<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Laptop Security Blog &#187; Theft News</title>
	<atom:link href="http://blog.absolute.com/category/theft-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.absolute.com</link>
	<description>Laptop Security blog by Absolute Software</description>
	<lastBuildDate>Fri, 20 Nov 2009 21:57:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Identity Fraud Latest Crime Trend in UK</title>
		<link>http://blog.absolute.com/identity-fraud-latest-crime-trend-in-uk/</link>
		<comments>http://blog.absolute.com/identity-fraud-latest-crime-trend-in-uk/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 08:00:35 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Consumer Security Tips]]></category>
		<category><![CDATA[Theft News]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1859</guid>
		<description><![CDATA[Identity theft in the UK is rising at an alarming rate. A study has shown that “60,000 cases of impersonation related to criminal activity have been reported in the 9 months to date of this year, a huge increase of around 35% from the same period last year.”
The hardest hit areas are London and Birmingham.
Britons [...]]]></description>
			<content:encoded><![CDATA[<p>Identity theft in the UK is rising at an alarming rate. A study has shown that “60,000 cases of impersonation related to criminal activity have been reported in the 9 months to date of this year, a huge increase of around 35% from the same period last year.”</p>
<p>The hardest hit areas are London and Birmingham.</p>
<p>Britons are understandably worried about being affected by identity theft but it doesn’t appear that they realize what they can do to protect themselves. A recent study showed that more than 80% of Britons are concerned about becoming victims of the crime, but a fifth of them continue to do their internet banking from public computers.</p>
<p>Even more surprising, however, is the fact that 80% of businesses admitted to not having a secure way of destroying sensitive legal documents. That’s taking a huge risk with personal information!</p>
<p>The National Identity Fraud Prevention Week has been launched by the Metropolitan Police in the UK in an effort to help raise awareness about the seriousness of the crime. Hopefully, this will help Britons realize how risky some of their choices are while informing them on how to protect themselves.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/identity-fraud-latest-crime-trend-in-uk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Stolen &amp; Held for Ransom</title>
		<link>http://blog.absolute.com/data-stolen-held-for-ransom/</link>
		<comments>http://blog.absolute.com/data-stolen-held-for-ransom/#comments</comments>
		<pubDate>Tue, 12 May 2009 18:36:05 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Theft News]]></category>
		<category><![CDATA[breach report]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[hacked]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1350</guid>
		<description><![CDATA[Who Breached: Virgina Prescription Monitoring Program
Number Affected: 8 million +
Information breached: Prescription records
How: hacker
This isn&#8217;t an April Fool&#8217;s Joke, though it may seem like it. Hackers allegedly broke into a Virginia state website used by pharmacists to track prescription drug abuse. The hackers then deleted records on more than 8 million patients and 35 million [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/../uploads/breach.jpg" alt="" width="135" height="150" /><strong>Who Breached: </strong>Virgina Prescription Monitoring Program</p>
<p><strong>Number Affected: </strong>8 million +</p>
<p><strong>Information breached: </strong>Prescription records</p>
<p><strong>How: </strong>hacker</p>
<p>This isn&#8217;t an April Fool&#8217;s Joke, though it may seem like it. Hackers allegedly broke into a Virginia state website used by pharmacists to track prescription drug abuse. The hackers then <strong>deleted records on more than 8 million patients</strong> and 35 million prescription records.</p>
<p>Not satisfied just with the data, the alleged hackers replaced the site&#8217;s homepage with a <strong>ransom note demanding $10 million</strong> for the return of the records. The <a href="http://www.pmp.dhp.virginia.gov/">site</a> is now completely unavailable (the state shut down access after they detected the breach), though the message was recorded.</p>
<blockquote><p>&#8220;I have your [expletive] In *my* possession, right now, are 8,257,378 patient records and a total of 35,548,087 prescriptions. Also, I made an encrypted backup and deleted the original. Unfortunately for Virginia, their backups seem to have gone missing, too. Uhoh :(For $10 million, I will gladly send along the password.&#8221;</p></blockquote>
<p>Director of Virginia&#8217;s Department of Health Professions, Sandra Whitley Ryals, declined to discuss the reported hack, saying [<a href="http://www.dhp.virginia.gov/Statement050609.pdf">PDF</a>] only that an investigation is underway by federal and state authorities. She said that they are <strong>working with experts to restore systems and ensure they&#8217;re safe</strong>. The Virginia Department of Health Professions says that all data has been backed up and those files remain secure. There is no word yet if affected patients will be contacted about this breach.</p>
<p>Via <a href="http://consumerist.com/5241357/8-million-patient-records-stolen-from-virginia-state-database-held-for-ransom">consumerist</a>, <a href="http://voices.washingtonpost.com/securityfix/2009/05/hackers_break_into_virginia_he.html">washington post</a>, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=cybercrime_and_hacking&amp;articleId=9132678&amp;taxonomyId=82&amp;intsrc=kc_top">computerworld</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/data-stolen-held-for-ransom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Don&#8217;t Ignore Physical Data Management</title>
		<link>http://blog.absolute.com/dont-ignore-physical-data-management/</link>
		<comments>http://blog.absolute.com/dont-ignore-physical-data-management/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 19:41:02 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Business Security]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[Theft News]]></category>
		<category><![CDATA[Theft Prevention]]></category>
		<category><![CDATA[data security]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1204</guid>
		<description><![CDATA[Normally we hear about the massive data breaches that happen due to some loss of electronic data &#8211; whether it&#8217;s a lost data storage device or laptop or from hacking. However, we can&#8217;t forget that paper too is at risk for breaching data. This week there were 4 reports of data breaches the result of [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right;" src="http://blog.absolute.com/wp/../uploads/lockcn-2995.jpg" alt="" width="200" height="133" />Normally we hear about the massive data breaches that happen due to some loss of electronic data &#8211; whether it&#8217;s a lost data storage device or laptop or from hacking. However, we can&#8217;t forget that <strong>paper too is at risk for breaching data</strong>. This week there were <strong>4 reports of data breaches</strong> the result of incidents with paper.</p>
<ol>
<li>Dozens of files with Social Security Numbers for public housing residents were <strong>dumped on the street</strong> in New York. People were seen picking up the loose papers, raising concerns of identity theft. The New York Housing Authority has policies to shred documents for disposal, but that policy was overlooked. [<a href="http://www.nydailynews.com/ny_local/brooklyn/2009/03/19/2009-03-19_id_theft_feared_as_files_found_in_street.html">read more</a>]</li>
<li>Medical records were found <strong>discarded in a trash bin</strong> at a convenience store in Shreveport; Social Security Numbers were included. A Doctor has admitted to his mistake in improperly disposing of the files. [<a href="http://www.ktbs.com/news/Medical-records-discarded-in-trash-bin-27856/">read more</a>]</li>
<li>Files about seriously ill patients at a New York hospital were found 2 miles away on the <strong>pavement.</strong> The files contained name, age and medical history, breaching confidentiality though not risking identity theft. [<a href="http://www.thepress.co.uk/news/4218816.Medical_records_from_York_Hospital_found_in_street/">read more</a>]</li>
<li>A Dallas man found a box of medical records, including Social Security Numbers, the the parking lot at a storage business. The <strong>storage unit </strong>belonging to a doctor was <strong>broken into</strong> and the records left out. [<a href="http://www.msnbc.msn.com/id/29737855/">read more</a>]</li>
</ol>
<p>I think we can learn some important things from these breaches of trust and data. Most indicate a<strong> lack of awareness about the data and how it should be treated for storage and disposal.</strong> Policies to restrict how data moves about &#8211; whether paper or electronic &#8211; should be considered. The <a href="http://blog.absolute.com/document-retention-policy/">data retention policy</a> should define how information is disposed of, which can include policies on shredding or purging electronic devices. In terms of data storage for physical papers, standard consumer storage facilities may not have enough security; try looking for companies that specialize in business data storage.</p>
<p>As we shared in a <a href="http://blog.absolute.com/data-breaches-under-reported-by-factor-of-100/">report earlier this month</a>, data breaches at small companies often go unreported. There&#8217;s a great deal of education that needs to be done to small business owners &#8211; including those practicing in the medical fields &#8211; about how to securely handle confidential data in all stages of its life cycle.</p>
<p>Hat tip to <a href="http://www.databreaches.net">databreaches.net</a> ; image: <a href="http://morguefile.com/archive/?display=55949&amp;">clarita</a> @morguefile</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/dont-ignore-physical-data-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Breach News: Heartland &amp; More</title>
		<link>http://blog.absolute.com/breach-news-heartland-more/</link>
		<comments>http://blog.absolute.com/breach-news-heartland-more/#comments</comments>
		<pubDate>Thu, 05 Mar 2009 16:51:06 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Theft News]]></category>
		<category><![CDATA[breach report]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1128</guid>
		<description><![CDATA[Following on the heels of the Heartland Payment Systems breach that affected as many as 100 million credit cards, 3 arrests were made. The arrests followed the 3-month investigation into a stolen credit card ring. The arrests were for men caught using stolen credit card numbers at local WalMart stores. Apparently the Secret Service has [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0411534.gif" alt="" width="192" height="192" />Following on the heels of the <a href="http://blog.absolute.com/payment-system-breach-may-expose-100-million/"><strong>Heartland Payment Systems breach</strong></a> that affected as many as 100 million credit cards, <a href="http://consumerist.com/5154010/three-men-arrested-in-heartland-data-breach-for-using-fake-visa-gift-cards">3 arrests</a> were made. The arrests followed the 3-month investigation into a stolen credit card ring. The arrests were for men caught using stolen credit card numbers at local WalMart stores. Apparently the Secret Service has a <strong><a href="http://www.storefrontbacktalk.com/securityfraud/feds-identify-overseas-suspect-in-heartland-case/">suspect</a></strong> in the Heartland data breach, someone outside North America.</p>
<p>With more than 580 institutions <a href="http://www.bankinfosecurity.com/articles.php?art_id=1200">affected</a> by this data breach, it should be no surprise that lawsuits would follow. A PA-based law firm filed a <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1346268,00.html">class action lawsuit</a> against Heartland in January, accusing Heartland of belated and inaccurate notifications of the breach and inadequate security precautions. In addition, this week<strong> 8 banks and credit unions filed <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9128841&amp;intsrc=news_ts_head">lawsuits</a> against Heartland</strong> over its failure to protect credit and debit card data. The lawsuits seek compensation for the costs of breach notification and re-issue of cards by the financial institutions. Where fraud has occurred, the banks also seek recompense.</p>
<p><strong>Other large breaches</strong>: the Arkansas Department of Information Systems lost a data tape from storage (<a href="http://breach.scmagazineblogs.com/2009/02/25/sensitive-tape-missing-from-arkansas-dis/">807,000 affected</a>), and it appears that information about the communications, navigation and management electronics on Marine One (the Presidential helicopter) were <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9128820">accidentally leaked</a> onto a peer-to-peer file sharing network. It was thought for a week that there was a new large <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=cybercrime_and_hacking&amp;articleId=9128429&amp;taxonomyId=82&amp;intsrc=kc_top">payment processing</a> breach, but Visa has issued a <a href="http://www.scmagazineus.com/Visa-claims-payment-processor-breach-is-not-new/article/128104/">statement</a> that clarifies that breach notifications pertain to existing, not new, issues.</p>
<p>It also caught my eye that the Berkeley Center for Law &amp; Technology and the Berkeley Technology Law Journal are holding their 13th annual<strong> Security Breach Notification seminar</strong> on March 6th. The seminar talks about identity theft and changes coming in the future. You can <a href="http://www.law.berkeley.edu/institutes/bclt/security/schedule.htm">learn more here</a>. If you can&#8217;t make it, check out some resources <a href="http://www.law.berkeley.edu/institutes/bclt/security/resources.html">here</a>.</p>
<p><em>Image: Clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/breach-news-heartland-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Top 10 Ways Your Privacy Is Threatened</title>
		<link>http://blog.absolute.com/the-top-10-ways-your-privacy-is-threatened/</link>
		<comments>http://blog.absolute.com/the-top-10-ways-your-privacy-is-threatened/#comments</comments>
		<pubDate>Fri, 13 Feb 2009 15:49:52 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Theft News]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1024</guid>
		<description><![CDATA[It was Data Privacy Day on January 28th and Canada&#8217;s Privacy Commissioner put together The Top 10 Ways Your Privacy Is Threatened in order to commemorate the occasion.
Data Privacy Day was marked on January 28th in Canada, the United States and in 27 European countries. It is a day meant to remind us that data [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/dpd-10-e.jpg" alt="" />It was <strong>Data Privacy Day</strong> on January 28th and Canada&#8217;s Privacy Commissioner put together <a href="http://blog.privcom.gc.ca/index.php/2009/01/28/data-privacy-day/"><strong>The Top 10 Ways Your Privacy Is Threatened</strong></a> in order to commemorate the occasion.</p>
<p>Data Privacy Day was marked on January 28th in <a href="http://www.privcom.gc.ca/resource/dpd/index_e.asp">Canada</a>, the <a href="http://www.intel.com/policy/dataprivacy.htm">United States</a> and in 27 European countries. It is a day meant to remind us that data privacy is important and that we should all be better advocates for it. As the Canadian government notes:</p>
<blockquote><p>&#8220;Every day, we see headlines about sophisticated phishing attacks, enormous data breaches, in both the public and private sectors, and the proliferation of identity theft. It is no coincidence that as businesses began to recognize the immense potential of personal data in their efforts to connect with customers, so too did criminals begin to realize its value.&#8221;</p></blockquote>
<p>Here is what the Canadian government suggests are the 10 ways your privacy is threatened:</p>
<ol>
<li>People need to stand up for their privacy as a right</li>
<li>Information flows too freely with privacy protection laws being unequal around the world</li>
<li>Identity theft is a lucrative business</li>
<li>Cybercrime and physical data theft (laptop theft, unshredded documents)</li>
<li>Data breaches in all sectors and a lack of reporting requirements &#8211; so you may never know</li>
<li>Businesses collecting, but not protecting, data</li>
<li>Governments collecting data for national security and public safety</li>
<li>Information posted on social networking sites without reviewing privacy policies or privacy settings</li>
<li>Information you submit to new applications, online games or online shopping</li>
<li>Surveillance cameras, swipe cards, Internet searches</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/the-top-10-ways-your-privacy-is-threatened/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Veteran Affairs $20 Million Breach Settlement</title>
		<link>http://blog.absolute.com/veteran-affairs-20-million-breach-settlement/</link>
		<comments>http://blog.absolute.com/veteran-affairs-20-million-breach-settlement/#comments</comments>
		<pubDate>Wed, 28 Jan 2009 10:24:27 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Government Security]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Theft News]]></category>
		<category><![CDATA[breach settlement]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[veteran affairs]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=964</guid>
		<description><![CDATA[The U.S. Department of Veteran Affairs (VA), which suffered a data breach affecting 26.5 million people in 2006, has agreed to pay $20 million to veterans affected by the breach.
The VA data breach of 2006, which was listed as one of the 10 largest data breaches since 2000 and as one of the worst breaches [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.va.gov/"><strong>U.S. Department of Veteran Affairs</strong></a> (VA), which suffered a data breach affecting 26.5 million people in 2006, has agreed to <strong>pay $20 million to veterans affected by the breach</strong>.</p>
<p>The VA <a href="http://www.usa.gov/veteransinfo.shtml">data breach of 2006</a>, which was listed as one of the <a href="http://blog.absolute.com/10-largest-data-breaches-since-2000">10 largest data breaches since 2000 </a>and as one of the <a href="http://blog.absolute.com/worst-data-breaches/">worst breaches ever</a>, was the result of <strong>computer going missing from the home of an employee</strong>, who had taken the computer home without permission. The computer contained insurance claim data (including Social Security Numbers and insurance information) for <strong>26.5 million</strong> active duty troops and veterans, leaving them open to to identity theft and fraud.</p>
<p>The FBI was able to <a href="http://www.scmagazineus.com/Infamous-VA-laptop-recovered-appears-not-to-have-been-tampered-with/article/33575/">recover</a> the equipment and <a href="http://www.scmagazineus.com/VA-laptop-thieves-apprehended/article/33768/">apprehended</a> the thieves; the VA found no evidence that data had been compromised. The VA Inspector General faulted the data analyst and his supervisors for <strong>putting veterans at unreasonable risk</strong>. A series of delays after the employee notified his superiors meant that affected veterans were not told about the breach until 3 weeks later.</p>
<p>Five veteran groups filed a <a href="http://www.foxnews.com/story/0,2933,198561,00.html"><strong>class-action lawsuit</strong></a> against the VA alleging invasion of privacy. The lawsuit sought $1000 in damages for violations of privacy for each military personnel affected. This would have amounted to <strong>$26.5 billion in damages</strong>.</p>
<p>In court filings on Tuesday, lawyers for the VA and the veterans represented in the suit agreed to <strong>settle the lawsuit for $20 million</strong>. VA spokesman Phil Budahn made a statement, after the settlement, that:</p>
<blockquote><p>&#8220;We want to assure veterans there is no evidence that the information involved in this incident was used to harm a single veteran.&#8221;</p></blockquote>
<p>The money for the settlement will come from the U.S. Treasury and will go to veterans who can show they suffered &#8220;actual harm&#8221; (physical symptoms of emotional distress or expenses) as the result of the breach. I&#8217;ll be curious to see how they determine the &#8216;proof&#8217; of these items. Each veteran will receive <strong>$75 &#8211; $1500 upon proving their suffering</strong>. Any remainder of funds will be donated to veterans&#8217; charities. U.S. District Judge James Robertson must approve the terms of this settlement before it becomes final.</p>
<p>In November of 2007, the VA suffered a <a href="http://blog.absolute.com/veterans-affairs-new-breach-arrest/">smaller breach</a>, affecting 12,000, after 3 computers were stolen. They have suffered other data breaches, affecting up to 1.8 million, <a href="http://blog.absolute.com/veterans-affairs-new-breach-arrest/">several times</a> since 2006. Let&#8217;s hope this settlement means that the VA is truly accepting responsibility for the data breach suffered in 2006.</p>
<p>Via <a href="http://news.yahoo.com/s/ap/20090128/ap_on_go_ca_st_pe/veterans_data_theft;_ylt=AvzA5DqoYIIN1fAlHYkryQoDW7oF">Yahoo</a>, <a href="http://www.scmagazineus.com/US-Veteran-Affairs-Department-settles-data-breach-case/article/126518/">SC Magazine</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/veteran-affairs-20-million-breach-settlement/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>11 People Charged in Massive ID Theft Ring</title>
		<link>http://blog.absolute.com/11-people-charged-in-massive-id-theft-ring/</link>
		<comments>http://blog.absolute.com/11-people-charged-in-massive-id-theft-ring/#comments</comments>
		<pubDate>Fri, 08 Aug 2008 16:25:29 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Theft News]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=459</guid>
		<description><![CDATA[The Department of Justice (DoJ) has charged 11 people in connection with the hacking of 9 major retailers and the theft &#38; sale of more than 41 million credit &#38; debit card numbers (the breach figure many times more than this). This is the largest hacking and identity theft ring that the DoJ has prosecuted [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.usdoj.gov/opa/pr/2008/August/08-ag-689.html">Department of Justice</a> (DoJ) has<strong> charged 11 peopl</strong>e in connecti<img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/sealdoj.gif" alt="" width="75" height="74" />on with the hacking of 9 major retailers and the theft &amp; sale of more than<strong> 41 million </strong>credit &amp; debit card numbers (the breach figure many times more than this). This is the <strong>largest hacking and identity theft ring </strong>that the DoJ has prosecuted and is the result of 3 years worth of undercover investigations.</p>
<p>The eleven people being prosecuted, including the US Secret Service informant, have been charged with conspiracy, computer intrusion, fraud and identity theft. Three of those charged are US citizens, while the others are from Estonia, Ukraine, China, and Belarus.</p>
<p>The indictment returned on August 5th by a federal grand jury in Boston alleges that the suspects hacked into the networks of <strong>TJX Companies</strong>, BJ’s Wholesale Club, OfficeMax, Boston Market, Barnes &amp; Noble, Sports Authority, Forever 21 and DSW. Once there, the indictment alleges they installed &#8220;sniffer&#8221; programs to capture card numbers, passwords and account information. Some of the numbers were used for personal gain, while others were sold and then used to cash out large sums of money. The total dollar amount of the theft is &#8220;impossible to quantify&#8221;, but is in the multi-million-dollar range. The <a href="http://blog.absolute.com/visa-allowed-tjx-to-be-non-compliant/">TJX breach</a> alone has caused severe losses to the company.</p>
<blockquote><p>&#8220;So far as we know, this is the single largest and most complex identity theft case ever charged in this country,&#8221; said Attorney General Mukasey. &#8220;It highlights the efforts of the Justice Department to fight this pernicious crime and shows that, with the cooperation of our law enforcement partners around the world, we can identify, charge and apprehend even the most sophisticated international computer hackers.&#8221;</p></blockquote>
<p>The United States Secret Service and the Department of Justice has worked with the governments and police forces in Estonia, Ukraine, China, and Belarus to investigate, apprehend and prosecute the individuals allegedly associated with these crimes.</p>
<p><strong><a href="http://www.usdoj.gov/opa/pr/2008/August/08-ag-689.html">Read more from the DoJ release here.</a></strong></p>
<p>Via <a href="http://www.huffingtonpost.com/2008/08/05/biggest-identity-theft-ca_n_117094.html">huffington post</a>, <a href="http://money.cnn.com/2008/08/05/news/companies/card_fraud/?postversion=2008080604">CNN,</a> <a href="http://www.pcworld.com/article/149485/massive_identity_theft_exposes_troubling_trend.html">PC World</a> (<a href="http://www.pcworld.com/article/149441/article.html?tk=rel_news">2</a>) <small>Tags: <a rel="tag" href="http://technorati.com/tag/department+of+justice">department of justice</a>, <a rel="tag" href="http://technorati.com/tag/doj">doj</a>, <a rel="tag" href="http://technorati.com/tag/identity+theft">identity theft</a>, <a rel="tag" href="http://technorati.com/tag/id+theft">id theft</a>, <a rel="tag" href="http://technorati.com/tag/tjx">tjx</a>, <a rel="tag" href="http://technorati.com/tag/tjx+breach">tjx breach</a>, <a rel="tag" href="http://technorati.com/tag/fraud">fraud</a>, <a rel="tag" href="http://technorati.com/tag/hacking">hacking</a>, <a rel="tag" href="http://technorati.com/tag/prosecution">prosecution</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/11-people-charged-in-massive-id-theft-ring/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Sophistication of the Underground Data Economy</title>
		<link>http://blog.absolute.com/the-sophistication-of-the-underground-data-economy/</link>
		<comments>http://blog.absolute.com/the-sophistication-of-the-underground-data-economy/#comments</comments>
		<pubDate>Tue, 13 May 2008 13:00:15 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Theft News]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=315</guid>
		<description><![CDATA[The black market for data is much more sophisticated than most people realize. It&#8217;s not a &#8220;one price fits all&#8221; scenario. There are price points, just like in any advanced market. And, just like the same markets, there are services provided to prospective customers.
Francois Paget of McAfee&#8217;s Avert Labs blog has shared a discovery about [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>black market for data is much more sophisticated</strong> than most people realize. It&#8217;s not a &#8220;one price fits all&#8221; scenario. There are price points, just like in any advanced market. And, just like the same markets, there are services provided to prospective customers.</p>
<p>Francois Paget of <a href="http://www.avertlabs.com/research/blog/index.php/2008/05/07/you-have-to-pay-for-quality/">McAfee&#8217;s Avert Labs blog</a> has shared a discovery about the<strong> prices going on different &#8220;quality&#8221; levels of data</strong> on the black market.</p>
<p>Avert Labs has discovered a <strong>&#8220;price list&#8221; for everything</strong> from credit card numbers to bank account logins and other personal data that is sold in the underground economy. A tip led them to a website that was<strong> auctioning off data,</strong> including bank logons and credit card information, with prices such as:</p>
<ul>
<li>Washington Mutual (US), balance $14,400 (sell price 600 euros/$924)</li>
<li>Citibank (UK), balance 10,044 pounds/$19,626 (sell price 850 euros/$1,310)</li>
</ul>
<p>If you buy a bank account login, and the data owner has cancelled the account within 24 hours, they&#8217;ll even <em>give you a replacement stolen account. </em></p>
<p>So, the black market is an <strong>organized system</strong> with value for quality, and even customer service. The same website sold information in &#8220;bundle prices&#8221; and offers <em>free data </em>only a daily basis, as &#8220;goodies&#8221; to entice their sale.</p>
<p><strong>Visit the <a href="http://www.avertlabs.com/research/blog/index.php/2008/05/07/you-have-to-pay-for-quality/">Avert Labs site </a>for more information and screen shots of the system in question. </strong></p>
<p>Via <a href="http://www.news.com/8301-10784_3-9939862-7.html?part=rss&amp;tag=feed&amp;subj=NewsBlog">CNet</a> <small>Tags: <a rel="tag" href="http://technorati.com/tag/black+market">black market</a>, <a rel="tag" href="http://technorati.com/tag/data">data</a>, <a rel="tag" href="http://technorati.com/tag/data+resale">data resale</a>, <a rel="tag" href="http://technorati.com/tag/underground+economy">underground economy</a>, <a rel="tag" href="http://technorati.com/tag/data+breach">data breach</a>, <a rel="tag" href="http://technorati.com/tag/personal+data">personal data</a>, <a rel="tag" href="http://technorati.com/tag/data+resale">data resale</a>, <a rel="tag" href="http://technorati.com/tag/identity+theft">identity theft</a>, <a rel="tag" href="http://technorati.com/tag/fraud">fraud</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/the-sophistication-of-the-underground-data-economy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>University of Virginia Breaches 7,000 after laptop theft</title>
		<link>http://blog.absolute.com/university-of-virginia-breaches-7000-after-laptop-theft/</link>
		<comments>http://blog.absolute.com/university-of-virginia-breaches-7000-after-laptop-theft/#comments</comments>
		<pubDate>Fri, 18 Apr 2008 15:55:36 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Education Security]]></category>
		<category><![CDATA[Laptop Security]]></category>
		<category><![CDATA[Real Theft Reports]]></category>
		<category><![CDATA[Theft News]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/university-of-virginia-breaches-7000-after-laptop-theft/</guid>
		<description><![CDATA[Who Breached: University of Virginia (UVa)
Number Affected: 7,000
Information breached: Social Security Numbers
How: laptop theft
Daily Progress is reporting that the University of Virginia (UVa) has breached the information of 7,000 students, staff and faculty members as the result of a laptop theft. The laptop contained personally identifiable information including names and Social Security Numbers.
The laptop was [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Who Breached:</strong> University of Virginia (UVa)<br />
<strong>Number Affected:</strong> 7,000<br />
<strong>Information breached:</strong> Social Security Numbers<br />
<strong>How:</strong> laptop theft</p>
<p><a href="http://www.dailyprogress.com/cdp/news/local/article/uva_laptop_stolen_had_sensitive_data/17976/">Daily Progress</a> is reporting that the <a href="http://www.virginia.edu/">University of Virginia</a> (UVa) has breached the information of<strong> 7,000 students,</strong> staff and faculty members as the result of a <strong>laptop theft. </strong>The laptop contained personally identifiable information including names and Social Security Numbers.</p>
<p>The laptop was stolen from an employee at an &#8220;undisclosed location&#8221; off-campus in Albemarle County. Carol Wood, UVa spokeswoman, said that letters have been mailed to those affected by the data breach.</p>
<p>Students have been expressing their <strong>concern and frustration that their personal data would be left on an unsecured laptop </strong>despite the myriad of data breaches caused by such negligence.</p>
<p>The University of Virginia experienced a data breach in June, 2007 that was the result of a hacker accessing 5,735 faculty records over a two-year period. The University claims that the use of Social Security Numbers as a personal identification number was being phased out. Obviously, not soon enough.</p>
<p><strong>Other notable data breaches this week:</strong></p>
<ul>
<li><a href="http://www.suburbanchicagonews.com/heraldnews/news/887530,4_1_JO10_HACK_S1.article">Joliet West High School hacked</a>, breaches data for &#8220;about every student&#8221;</li>
<li><a href="http://www.silive.com/newsflash/index.ssf?/base/news-33/1207944571223200.xml&#038;storylist=simetro">New York-Presbyterian Hospital/Weill Cornell Medical Center finds 40,000 person breach in audit</a>, likely stolen by an employee</li>
</ul>
<p><em>hat tip to <a href="http://www.Attrition.org">Attrition.org</a> </em>; <small>Tags: <a href="http://technorati.com/tag/laptop+theft" rel="tag">laptop theft</a>, <a href="http://technorati.com/tag/laptop+security" rel="tag">laptop security</a>, <a href="http://technorati.com/tag/data+breach" rel="tag">data breach</a>, <a href="http://technorati.com/tag/breach" rel="tag">breach</a>, <a href="http://technorati.com/tag/security+breach" rel="tag">security breach</a>, <a href="http://technorati.com/tag/education+breach" rel="tag">education breach</a>, <a href="http://technorati.com/tag/identity+theft" rel="tag">identity theft</a>, <a href="http://technorati.com/tag/id+theft" rel="tag">id theft</a>, <a href="http://technorati.com/tag/breach+notification" rel="tag">breach notification</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/university-of-virginia-breaches-7000-after-laptop-theft/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>House Identity Theft?</title>
		<link>http://blog.absolute.com/house-identity-theft/</link>
		<comments>http://blog.absolute.com/house-identity-theft/#comments</comments>
		<pubDate>Mon, 31 Mar 2008 16:08:57 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Theft News]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/house-identity-theft/</guid>
		<description><![CDATA[Today&#8217;s oddball piece of security news: house identity theft! What is &#8216;house identity theft&#8217;? The FBI say it&#8217;s the result of combining identity theft with mortgage fraud &#8211; the result of which is house stealing. How the criminals do it:

Pick your house to steal
Assume your identity &#038; create fake IDs
Purchase property tranfer forms from any [...]]]></description>
			<content:encoded><![CDATA[<p><img style="float: right; margin: 5px" height="108" src="http://blog.absolute.com/wp/../uploads/Melodi2_NZ_farmhouse.jpg" width="145" />Today&#8217;s oddball piece of security news: house identity theft! What is &#8216;house identity theft&#8217;? The <a href="http://www.fbi.gov/page2/march08/housestealing_032508.html">FBI</a> say it&#8217;s the result of combining identity theft with mortgage fraud &#8211; the result of which is house stealing. How the criminals do it:</p>
<ol>
<li>Pick your house to steal</li>
<li>Assume your identity &#038; create fake IDs</li>
<li>Purchase property tranfer forms from any office supply store</li>
<li>Forge your signature and use your IDs to sign YOUR house over to THEM</li>
</ol>
<p>Scary, isn&#8217;t it? It&#8217;s that easy.</p>
<p>The FBI say that mortgage fraud is <a href="http://www.fbi.gov/publications/financial/fcs_report2006/financial_crime_2006.htm#Mortgage">growing,</a> and its combination with identity theft could grow as well.</p>
<p>Via <a href="http://www.networkworld.com/community/node/26300">network world</a> Image credit: <a href="http://morguefile.com/archive/?display=157728&#038;">melodi2</a> @ morguefile <small>Tags: <a href="http://technorati.com/tag/identity+theft" rel="tag">identity theft</a>, <a href="http://technorati.com/tag/house+stealing" rel="tag">house stealing</a>, <a href="http://technorati.com/tag/house+identity+theft" rel="tag">house identity theft</a>, <a href="http://technorati.com/tag/fraud" rel="tag">fraud</a>, <a href="http://technorati.com/tag/mortgage+fraud" rel="tag">mortgage fraud</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/house-identity-theft/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
