Showing posts with label Bank. Show all posts
Showing posts with label Bank. Show all posts

Tuesday, February 7, 2012

Man in the Browser Attacks Online Banking Customers

Last week you may remember that Symantec notified pcAnywhere customers of the potential for "Man in the Middle" attacks as a result of their leaked source code. This week a malware testing lab out of Britain,  S21sec, is warning online banking users of "Man in the Browser" or MitB threats. 


The idea behind these two threats, despite the different name, is the same. The user downloads malware accidentally and the application lives in their browser and alters what is seen on the site and where the entered data goes. Some more sophisticated versions will change payment details and amounts to try and cover the malicious activity.


Fortunately, many banks use software that understands a user's patterns and when something out of the norm occurs, the bank will alert the account holder of the activity. 


Read more: UPI.com

Wednesday, January 4, 2012

Stratfor Breach

New year, new breach investigation. This time hackers claiming to be a part of the "hacktivist" group Anonymous have breached Austin based research company Strategic Forensics. A spokesperson from Anonymous denies this claim and lays blame on a hacker known as “Sabu,” who is closely associated with the LulzSec group.


Strategic Forensics, commonly known as "Stratfor", lost data for about 4,000 clients including passwords, credit card details, and home addresses. 


The hacker or hackers claim they will use the credit card information to make fraudulent donations to charities. Many experts speculate that they will also make efforts to decrypt the passwords and then use them to try and gain access to other accounts held by Stratfor's considerably high-end clientele. Their clients span many big name organizations including U.S. Military, U.S. State Department, Bank of America, JP Morgan Chase, IBM, and Microsoft employees.


This initial dump of client information is apparently not final blow for Stratfor from Anonymous. The group is planning to release millions of private company emails as well.


For a great article on this breach: Digital Trends -- Stratfor Breach

Tuesday, December 21, 2010

US Bank Accused of Data Breach Cover-Up

Two small business owners find themselves at the center of a class action lawsuit against banking giant US Bank over the accusation of a large scale data breach cover-up. The family-owned online Paintball retailer, Paintball Punks, received 9 orders that were placed using US Bank credit cards. As was standard protocol, the credit card security numbers and billing addresses were verified. Weeks later, US Bank customers began disputing the charges and US Bank recouped their losses by doing "charge backs" where they essentially take back the money that was given to the retailer.


These charge backs cost Paintball Punks over  $11,000, while this amount seems small, the class action law suit was filed due to the unknown scope of the alleged breach. After investigating the claims by US Bank, one owner claims that a US Bank employee divulged that there had been a breach, but it did not go public. The alleged cover-up is in violation of state and federal data breach laws. U.S. Bank maintains that there was no breach and that the claims made in this lawsuit are wholly without merit.

Monday, December 20, 2010

Bank of America Breached: Employees Take Customer Data

According to papers filed last week at the New York Supreme Court, four former Bank of America employees left the organization for another wealth management firm, and brought an unnamed number of customer databases with them.

The employees felt that they were entitled to the information in the databases based on a contact sharing protocol that many banks agree to during job negotiations. Bank of America denies agreeing to this protocol.

Further hearings on this case will take place in January. This case comes as Bank of America is rumored to be preparing for the posting of damaging leaked documents pertaining to the mortgage crisis, by the website WikiLeaks.

Monday, December 6, 2010

WikiLeaks Threatens Release of Unredacted Documents

For WikiLeaks Founder, Julian Assange, the days following the latest release of secret documents have brought legal troubles, sex crime allegations, and death threats. 

In response, Assange has released an encrypted document to tens of thousands of hackers and open-government campaigners that contains all of the documents that WikiLeaks has received to date. Assange's  lawyer has said that if anything happens to Assange, either physically or legally, the encryption key will be released, and all of the documents will be immediately available. Assange refers to the document as his "insurance policy." 


This file is believed to contain US Government papers on the Guantanamo Bay detention camp as well as damaging private-sector documents pertaining to the energy and banking industries. It is believed that two of the targets are industry leaders BP and Bank of America.


Does your organization have processes in place to prevent data loss?
Start your conversations with Attevo now to mitigate your organization's risk and exposure because your industry could be next. Call (216)928-2800 to set up a meeting today!