<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Laptop Security Blog &#187; Real Theft Reports</title>
	<atom:link href="http://blog.absolute.com/category/real-theft-reports/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.absolute.com</link>
	<description>Laptop Security blog by Absolute Software</description>
	<lastBuildDate>Fri, 20 Nov 2009 21:57:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Hackers Stealing Through Electrical Outlets</title>
		<link>http://blog.absolute.com/hackers-stealing-through-electrical-outlets/</link>
		<comments>http://blog.absolute.com/hackers-stealing-through-electrical-outlets/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 15:00:21 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Theft Prevention]]></category>
		<category><![CDATA[electrical outlet identity theft]]></category>
		<category><![CDATA[hackers power outlet]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1808</guid>
		<description><![CDATA[It’s almost unbelievable but hackers have found a way to steal personal information through electrical outlets.  It sounds implausible to many but, unfortunately, the threat is actually real.
I read an article about how hackers have found a way to “steal information typed on a computer keyboard using nothing more than the power outlet to which [...]]]></description>
			<content:encoded><![CDATA[<p>It’s almost unbelievable but hackers have found a way to steal personal information through electrical outlets.  It sounds implausible to many but, unfortunately, the threat is actually real.</p>
<p>I <a href="http://ca.tech.yahoo.com/blogs/the_working_guy/rss/article/3717">read an article</a> about how hackers have found a way to “steal information typed on a computer keyboard using nothing more than the power outlet to which the computer is connected.”</p>
<p>How is that possible?  Typing on a regular keyboard sends an electrical signal through the unshielded cable to the computer which then leaks the information into the ground wire on the computer’s power supply.  All a thief has to do is set up in a nearby location and use a power socket in order to detect and grab the information in the ground leakage.  This is possible up to 15 meters away.</p>
<p>I never would have thought this sort of thing was possible but that’s why hackers are so good at what they do – they find ingenious ways to get other people’s vital information.  If only they used those skills to do something good for the world…like find a solution to this problem.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/hackers-stealing-through-electrical-outlets/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Be Prepared, Not Lucky</title>
		<link>http://blog.absolute.com/be-prepared-not-lucky/</link>
		<comments>http://blog.absolute.com/be-prepared-not-lucky/#comments</comments>
		<pubDate>Wed, 23 Sep 2009 14:06:04 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Absolute Software]]></category>
		<category><![CDATA[Computrace]]></category>
		<category><![CDATA[Laptop Security]]></category>
		<category><![CDATA[Laptop Tracking]]></category>
		<category><![CDATA[LoJack for Laptops]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[absolute in the news]]></category>
		<category><![CDATA[computer theft]]></category>
		<category><![CDATA[laptop theft]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1671</guid>
		<description><![CDATA[Earlier this month, PC World posted a true story about a man who was able to recover his stolen laptops using a free remote-access service, LogMeIn.
The story was this: David Krop left 2 laptops in his SUV in a parking garage while he attended a meeting. The computers were stolen and they weren&#8217;t even password [...]]]></description>
			<content:encoded><![CDATA[<p>Earlier this month, <a href="http://tech.yahoo.com/news/pcworld/20090917/tc_pcworld/anamazinglaptoprecoverystory">PC World</a> posted a true story about a man who was able to recover his stolen laptops using a free remote-access service, LogMeIn.</p>
<p>The story was this: David Krop left 2 laptops in his SUV in a parking garage while he attended a meeting. The computers were stolen and they weren&#8217;t even password protected. However, David had a trial access of <a href="https://secure.logmein.com/US/home.aspx">LogMeIn</a> installed, which allowed him to remotely access his laptop. He was able to use this service to see that his stolen laptop was being used by its alleged thief. By <strong>spying on this person</strong>, and collecting all his personal information as he browsed the internet (including his face via a video chat), Krop was able to supply information to the police. The police were then able to recover the laptop.</p>
<p>Now, this sounds like a good deal, right? However, it&#8217;s a pretty a-typical situation to be in, and <strong>does not guarantee laptop recovery.</strong> The scenario depended on many factors, including:</p>
<ul>
<li>That the unauthorized user did not dismiss the tracking icon that appeared when his laptop activity was being watched</li>
<li>That the unauthorized user would reveal a wide variety of detailed personal information while using the laptop (phone number, email address, face)</li>
<li>That the unauthorized user wouldn&#8217;t wipe all the existing software off the computer</li>
</ul>
<p><img height="101" border="" width="215" style="margin: 5px; float: left" class="size-medium wp-image-1558 alignleft" alt="Computrace LoJack for Laptops" src="http://blog.absolute.com/wp/../uploads/l4l_logo-300x136.jpg" title="Computrace LoJack for Laptops" />As you can see, using LogMeIn or other free laptop tracking or remote access services is <strong>not the same thing as using a dedicated laptop tracking &amp; recovery program and service</strong> such as <a href="http://www.absolute.com/products/computrace-complete">Computrace</a> or <a href="http://www.absolute.com/products/lojack">LoJack for Laptops</a> from Absolute Software. Only Absolute has a dedicated Theft Recovery Team to work with police to recover your computer. Our software does not require your to sit around waiting for the alleged thief to supply detailed information about him/herself &#8211; all investigations and tracking are done on your behalf.  And you don&#8217;t have to hope to talk a police officer into taking on your case &#8211; we have existing relationships with local police around the world. Also, most PCs also now have our software at the <a href="http://www.absolute.com/products/bios-compatibility">BIOS level</a>, protecting it from being wiped if software is deleted. So even if a crafty thief that tries to remove the software, the BIOS firmware will make sure its installed.</p>
<p>David Krop has learned his lesson about leaving his laptop in his car. And he now uses remote tracking software. If you aren&#8217;t yet set up to track your laptop, check out our <a href="http://www.absolute.com/products">theft recovery products here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/be-prepared-not-lucky/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>DuPont Sues Employee for Insider Theft</title>
		<link>http://blog.absolute.com/dupont-sues-employee-for-insider-theft/</link>
		<comments>http://blog.absolute.com/dupont-sues-employee-for-insider-theft/#comments</comments>
		<pubDate>Mon, 14 Sep 2009 15:30:03 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Computrace]]></category>
		<category><![CDATA[Laptop Security]]></category>
		<category><![CDATA[Privacy & Security Laws]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Theft Prevention]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[dupont security breach]]></category>
		<category><![CDATA[insider theft]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1610</guid>
		<description><![CDATA[Many of us think about protecting our data against the strangers of the world who might be trying to find a way to use our information to their benefit.  It can be surprising, therefore, when the breach occurs within our company (or circle of friends, family, etc…).  Unfortunately, DuPont is learning that insider theft is [...]]]></description>
			<content:encoded><![CDATA[<p>Many of us think about protecting our data against the strangers of the world who might be trying to find a way to use our information to their benefit.  It can be surprising, therefore, when the breach occurs within our company (or circle of friends, family, etc…).  Unfortunately, <strong>DuPont</strong> is <a href="http://www.scmagazineus.com/DuPont-sues-employee-for-trade-secrets-data-breach/article/148479/">learning</a> that <a href="http://blog.absolute.com/index.php?s=insider+theft&amp;x=0&amp;y=0">insider theft</a> is becoming more and more common.<a href="http://blog.absolute.com/uploads/businessmanatlaptop.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; margin-left: 0px; border-top: 0px; margin-right: 0px; border-right: 0px" title="businessman at laptop" src="http://blog.absolute.com/uploads/businessmanatlaptop_thumb.jpg" border="0" alt="businessman at laptop" width="159" height="214" align="right" /></a></p>
<p>The industrial manufacturing company discovered that one of their employees, a senior research chemist, transferred confidential files containing trade secrets from his company-issued laptop to an external hard drive.</p>
<p>Immediately, I couldn’t help but wonder why DuPont wouldn’t have some sort of alert in place in case someone tried to attach a hard drive to company computers.  I was further baffled when I learned that this <a href="http://www.scmagazineus.com/400-million-corporate-espionage-incident-at-DuPont/article/34633/">isn’t the first time</a> they’ve been through this. </p>
<p>After 10 years with DuPont, an employee gathered information from thousands of documents and scientific abstracts.  His mission?  To sell the information to rival company, Victrex.  He ended up being sentenced to 18 months of jail time.</p>
<p>Aside from setting up some sort of alert system for when data breaches occur and using laptop security products like <a href="http://www.absolute.com/products/lojack">Computrace</a>, DuPont (and other companies) has to find a way to work around the fact that even people with legitimate access to their information need to be considered potential threats. </p>
<p><span style="font-size: xx-small;">image: www.sxc.hu</span></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/dupont-sues-employee-for-insider-theft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Network Solutions Breach Is Handled Well</title>
		<link>http://blog.absolute.com/network-solutions-breach-is-handled-well/</link>
		<comments>http://blog.absolute.com/network-solutions-breach-is-handled-well/#comments</comments>
		<pubDate>Thu, 06 Aug 2009 00:18:26 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[breach report]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1468</guid>
		<description><![CDATA[Who Breached: Network Solutions
Number Affected: 500,000+
Information breached: Credit card information
How: hacked
As the result of a hacker penetrating their e-commerce system, Network Solutions has determined that approximately 573,938 credit card holders may have had their data transfered. The company detected that hackers had placed unauthorized code on servers for some e-commerce merchants&#8217; websites, and that this [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/../uploads/breach.jpg" alt="" width="135" height="150" /><strong>Who Breached: </strong>Network Solutions<br />
<strong>Number Affected: </strong>500,000+<br />
<strong>Information breached: </strong>Credit card information<br />
<strong>How: </strong>hacked</p>
<p>As the result of a hacker penetrating their e-commerce system, <a href="http://www.networksolutions.com/">Network Solutions</a> has determined that approximately 573,938 credit card holders may have had their data transfered. The company detected that <strong>hackers had placed unauthorized code </strong>on servers for some e-commerce merchants&#8217; websites, and that this code may have been used to transfer data on some transactions. The credit card data was encrypted and PCI-compliant, and it is currently unknown how the malicious code entered the system.</p>
<p>From their<a href="http://about.networksolutions.com/site/data-security-alert-problem-fix-and-customers-notified/"> news report</a>:</p>
<blockquote><p>The unauthorized code may have been used to transfer data on certain transactions for approximately 4,343 of our more than 10,000 merchant websites to servers outside the company. On July 13, 2009, we were informed by our outside forensic experts that the data being transferred may have included credit card information. The code may have captured transaction data from approximately 573,928 cardholders for certain periods this spring.</p></blockquote>
<p>Merchants and their customers are currently being notified. Network Solutions has additionally put together an <strong>informational website for their merchants at <a href="http://www.careandprotect.com/">careandprotect.com</a></strong>. Consumer information is also included there for reference. They have included a <a href="http://www.careandprotect.com/feedback/">blog</a> in the website to answer questions that have arisen in the last week.</p>
<p>The quick and forthright response by Network Solutions has been quite impressive. They seem very keen to answer questions and be public with their responses. In addition, they have offered to foot the bill for customer notification, rather than those costs falling to the merchants affected.</p>
<p><strong>Other notable data breaches from July:</strong></p>
<ul>
<li>HSBC Life, Lost Media, 180,000 affected (<a href="http://news.bbc.co.uk/1/hi/business/8162787.stm">read more</a>)</li>
<li>University of California San Diego Moores Cancer Center, Hack, 30,000 affected (<a href="http://www3.signonsandiego.com/stories/2009/jul/16/1m16breach001243-computers-breached-cancer-center/">read more</a>)</li>
<li>LexisNexis, possible organized crime, &gt;13,000 (<a href="http://www.pcworld.com/article/168311/lexisnexis_warns_of_breach_after_alleged_mafia_bust.html">read more</a>)</li>
<li>Alberta Health Services Edmonton, Virus, &gt;11,000 (<a href="http://www.cbc.ca/canada/edmonton/story/2009/07/09/edmonton-virus-ahs.html">read more</a>)</li>
</ul>
<p>Via <a href="http://datalossdb.org">datalossdb</a>, <a href="http://www.theregister.co.uk/2009/07/25/network_solutions_ecommerce_breach/">the register</a>,</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/network-solutions-breach-is-handled-well/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Heartland Breach is Costly</title>
		<link>http://blog.absolute.com/heartland-breach-is-costly/</link>
		<comments>http://blog.absolute.com/heartland-breach-is-costly/#comments</comments>
		<pubDate>Thu, 21 May 2009 15:53:27 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[breach costs]]></category>
		<category><![CDATA[breach statistics]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1371</guid>
		<description><![CDATA[Earlier this year, we posted about one of the largest data breaches to ever come to light: the Heartland Payment Systems breach that affected as many as 100 million people after their network was compromised. News this month indicates that the breach has cost the company $12.6 million in legal costs and fines from MasterCard [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right;" src="http://blog.absolute.com/wp/wp-content/uploads/j0411534.gif" alt="" width="192" height="192" />Earlier this year, we posted about one of the largest data breaches to ever come to light: the <a href="http://blog.absolute.com/payment-system-breach-may-expose-100-million/"><strong>Heartland Payment Systems breach</strong></a> that affected as many as 100 million people after their network was compromised. <a href="http://blogs.zdnet.com/security/?p=3352">News</a> this month indicates that the breach has cost the company <strong>$12.6 million</strong> in legal costs and fines from MasterCard and Visa.</p>
<p>In a <a href="http://seekingalpha.com/article/136164-heartland-payment-systems-inc-q1-2009-earnings-call-transcript?page=-1">conference call with investors</a>, Heartland&#8217;s CEO, Robert Carr, shared the financial damage that was the result of the Q1 breach. They say that of the $12.6 million charge, less than $1 million is related to fines by Visa, but more than 50% of the cost is associated with a fine from MasterCard. The company is <strong>contesting the fines, </strong>which allege a failure by Heartland to take appropriate action upon learning of the network compromise.</p>
<p>Carr has been frank about talking about the data breach, and <strong>lays some <a href="http://www.pcworld.com/businesscenter/blogs/stub/164637/heartland_comes_out_swinging_after_data_breach.html">blame</a> on the payment industry itself for not having stringent enough best practices</strong>. Though I think it&#8217;s great that Heartland is encouraging new best practices, those <strong>best practices are a baseline of efforts in any industry</strong>. Companies should always be considering their particular risk factors and taking any added measures necessary to mitigate those.</p>
<p>Heartland was recently re-certified as PCI DSS compliant by Visa, MasterCard and Discover. However, much damage has been done to their reputation and, fines aside, the costs of this breach have been severe.</p>
<p><em>Image: Clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/heartland-breach-is-costly/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Stolen &amp; Held for Ransom</title>
		<link>http://blog.absolute.com/data-stolen-held-for-ransom/</link>
		<comments>http://blog.absolute.com/data-stolen-held-for-ransom/#comments</comments>
		<pubDate>Tue, 12 May 2009 18:36:05 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Theft News]]></category>
		<category><![CDATA[breach report]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[hacked]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1350</guid>
		<description><![CDATA[Who Breached: Virgina Prescription Monitoring Program
Number Affected: 8 million +
Information breached: Prescription records
How: hacker
This isn&#8217;t an April Fool&#8217;s Joke, though it may seem like it. Hackers allegedly broke into a Virginia state website used by pharmacists to track prescription drug abuse. The hackers then deleted records on more than 8 million patients and 35 million [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/../uploads/breach.jpg" alt="" width="135" height="150" /><strong>Who Breached: </strong>Virgina Prescription Monitoring Program</p>
<p><strong>Number Affected: </strong>8 million +</p>
<p><strong>Information breached: </strong>Prescription records</p>
<p><strong>How: </strong>hacker</p>
<p>This isn&#8217;t an April Fool&#8217;s Joke, though it may seem like it. Hackers allegedly broke into a Virginia state website used by pharmacists to track prescription drug abuse. The hackers then <strong>deleted records on more than 8 million patients</strong> and 35 million prescription records.</p>
<p>Not satisfied just with the data, the alleged hackers replaced the site&#8217;s homepage with a <strong>ransom note demanding $10 million</strong> for the return of the records. The <a href="http://www.pmp.dhp.virginia.gov/">site</a> is now completely unavailable (the state shut down access after they detected the breach), though the message was recorded.</p>
<blockquote><p>&#8220;I have your [expletive] In *my* possession, right now, are 8,257,378 patient records and a total of 35,548,087 prescriptions. Also, I made an encrypted backup and deleted the original. Unfortunately for Virginia, their backups seem to have gone missing, too. Uhoh :(For $10 million, I will gladly send along the password.&#8221;</p></blockquote>
<p>Director of Virginia&#8217;s Department of Health Professions, Sandra Whitley Ryals, declined to discuss the reported hack, saying [<a href="http://www.dhp.virginia.gov/Statement050609.pdf">PDF</a>] only that an investigation is underway by federal and state authorities. She said that they are <strong>working with experts to restore systems and ensure they&#8217;re safe</strong>. The Virginia Department of Health Professions says that all data has been backed up and those files remain secure. There is no word yet if affected patients will be contacted about this breach.</p>
<p>Via <a href="http://consumerist.com/5241357/8-million-patient-records-stolen-from-virginia-state-database-held-for-ransom">consumerist</a>, <a href="http://voices.washingtonpost.com/securityfix/2009/05/hackers_break_into_virginia_he.html">washington post</a>, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=cybercrime_and_hacking&amp;articleId=9132678&amp;taxonomyId=82&amp;intsrc=kc_top">computerworld</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/data-stolen-held-for-ransom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>1 Million Affected After Laptop Stolen from Car</title>
		<link>http://blog.absolute.com/1-million-affected-after-laptop-stolen-from-car/</link>
		<comments>http://blog.absolute.com/1-million-affected-after-laptop-stolen-from-car/#comments</comments>
		<pubDate>Mon, 04 May 2009 16:37:23 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Laptop Security]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[breach report]]></category>
		<category><![CDATA[laptop theft]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1323</guid>
		<description><![CDATA[Who Breached: Oklahoma Department of Human Services
Number Affected: 1 Million+
Information breached: Social Security Numbers
How: laptop stolen from car
It&#8217;s been a while since I&#8217;ve done a major highlight of any recent data breaches. They keep happening, to be sure, but the details often start to look the same. However, this one caught my eye from it&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/../uploads/breach.jpg" alt="" width="135" height="150" /><strong>Who Breached: </strong>Oklahoma Department of Human Services<br />
<strong>Number Affected: </strong>1 Million+<br />
<strong>Information breached: </strong>Social Security Numbers<br />
<strong>How: </strong>laptop stolen from car</p>
<p>It&#8217;s been a while since I&#8217;ve done a major highlight of any recent data breaches. They keep happening, to be sure, but the details often start to look the same. However, this one caught my eye from it&#8217;s magnitude. The <a href="http://www.okdhs.org/">Oklahoma Department of Human Services</a> (OKDHS) is notifying more than <strong>1 million</strong> residents of the state that their data has been breached as the result of a <strong>stolen, unencrypted, laptop</strong>.</p>
<p>According to their <a href="http://www.okdhs.org/library/news/rel/2009/04/iso04232009.htm">press release</a>, a password-protected OKDHS laptop was stolen from an employee vehicle (<a href="http://blog.absolute.com/why-you-need-absolute-software-videos/">a far too common theft location</a>). The laptop contained names, Social Security Numbers, dates of birth and home addresses for clients who received Medicaid, Child Care assistance, and other program assistance. The laptop was stolen on April 3rd with a press release going out from OKDHS on April 23rd. Letters to affected clients started to go out in the same week.</p>
<p>OKDHS Director Howard H. Hendrick <a href="http://www.okdhs.org/library/news/rel/2009/04/iso04232009.htm">believes</a> the &#8220;risk of the data being accessed is low because the computer uses a password protected system,&#8221; which is only a <strong>very minor security protocol</strong>. There&#8217;s no guarantee the password was strong and, even with strong password-protection, systems with no additional security precautions pose a high risk for being easily accessed. It is believed that the employee was <strong>not violating any policy in place</strong>, indicating that the current information security policy does not deal with taking data home or with proper data asset handling.</p>
<p>According to the <a href="http://www.okdhs.org/protectyouridentity/default.htm">Security Incident FAQ</a>, OKDHS believes they have<strong> &#8220;numerous security measures&#8221; in place already</strong> to ensure client data is safeguarded, but plan to review all policy, procedures and training methods. Let&#8217;s hope this sheds some light through the entire organization about how much more can &#8211; and should &#8211; be done to protect sensitive information.</p>
<p>You can help prevent data breaches such as these, or recover from them more easily, with strong <strong>computer security policies, enforcement and training and software such as <a href="http://www.absolute.com/products-computrace-products.asp">Computrace</a> </strong>from Absolute, which offers many <a href="http://www.absolute.com/laptop-security-solutions.asp">layers</a> of security protection.</p>
<p>Via <a href="http://www.scmagazineus.com/Unencrypted-laptop-with-1-million-SSNs-stolen-from-state/article/131333/">SC Magazine</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/1-million-affected-after-laptop-stolen-from-car/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Breach News: Heartland &amp; More</title>
		<link>http://blog.absolute.com/breach-news-heartland-more/</link>
		<comments>http://blog.absolute.com/breach-news-heartland-more/#comments</comments>
		<pubDate>Thu, 05 Mar 2009 16:51:06 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Theft News]]></category>
		<category><![CDATA[breach report]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1128</guid>
		<description><![CDATA[Following on the heels of the Heartland Payment Systems breach that affected as many as 100 million credit cards, 3 arrests were made. The arrests followed the 3-month investigation into a stolen credit card ring. The arrests were for men caught using stolen credit card numbers at local WalMart stores. Apparently the Secret Service has [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0411534.gif" alt="" width="192" height="192" />Following on the heels of the <a href="http://blog.absolute.com/payment-system-breach-may-expose-100-million/"><strong>Heartland Payment Systems breach</strong></a> that affected as many as 100 million credit cards, <a href="http://consumerist.com/5154010/three-men-arrested-in-heartland-data-breach-for-using-fake-visa-gift-cards">3 arrests</a> were made. The arrests followed the 3-month investigation into a stolen credit card ring. The arrests were for men caught using stolen credit card numbers at local WalMart stores. Apparently the Secret Service has a <strong><a href="http://www.storefrontbacktalk.com/securityfraud/feds-identify-overseas-suspect-in-heartland-case/">suspect</a></strong> in the Heartland data breach, someone outside North America.</p>
<p>With more than 580 institutions <a href="http://www.bankinfosecurity.com/articles.php?art_id=1200">affected</a> by this data breach, it should be no surprise that lawsuits would follow. A PA-based law firm filed a <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1346268,00.html">class action lawsuit</a> against Heartland in January, accusing Heartland of belated and inaccurate notifications of the breach and inadequate security precautions. In addition, this week<strong> 8 banks and credit unions filed <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9128841&amp;intsrc=news_ts_head">lawsuits</a> against Heartland</strong> over its failure to protect credit and debit card data. The lawsuits seek compensation for the costs of breach notification and re-issue of cards by the financial institutions. Where fraud has occurred, the banks also seek recompense.</p>
<p><strong>Other large breaches</strong>: the Arkansas Department of Information Systems lost a data tape from storage (<a href="http://breach.scmagazineblogs.com/2009/02/25/sensitive-tape-missing-from-arkansas-dis/">807,000 affected</a>), and it appears that information about the communications, navigation and management electronics on Marine One (the Presidential helicopter) were <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9128820">accidentally leaked</a> onto a peer-to-peer file sharing network. It was thought for a week that there was a new large <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=cybercrime_and_hacking&amp;articleId=9128429&amp;taxonomyId=82&amp;intsrc=kc_top">payment processing</a> breach, but Visa has issued a <a href="http://www.scmagazineus.com/Visa-claims-payment-processor-breach-is-not-new/article/128104/">statement</a> that clarifies that breach notifications pertain to existing, not new, issues.</p>
<p>It also caught my eye that the Berkeley Center for Law &amp; Technology and the Berkeley Technology Law Journal are holding their 13th annual<strong> Security Breach Notification seminar</strong> on March 6th. The seminar talks about identity theft and changes coming in the future. You can <a href="http://www.law.berkeley.edu/institutes/bclt/security/schedule.htm">learn more here</a>. If you can&#8217;t make it, check out some resources <a href="http://www.law.berkeley.edu/institutes/bclt/security/resources.html">here</a>.</p>
<p><em>Image: Clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/breach-news-heartland-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Computers Missing at Nuclear Lab</title>
		<link>http://blog.absolute.com/computers-missing-at-nuclear-lab/</link>
		<comments>http://blog.absolute.com/computers-missing-at-nuclear-lab/#comments</comments>
		<pubDate>Thu, 26 Feb 2009 09:52:31 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[breach report]]></category>
		<category><![CDATA[Government Security]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1069</guid>
		<description><![CDATA[An email [PDF] obtained by the Project on Government Oversight earlier indicated that the Los Alamos National Laboratory (LANL) had lost 3 computers and a BlackBerry device during a 2-week period this year. After the news went public, further government response indicates that the nuclear weapons laboratory has a total of 67 &#8220;missing&#8221;, lost or [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/../uploads/breach.jpg" alt="" width="135" height="150" />An <a href="http://pogoarchives.org/m/nss/lanl-email-20090127.pdf">email</a> [PDF] obtained by the <a href="http://www.pogo.org/">Project on Government Oversight</a> earlier indicated that the <a href="http://www.lanl.gov/"><strong>Los Alamos National Laboratory</strong></a> (LANL) had lost 3 computers and a BlackBerry device during a 2-week period this year. After the news went public, further government response indicates that the <strong>nuclear weapons laboratory has a total of 67 &#8220;missing&#8221;,</strong> lost or stolen data devices.</p>
<p>The National Nuclear Security Administration (NNSA) <a href="http://pogoarchives.org/m/nss/nnsa-cybersecurity-letter-20090203.pdf">wrote</a> [PDF] to the LANL about the most recent computer theft expressing concern that the apparent &#8220;robustness of cyber security implementation&#8221; was not being vigilantly overseen. They say there are <strong>issues with individual security controls</strong> but also configuration management and accountability issues.</p>
<blockquote><p>&#8220;In treating this initially as only a property management issue, my staff and I, and apparently the cyber security elements of the laboratory, were not engaged in a timely and proactive manner to assess and address potential loss of sensitive information.&#8221;</p></blockquote>
<p>The quote above indicates a common misconception &#8211; that the loss of data devices is a <strong>property issue</strong>, not a data security issue. The memo advices LANL to treat all loss of equipment that can carry data &#8211; not just computers &#8211; as a cyber-security concern.</p>
<p>The letter revealed that 13 LANL computers have been stolen within the last year and that 67 are currently &#8220;missing.&#8221; Very little data was available &#8211; or collected &#8211; about what data has been compromised as the result of these breaches. Jeffrey Berger, director of communications at LANM, says that no classified data was held on any of the lost devices and thinks the leaked memos &#8220;distorted&#8221; the situation.</p>
<p>Los Alamos has suffered <a href="http://www.eweek.com/c/a/Security/Los-Alamos-Lab-Missing-Almost-100-Computers/">3 major public breaches</a> in the past, so none of this experience is &#8216;new&#8217; to them. A system like Absolute Software&#8217;s <strong><a href="http://www.absolute.com/products-computrace-products.asp">Computrace</a> could help</strong> with the <a href="http://www.absolute.com/solutions-secure-asset-tracking.asp">asset tracking</a> that appears to be a major problem for the lab &#8211; so they would know, in seconds, where every single computer is.</p>
<p>Via <a href="http://www.google.com/hostednews/afp/article/ALeqM5jXipyrzU1GKO4KQ3f4hhKyLvJvTA">AFP</a>, <a href="http://www.eweek.com/c/a/Security/Los-Alamos-Lab-Missing-Almost-100-Computers/">eweek</a>, <a href="http://news.cnet.com/8301-1009_3-10163715-83.html">CNet</a>, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyId=13&amp;articleId=9128160&amp;intsrc=hm_topic">Computerworld</a>, <a href="http://blogs.wsj.com/digits/2009/02/16/government-hack-attacks-prompt-scrutiny/">WSJ</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/computers-missing-at-nuclear-lab/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Monster.com Hack #3</title>
		<link>http://blog.absolute.com/monstercom-hack-3/</link>
		<comments>http://blog.absolute.com/monstercom-hack-3/#comments</comments>
		<pubDate>Wed, 28 Jan 2009 18:33:48 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[breach report]]></category>
		<category><![CDATA[hacked]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=945</guid>
		<description><![CDATA[Monster.com posted on January 23rd that their database had been hacked, this being the third time the company has experienced a breach of this sort.
The breached data includes contact information such as email addresses, phone numbers and usernames/passwords, but does not include personal data such as Social Security Numbers or financial data, as that is [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Monster.com</strong> <a href="http://help.monster.com/besafe/jobseeker/">posted</a> on January 23rd that their database had been <strong>hacked</strong>, this being the <strong>third</strong> time the company has experienced a breach of this sort.</p>
<p>The breached data includes contact information such as email addresses, phone numbers and usernames/passwords, but does not include personal data such as Social Security Numbers or financial data, as that is not data collected by the company. The breach affects USAJobs.gov (official job site for the US Federal Government) as well as Monster.com.</p>
<p>Despite the fact that SSNs and financial data was not breached, consumers should still be concerned about their lost data. Email addresses and other personal information can be used in <a href="http://www.cnn.com/video/?/video/tech/2008/04/26/intv.data.doctor.cnn">various</a> <strong>identity theft scams</strong> as a means to gain higher-level personal data. If consumers use the <strong>same access username &amp; password</strong> for banking services, which is all too common (41% user the same password for everything, via <a href="http://www.sophos.com/pressoffice/news/articles/2009/01/monster.html?_log_from=rss">Sophos</a>), this information can be used directly in fraud or identity theft.</p>
<p>Here&#8217;s an opinion video from <a href="http://www.sophos.com/pressoffice/news/articles/2009/01/monster.html?_log_from=rss">Sophos</a> about the Monser.com breach and why it&#8217;s important:</p>
<p align="center"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="500" height="315" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/VRFSD714MPg&amp;hl=en&amp;fs=1&amp;rel=0&amp;border=1" /><embed type="application/x-shockwave-flash" width="500" height="315" src="http://www.youtube.com/v/VRFSD714MPg&amp;hl=en&amp;fs=1&amp;rel=0&amp;border=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>In August 2007 Monster.com experienced a <a href="http://www.theregister.co.uk/2009/01/24/latest_monster_security_breach/">data breach</a> that affected 1.3 million people, who then were targeted by phishers, and in October of the same year <a href="http://www.theregister.co.uk/2007/11/20/latest_monster_security_breach/">another</a> a hacker hijacked job listings to infect visitors with malware.</p>
<p>Monster.com <a href="http://help.monster.com/besafe/jobseeker/">recommends</a> that its users <strong>change their passwords</strong> (making it mandatory on the site), with a warning to not fall prey to phishing attacks based on that premise. Monster.com will <em>not</em> be contacting consumers about this breach, by email or by mail.</p>
<p><strong>For tips about choosing a strong password, read <a href="http://blog.absolute.com/choosing-a-strong-password/">here</a> or <a href="http://blog.absolute.com/passwords-a-security-threat/">here</a>.</strong></p>
<p>Via <a href="http://ivebeenmugged.typepad.com/my_weblog/2009/01/monster-breach.html">I&#8217;ve been mugged</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/monstercom-hack-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
