Showing posts with label UK. Show all posts
Showing posts with label UK. Show all posts

Tuesday, February 7, 2012

Man in the Browser Attacks Online Banking Customers

Last week you may remember that Symantec notified pcAnywhere customers of the potential for "Man in the Middle" attacks as a result of their leaked source code. This week a malware testing lab out of Britain,  S21sec, is warning online banking users of "Man in the Browser" or MitB threats. 


The idea behind these two threats, despite the different name, is the same. The user downloads malware accidentally and the application lives in their browser and alters what is seen on the site and where the entered data goes. Some more sophisticated versions will change payment details and amounts to try and cover the malicious activity.


Fortunately, many banks use software that understands a user's patterns and when something out of the norm occurs, the bank will alert the account holder of the activity. 


Read more: UPI.com

Wednesday, December 1, 2010

Fines Imposed by UK’s Information Commissioner’s Office

Two organizations, Action for Employment Ltd. (A4e) and Hertfordshire County Council, were recently fined by the UK’s Information Commissioner’s office (ICO) for data breaches that occurred in June.  Information Commissioner, Christopher Graham, said "these first monetary penalties send a strong message to all organizations handling personal information. Get it wrong and you do substantial harm to individuals and the reputation of your business. You could also be fined up to half a million pounds."

A4e was fined £60,000 for the theft of an unencrypted laptop.  The laptop was owned by A4e and stolen from an employee’s home. The laptop contained personal records of approximately 24,000 employees.  Although a policy stating all data temporarily stored on a laptop computer should be encrypted existed, the stolen laptop was not because it was not a part of a recent encryption rollout. 

Hertfordshire County Council was fined £100,000 after confidential documents were faxed to the wrong recipients on two separate occasions. The ICO believed that they should have taken a stronger action after the first accidental fax, but they failed to do so.

Does your organization have policies and procedures in place to protect your data in the event of a theft? Are you able to prevent accidentally faxing a confidential document? Contact Attevo about a risk assessment.


Tuesday, November 23, 2010

Security Software Vendor, Omniquad, Exposes Customer Details on the Web

On October 4, 2010, it was brought to the attention of the managing director of Omniquad that a helpdesk call system had posted sensitive information about their customers to the internet.  Omniquad, an anti-spyware company, was quick to place blame on the third-party vendor of the exploited software. A spokesperson from Privacy International expressed the feelings of disappointment that many share, "Security and privacy should be at the core of everything they [Omniquad] do and that includes carrying out security audits of all third-party software and services they offer."

This breach brings to light the fact that relying on the security measures of partners or third-party vendors is not enough. Carefully assessing risks to your organization does not stop at the front door.