net</a> ; image: <a href="http://morguefile.com/archive/?display=55949&amp;">clarita</a> @morguefile</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/dont-ignore-physical-data-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Breach News: Heartland &amp; More</title>
		<link>http://blog.absolute.com/breach-news-heartland-more/</link>
		<comments>http://blog.absolute.com/breach-news-heartland-more/#comments</comments>
		<pubDate>Thu, 05 Mar 2009 16:51:06 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Theft News]]></category>
		<category><![CDATA[breach report]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1128</guid>
		<description><![CDATA[Following on the heels of the Heartland Payment Systems breach that affected as many as 100 million credit cards, 3 arrests were made. The arrests followed the 3-month investigation into a stolen credit card ring. The arrests were for men caught using stolen credit card numbers at local WalMart stores. Apparently the Secret Service has [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0411534.gif" alt="" width="192" height="192" />Following on the heels of the <a href="http://blog.absolute.com/payment-system-breach-may-expose-100-million/"><strong>Heartland Payment Systems breach</strong></a> that affected as many as 100 million credit cards, <a href="http://consumerist.com/5154010/three-men-arrested-in-heartland-data-breach-for-using-fake-visa-gift-cards">3 arrests</a> were made. The arrests followed the 3-month investigation into a stolen credit card ring. The arrests were for men caught using stolen credit card numbers at local WalMart stores. Apparently the Secret Service has a <strong><a href="http://www.storefrontbacktalk.com/securityfraud/feds-identify-overseas-suspect-in-heartland-case/">suspect</a></strong> in the Heartland data breach, someone outside North America.</p>
<p>With more than 580 institutions <a href="http://www.bankinfosecurity.com/articles.php?art_id=1200">affected</a> by this data breach, it should be no surprise that lawsuits would follow. A PA-based law firm filed a <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1346268,00.html">class action lawsuit</a> against Heartland in January, accusing Heartland of belated and inaccurate notifications of the breach and inadequate security precautions. In addition, this week<strong> 8 banks and credit unions filed <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9128841&amp;intsrc=news_ts_head">lawsuits</a> against Heartland</strong> over its failure to protect credit and debit card data. The lawsuits seek compensation for the costs of breach notification and re-issue of cards by the financial institutions. Where fraud has occurred, the banks also seek recompense.</p>
<p><strong>Other large breaches</strong>: the Arkansas Department of Information Systems lost a data tape from storage (<a href="http://breach.scmagazineblogs.com/2009/02/25/sensitive-tape-missing-from-arkansas-dis/">807,000 affected</a>), and it appears that information about the communications, navigation and management electronics on Marine One (the Presidential helicopter) were <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9128820">accidentally leaked</a> onto a peer-to-peer file sharing network. It was thought for a week that there was a new large <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=cybercrime_and_hacking&amp;articleId=9128429&amp;taxonomyId=82&amp;intsrc=kc_top">payment processing</a> breach, but Visa has issued a <a href="http://www.scmagazineus.com/Visa-claims-payment-processor-breach-is-not-new/article/128104/">statement</a> that clarifies that breach notifications pertain to existing, not new, issues.</p>
<p>It also caught my eye that the Berkeley Center for Law &amp; Technology and the Berkeley Technology Law Journal are holding their 13th annual<strong> Security Breach Notification seminar</strong> on March 6th. The seminar talks about identity theft and changes coming in the future. You can <a href="http://www.law.berkeley.edu/institutes/bclt/security/schedule.htm">learn more here</a>. If you can&#8217;t make it, check out some resources <a href="http://www.law.berkeley.edu/institutes/bclt/security/resources.html">here</a>.</p>
<p><em>Image: Clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/breach-news-heartland-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Computers Missing at Nuclear Lab</title>
		<link>http://blog.absolute.com/computers-missing-at-nuclear-lab/</link>
		<comments>http://blog.absolute.com/computers-missing-at-nuclear-lab/#comments</comments>
		<pubDate>Thu, 26 Feb 2009 09:52:31 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[breach report]]></category>
		<category><![CDATA[Government Security]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1069</guid>
		<description><![CDATA[An email [PDF] obtained by the Project on Government Oversight earlier indicated that the Los Alamos National Laboratory (LANL) had lost 3 computers and a BlackBerry device during a 2-week period this year. After the news went public, further government response indicates that the nuclear weapons laboratory has a total of 67 &#8220;missing&#8221;, lost or [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/../uploads/breach.jpg" alt="" width="135" height="150" />An <a href="http://pogoarchives.org/m/nss/lanl-email-20090127.pdf">email</a> [PDF] obtained by the <a href="http://www.pogo.org/">Project on Government Oversight</a> earlier indicated that the <a href="http://www.lanl.gov/"><strong>Los Alamos National Laboratory</strong></a> (LANL) had lost 3 computers and a BlackBerry device during a 2-week period this year. After the news went public, further government response indicates that the <strong>nuclear weapons laboratory has a total of 67 &#8220;missing&#8221;,</strong> lost or stolen data devices.</p>
<p>The National Nuclear Security Administration (NNSA) <a href="http://pogoarchives.org/m/nss/nnsa-cybersecurity-letter-20090203.pdf">wrote</a> [PDF] to the LANL about the most recent computer theft expressing concern that the apparent &#8220;robustness of cyber security implementation&#8221; was not being vigilantly overseen. They say there are <strong>issues with individual security controls</strong> but also configuration management and accountability issues.</p>
<blockquote><p>&#8220;In treating this initially as only a property management issue, my staff and I, and apparently the cyber security elements of the laboratory, were not engaged in a timely and proactive manner to assess and address potential loss of sensitive information.&#8221;</p></blockquote>
<p>The quote above indicates a common misconception &#8211; that the loss of data devices is a <strong>property issue</strong>, not a data security issue. The memo advices LANL to treat all loss of equipment that can carry data &#8211; not just computers &#8211; as a cyber-security concern.</p>
<p>The letter revealed that 13 LANL computers have been stolen within the last year and that 67 are currently &#8220;missing.&#8221; Very little data was available &#8211; or collected &#8211; about what data has been compromised as the result of these breaches. Jeffrey Berger, director of communications at LANM, says that no classified data was held on any of the lost devices and thinks the leaked memos &#8220;distorted&#8221; the situation.</p>
<p>Los Alamos has suffered <a href="http://www.eweek.com/c/a/Security/Los-Alamos-Lab-Missing-Almost-100-Computers/">3 major public breaches</a> in the past, so none of this experience is &#8216;new&#8217; to them. A system like Absolute Software&#8217;s <strong><a href="http://www.absolute.com/products-computrace-products.asp">Computrace</a> could help</strong> with the <a href="http://www.absolute.com/solutions-secure-asset-tracking.asp">asset tracking</a> that appears to be a major problem for the lab &#8211; so they would know, in seconds, where every single computer is.</p>
<p>Via <a href="http://www.google.com/hostednews/afp/article/ALeqM5jXipyrzU1GKO4KQ3f4hhKyLvJvTA">AFP</a>, <a href="http://www.eweek.com/c/a/Security/Los-Alamos-Lab-Missing-Almost-100-Computers/">eweek</a>, <a href="http://news.cnet.com/8301-1009_3-10163715-83.html">CNet</a>, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyId=13&amp;articleId=9128160&amp;intsrc=hm_topic">Computerworld</a>, <a href="http://blogs.wsj.com/digits/2009/02/16/government-hack-attacks-prompt-scrutiny/">WSJ</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/computers-missing-at-nuclear-lab/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Monster.com Hack #3</title>
		<link>http://blog.absolute.com/monstercom-hack-3/</link>
		<comments>http://blog.absolute.com/monstercom-hack-3/#comments</comments>
		<pubDate>Wed, 28 Jan 2009 18:33:48 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[breach report]]></category>
		<category><![CDATA[hacked]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=945</guid>
		<description><![CDATA[Monster.com posted on January 23rd that their database had been hacked, this being the third time the company has experienced a breach of this sort.
The breached data includes contact information such as email addresses, phone numbers and usernames/passwords, but does not include personal data such as Social Security Numbers or financial data, as that is [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Monster.com</strong> <a href="http://help.monster.com/besafe/jobseeker/">posted</a> on January 23rd that their database had been <strong>hacked</strong>, this being the <strong>third</strong> time the company has experienced a breach of this sort.</p>
<p>The breached data includes contact information such as email addresses, phone numbers and usernames/passwords, but does not include personal data such as Social Security Numbers or financial data, as that is not data collected by the company. The breach affects USAJobs.gov (official job site for the US Federal Government) as well as Monster.com.</p>
<p>Despite the fact that SSNs and financial data was not breached, consumers should still be concerned about their lost data. Email addresses and other personal information can be used in <a href="http://www.cnn.com/video/?/video/tech/2008/04/26/intv.data.doctor.cnn">various</a> <strong>identity theft scams</strong> as a means to gain higher-level personal data. If consumers use the <strong>same access username &amp; password</strong> for banking services, which is all too common (41% user the same password for everything, via <a href="http://www.sophos.com/pressoffice/news/articles/2009/01/monster.html?_log_from=rss">Sophos</a>), this information can be used directly in fraud or identity theft.</p>
<p>Here&#8217;s an opinion video from <a href="http://www.sophos.com/pressoffice/news/articles/2009/01/monster.html?_log_from=rss">Sophos</a> about the Monser.com breach and why it&#8217;s important:</p>
<p align="center"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="500" height="315" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/VRFSD714MPg&amp;hl=en&amp;fs=1&amp;rel=0&amp;border=1" /><embed type="application/x-shockwave-flash" width="500" height="315" src="http://www.youtube.com/v/VRFSD714MPg&amp;hl=en&amp;fs=1&amp;rel=0&amp;border=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>In August 2007 Monster.com experienced a <a href="http://www.theregister.co.uk/2009/01/24/latest_monster_security_breach/">data breach</a> that affected 1.3 million people, who then were targeted by phishers, and in October of the same year <a href="http://www.theregister.co.uk/2007/11/20/latest_monster_security_breach/">another</a> a hacker hijacked job listings to infect visitors with malware.</p>
<p>Monster.com <a href="http://help.monster.com/besafe/jobseeker/">recommends</a> that its users <strong>change their passwords</strong> (making it mandatory on the site), with a warning to not fall prey to phishing attacks based on that premise. Monster.com will <em>not</em> be contacting consumers about this breach, by email or by mail.</p>
<p><strong>For tips about choosing a strong password, read <a href="http://blog.absolute.com/choosing-a-strong-password/">here</a> or <a href="http://blog.absolute.com/passwords-a-security-threat/">here</a>.</strong></p>
<p>Via <a href="http://ivebeenmugged.typepad.com/my_weblog/2009/01/monster-breach.html">I&#8217;ve been mugged</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/monstercom-hack-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FTC&#8217;s 5 Recommendations to Reduce Role of SSNs in ID Theft</title>
		<link>http://blog.absolute.com/ftcs-5-recommendations-to-reduce-role-of-ssns-in-id-theft/</link>
		<comments>http://blog.absolute.com/ftcs-5-recommendations-to-reduce-role-of-ssns-in-id-theft/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 17:33:44 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Business Security]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Surveys & Reports]]></category>
		<category><![CDATA[Theft Prevention]]></category>
		<category><![CDATA[ftc]]></category>
		<category><![CDATA[id theft prevention]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[recommendations]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[social security number]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=914</guid>
		<description><![CDATA[The Federal Trade Commission (FTC) has released a report on Social Security Numbers (SSNs) and their correlation with Identity Theft. The report, which can be downloaded here [PDF], is a follow-up to a 2007 workshop on the same topic and the continued work of the President&#8217;s Identity Theft Task Force that was established in May [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.ftc.gov/bcp/workshops/ssn/index.shtml"><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/ssn-logo.jpg" alt="" width="175" height="95" /></a>The <strong>Federal Trade Commission</strong> (FTC) has released a <a href="hhttp://www.ftc.gov/opa/2008/12/ssnreport.shtm">report</a> on <strong>Social Security Numbers (SSNs) and their correlation with Identity Theft.</strong> The report, which can be <a href="http://www.ftc.gov/os/2008/12/P075414ssnreport.pdf">downloaded here</a> [PDF], is a follow-up to a 2007 <a href="http://www.ftc.gov/bcp/workshops/ssn/index.shtml">workshop</a> on the same topic and the continued work of the President&#8217;s Identity Theft Task Force that was established in May 2006.</p>
<p>In the report, the FTC makes <strong>5 recommendations to reduce the role of SSNs in identity theft</strong>. One of the recommendations is that Congress take action to strengthen procedures that private-sector organizations use to authenticate identities; they are pushing for nationwide standards in authentication. The task force believes that <strong>stronger authenticaton</strong> would make it more difficult for criminals to use stolen information, SSNs included, to impersonate consumers. As the report notes:</p>
<blockquote><p>&#8220;Identity theft continues to be a major problem in this country, with victims numbering in the millions each year and out-of-pocket losses (primarily to businesses) in the billions of dollars.&#8221;</p></blockquote>
<p><strong>The Commission’s five recommendations are: </strong></p>
<ul>
<li>Improve consumer authentication</li>
<li>Restrict the public display and the transmission of SSNs</li>
<li>Establish national standards for data protection and breach notification</li>
<li>Conduct outreach to businesses and consumers</li>
<li>Promote coordination and information sharing on use of SSNs</li>
</ul>
<p>The task force believes that better authentication will make it more difficult to use SSNs to open new accounts or access existing accounts or services. They hope that this will, in turn,<strong> limit the demand for SSNs by criminals.</strong> Currently financial institutions that are federally regulated by banking agencies are the only private companies subjected to nationwide authentication standards.</p>
<p>You can continue reading more about that <a href="http://www.ftc.gov/opa/2008/12/ssnreport.shtm">here</a>, or read the more comprehensive <a href="http://www.idtheft.gov/reports/IDTReport2008.pdf">Task Force Report here</a> [PDF].</p>
<p>Via <a href="http://www.databreachwatch.org/data-breach-news/ftc-report-on-social-security-numbers-and-their-relationship-to-identity-theft/">data breach watch</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/ftcs-5-recommendations-to-reduce-role-of-ssns-in-id-theft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Payment System Breach May Expose 100 Million</title>
		<link>http://blog.absolute.com/payment-system-breach-may-expose-100-million/</link>
		<comments>http://blog.absolute.com/payment-system-breach-may-expose-100-million/#comments</comments>
		<pubDate>Thu, 22 Jan 2009 16:08:06 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=921</guid>
		<description><![CDATA[Who Breached: Heartland Payment Systems
Number Affected: As many as 100 Million+
Information breached: Credit Card Data
How: Network compromised
In a breach to rival those of TJX (~45 &#8211; 94 million) in the US and HMRC (25 million) in the UK, Heartland Payment Systems announced on January 20th that they have uncovered malicious software in their processing system. [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/../uploads/breach.jpg" alt="" width="135" height="150" /><strong>Who Breached: </strong>Heartland Payment Systems<br />
<strong>Number Affected: </strong>As many as 100 Million+<br />
<strong>Information breached: </strong>Credit Card Data<br />
<strong>How: </strong>Network compromised</p>
<p>In a breach to rival those of <a href="http://blog.absolute.com/visa-allowed-tjx-to-be-non-compliant/">TJX</a> (~45 &#8211; 94 million) in the US and <a href="http://blog.absolute.com/hmrc-data-breach-affects-25-million/">HMRC</a> (25 million) in the UK, <a href="http://www.heartlandpaymentsystems.com/">Heartland Payment Systems</a> <a href="http://www.2008breach.com/">announced</a> on January 20th that they have uncovered <strong>malicious software</strong> in their processing system. Cyber criminals gained access to their network and to the<strong> 100 million credit card transactions it handles each month</strong>.</p>
<p>Although no merchant information or Social Security Numbers were compromised, data that was improperly accessed included the information on a <strong>card&#8217;s magnetic strip </strong>(card number, expiration date, bank codes), which could be used to duplicate the cards. Heartland says that it cannot estimate the number of records that may have been accessed.</p>
<p>Avivah Litan, analyst at Gartner, calls the Heartland Payment Systems breach the &#8220;<strong>largest card-data breach ever</strong>&#8220;. Heartland&#8217;s president <a href="http://online.wsj.com/article/SB123249174099899837.html">says</a> it&#8217;s too early for such a &#8220;speculative&#8221; statement.</p>
<p>Heartland has set up a <a href="http://www.2008breach.com/">breach website</a> with a statement of the incident:</p>
<blockquote><p>&#8220;After being alerted by Visa® and MasterCard® of suspicious activity surrounding processed card transactions, Heartland enlisted the help of several forensic auditors to conduct a thorough investigation into the matter. Last week, the investigation uncovered malicious software that compromised data that crossed Heartland&#8217;s network.&#8221;</p></blockquote>
<p>At the time of this breach, Heartland did <strong>not have real-time monitoring of network activities </strong>that would have detected the access. The company recommends that customers examine their monthly statements closely and to report any suspicious activity.</p>
<p>Earlier this month, <a href="http://www.computerworld.com/spring/pages/article.htm?articleId=9125078">CheckFree Corporation also notified</a> more than <strong>5 million customers</strong> that criminals took control of several of their domains and redirected customers to malicious websites.</p>
<p>Via <a href="http://www.foxnews.com/story/0,2933,481127,00.html">FOX</a>, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9126379&amp;intsrc=news_ts_head">Computerworld</a>, <a href="http://online.wsj.com/article/SB123249174099899837.html">WSJ</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/payment-system-breach-may-expose-100-million/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
