Monday, May 9, 2011

Sony CEO Apologizes for Data Breach

Last week, Sony announced that 24.6 million names, addresses, e-mails, birth dates, phone numbers, potentially credit cards and other private information from Sony Online Entertainment accounts could have been taken from company servers or from an old database.

Last month,  a hacker attack on the PlayStation Network may have caused the stealing of data from 77 million user accounts.

This totals over 100 million accounts that were potentially compromised.  Each potentially affected customer will get $1 million in identity theft insurance. 

Sony CEO, Howard Stringer, apologized for “inconvenience” and “concern” the data breach has caused. The company is working on restoring full and safe service as soon as possible. Stringer has a lot of brand mending to do as this breach is being referred to as one of the largest Internet security break-ins in history. 

Thursday, May 5, 2011

Epsilon Breach Estimated to Cost $4B


The highly publicized data breach of email service provider Epsilon could cost the organization upwards of four billion dollars. This estimate comes from a report done by cyber risk advisory firm CyberFactors, and is dependent on what is done with the data.
               
According to CSO.com
"That figure [$4 billion] could be reached if criminals get hold of the email addresses and successfully exploit them to gather more personal information and carry out a spear-phishing blitz, according to the report. 'However, until such an event takes place and can be directly linked back to this specific breach, the estimate remains theoretical, but certainly possible given the multitude of sites that use email addresses as user IDs,' the report says."
The report goes on further to estimate that the Costs to Epsilon's customers could be $5.5 million each for notification of their customers about the theft, settlements to those customers, legal defense, compliance adjustments and loss of business.

In contrast to this report CEO of Alliance Data Systems, Epsilon's parent company, Ed Heffernan says he sees no meaningful cost or liability stemming from the incident and that they will not see the customer churn that often follows a breach. 

Although Heffernan believes he will not see significant costs as a result of the breach, the widely known act could hold weighty impacts to Epsilon and even Alliance Data’s brand. If Epsilon is lucky, the company has the potential to escape any non-compliance fines, but this does not mean they will be free of detrimental brand impact. Brand losses are approximately 49% of the cost of a data breach and Heffernan may not be taking this into account when he states that the cost will not be meaningful.

If you were a company who needed third party email services, would you want to do business with a company that had more than a million customer records at risk? Probably not.  A tactical data loss prevention strategy may have saved this company, and those customers affected by the breach the trouble this breach has presented.

Wednesday, April 20, 2011

2011 Verizon Data Breach Investigations Report

Verizon recently released their Data Breach Investigations Report.  The report covers approximately 800 data breach cases from 2010.  The review of breaches covers threat agents and actions, how breaches typically occur, and provides statistics on breached organizations.

Below you will find a summary of organizations who have reported breaches in the past year by size. It may be surprising to find that organizations with 11 to 100 employees have reported 436 breaches.



1 to 10
46
11 to 100
436
101 to 1,000
74
1,001 to 10,000
49
10,001 to 100,000
59
Over 100,000
55
Unknown
40


This may not be surprising to you, but the report concludes that 97 percent of the breaches could have been avoided by using simple controls. Do you have the simple controls in place to protect your organization's data? According to the study, organizations should focus mitigation efforts in the following areas:


Monday, April 4, 2011

Marketing Firm's Customer Data Exposed by Hackers


One of the country's largest e-mail marketing firms, Epsilon, reported that on March 30th, “a subset of Epsilon clients’ customer data [was] exposed by an unauthorized entry into Epsilon’s email system."


Epsilon is a subsidiary of Alliance Data Systems and sends over 40 billion emails annually for their clients. These clients include 7 of the top Fortune 10 companies.

Companies whose clients may have been affected by this breach include:
Brookstone
Capital One Financial Corp.
Citigroup 
J.P. Morgan Chase & Co.
Kroger Co.
Marriott International Inc. 
McKinsey & Co.
New York & Co.
Ritz-Carlton
TiVo Inc.
US Bancorp
Walgreen Co.

The hackers were only able to access names and email addresses, and it is still unknown if the information has been used in any email based attacks aimed at obtaining credit card or social security numbers.

This attack reminds us to be vigilant and skeptical of all unsolicited emails or emails from unknown senders. Keep in mind the following tips next time you check your email:
  1. Under no circumstances should anyone respond to an email from an unknown or known party that asks for sensitive personal data. 
  2. If you receive an email from an unknown sender, delete it and mark it as spam in your email client. If you receive an email asking for personal or financial information from an organization that you are a customer of, notify their customer service office immediately.
  3. Also, do not click on links in email or pop-up messages that may come up after clicking a link in an email that asks for your personal or financial information. 
  4. Always use anti-spyware software and a firewall to protect your computer.
  5. Never open or download attachments from an email from an unknown sender.



Wednesday, March 30, 2011

Lost Laptop Exposes 13,000 Oil Spill Victims

According to a BP spokesman the laptop was lost on March 1 by an employee on routine business travel.


The laptop held unencrypted information including the names, Social Security numbers, addresses, phone numbers, and dates of birth of people who filed claims related to the Deepwater Horizon accident that occurred last spring.


"The lost laptop was immediately reported to law enforcement authorities and BP security, but has not been located despite a thorough search," BP said Tuesday. They added that the device was equipped with a tool that would allow them to disable the system under certain circumstances. No further details on the nature of the circumstances that would be required to be met were given.


Unfortunately lost laptops containing sensitive personal data are lost every day, and even more commonly when traveling. In Ponemon's "Billion Dollar Lost Laptop Study" the institution found that of laptops lost 46% contained confidential data, and only 30% of those laptops were encrypted, as shown below. Encryption is not the only method used to protect confidential data on a laptop, but it is one of the most easily implemented and trusted ways to protect your company's and customer's sensitive data.




Friday, March 11, 2011

Cost of Data Breaches Rising – Average Cost $7.2 Million

According to the Ponemon Institute, the average cost of a data breach in 2010 was $7.2 million. This number continues to rise each year. The Ponemon Institute also states that the cost per record breached in 2010 was $214. This cost is up 5% from 2009.


Negligence is main cause of a data breach and accounts for 41% of reported breaches. Close behind are malicious or criminal acts which are the reason for 31% of breaches. These malicious or criminal attacks are the most expensive breaches for an organization to respond to and cost an average of $318 per record. While some industries experience higher breach costs than others, these figures represent the averages.

To calculate the potential cost of a breach for your organization, log on to Attevo’s DLP Toolkit and use our free Risk Calculator. This tool will provide you with an estimated cost per record and a total remediation cost estimate.  

Friday, March 4, 2011

Do you consider your ZIP code "personal identification information" ?

The California Supreme Court does.  In a recent decision, the California Supreme Court ruled that a ZIP code is "personal identification information" for purposes of California Civil Code §1747.08. As a provision of the Song-Beverly Credit Card act of 1971, California Civil Code §1747.08 prohibits prohibits businesses, as a condition to accepting a credit card as payment for goods or services, from requesting and recording personal identification from credit card holders during credit card transactions. Personal identification is further defined in the statute as:
"information concerning the cardholder, other than information set forth on the credit card, and including, but not limited to, the cardholder’s address and telephone number."
The lawsuit was filed by a private citizen against retailer Williams-Sonoma after a ZIP code was requested at checkout and was later used in conjunction with other information to determine the customer's address for marketing purposes.

This decision comes as a further reminder to credit card processing retailers of the increasing complexity of credit card compliance. With the new Payment Card Industry Data Security Standards (PCI-DSS) and decisions such as this one, non-compliance is becoming more costly than ever. 

Does your organization process credit cards? Would your business be hurt by losing the ability to process credit cards? If you answered yes it is time to discover your compliance requirements and start working towards meeting the standards put in place by credit card companies and the courts. A great place to start is Attevo's DLP Toolkit where you can search a database of compliance regulations tailored to your business.