Sony's recent breach has affected the personal data of up to 100 million users. As one of the largest data breaches to date, Sony estimates that it will result in a $170 million hit to its operating profit.
The financial affects do not stop there. Brand "pain" or the financial losses experienced by loss of consumer confidence will likely be much greater than the $170 million hit on operational profits. The breach has already sent shares down more than 2% in Tokyo. Sony is not the only company to experience a drop in stock prices after a major data breach. The figure below is a sampling of other companies who experienced a similar drop.
The cost of a data breach will be detrimental to your organization. Develop a plan to protect your data to decrease the likelihood of a breach.
Monday, June 6, 2011
Monday, May 23, 2011
Massachusetts Executive Office of Labor and Workforce Development Breached
Client names, social security numbers, email addresses and residential addresses and bank account detail of users of the Massachusetts Executive Office of Labor and Workforce Development claim system. The 1,200 system users were warned that their personal details may have been accessed by a data-stealing worm named W32.QAKBOT.
Symantec defined the W32.QAKBOT as a worm that is capable of keylogging, collecting cookie data, DNS, operating system, private keys from system certificates and URLs. The virus can spread through a computer network, open a back door on a compromised computer that would allow someone to control the machine and keep itself hidden.
Although the problem has been fixed, Executive Office of Labor and Workforce Development is hoping people continue to use the system. It has been communicated that all possible steps are being taken to avoid future recurrence.
Symantec defined the W32.QAKBOT as a worm that is capable of keylogging, collecting cookie data, DNS, operating system, private keys from system certificates and URLs. The virus can spread through a computer network, open a back door on a compromised computer that would allow someone to control the machine and keep itself hidden.
Although the problem has been fixed, Executive Office of Labor and Workforce Development is hoping people continue to use the system. It has been communicated that all possible steps are being taken to avoid future recurrence.
Monday, May 9, 2011
Sony CEO Apologizes for Data Breach
Last week, Sony announced that 24.6 million names, addresses, e-mails, birth dates, phone numbers, potentially credit cards and other private information from Sony Online Entertainment accounts could have been taken from company servers or from an old database.
Last month, a hacker attack on the PlayStation Network may have caused the stealing of data from 77 million user accounts.
This totals over 100 million accounts that were potentially compromised. Each potentially affected customer will get $1 million in identity theft insurance.
Sony CEO, Howard Stringer, apologized for “inconvenience” and “concern” the data breach has caused. The company is working on restoring full and safe service as soon as possible. Stringer has a lot of brand mending to do as this breach is being referred to as one of the largest Internet security break-ins in history.
Labels:
3rd Party Security,
Attevo,
Breach Cost,
Compliance,
Credit Card,
Data Breach,
Data Loss Prevention,
DLP,
Hacked,
malware,
Personally Identifiable Information,
PHI,
PII,
Security,
Social networking
Thursday, May 5, 2011
Epsilon Breach Estimated to Cost $4B
The highly publicized data breach of email service provider Epsilon could cost the organization upwards of four billion dollars. This estimate comes from a report done by cyber risk advisory firm CyberFactors, and is dependent on what is done with the data.
According to CSO.com
"That figure [$4 billion] could be reached if criminals get hold of the email addresses and successfully exploit them to gather more personal information and carry out a spear-phishing blitz, according to the report. 'However, until such an event takes place and can be directly linked back to this specific breach, the estimate remains theoretical, but certainly possible given the multitude of sites that use email addresses as user IDs,' the report says."
The report goes on further to estimate that the Costs to Epsilon's customers could be $5.5 million each for notification of their customers about the theft, settlements to those customers, legal defense, compliance adjustments and loss of business.
In contrast to this report CEO of Alliance Data Systems, Epsilon's parent company, Ed Heffernan says he sees no meaningful cost or liability stemming from the incident and that they will not see the customer churn that often follows a breach.
Although Heffernan believes he will not see significant costs as a result of the breach, the widely known act could hold weighty impacts to Epsilon and even Alliance Data’s brand. If Epsilon is lucky, the company has the potential to escape any non-compliance fines, but this does not mean they will be free of detrimental brand impact. Brand losses are approximately 49% of the cost of a data breach and Heffernan may not be taking this into account when he states that the cost will not be meaningful.
If you were a company who needed third party email services, would you want to do business with a company that had more than a million customer records at risk? Probably not. A tactical data loss prevention strategy may have saved this company, and those customers affected by the breach the trouble this breach has presented.
Labels:
3rd Party Security,
Attevo,
Breach Cost,
Compliance,
Credit Card,
Data Breach,
Data Loss Prevention,
DLP,
Employee Misuse,
Encryption,
Hacked,
malware,
Personally Identifiable Information,
PII,
Security
Wednesday, April 20, 2011
2011 Verizon Data Breach Investigations Report
Verizon recently released their Data Breach Investigations Report. The report covers approximately 800 data breach cases from 2010. The review of breaches covers threat agents and actions, how breaches typically occur, and provides statistics on breached organizations.
Below you will find a summary of organizations who have reported breaches in the past year by size. It may be surprising to find that organizations with 11 to 100 employees have reported 436 breaches.
Below you will find a summary of organizations who have reported breaches in the past year by size. It may be surprising to find that organizations with 11 to 100 employees have reported 436 breaches.
1 to 10
|
46
|
11 to 100
|
436
|
101 to 1,000
|
74
|
1,001 to 10,000
|
49
|
10,001 to 100,000
|
59
|
Over 100,000
|
55
|
Unknown
|
40
|
This may not be surprising to you, but the report concludes that 97 percent of the breaches could have been avoided by using simple controls. Do you have the simple controls in place to protect your organization's data? According to the study, organizations should focus mitigation efforts in the following areas:
Monday, April 4, 2011
Marketing Firm's Customer Data Exposed by Hackers
One of the country's largest e-mail marketing firms, Epsilon, reported that on March 30th, “a subset of Epsilon clients’ customer data [was] exposed by an unauthorized entry into Epsilon’s email system."
Epsilon is a subsidiary of Alliance Data Systems and sends over 40 billion emails annually for their clients. These clients include 7 of the top Fortune 10 companies.
Companies whose clients may have been affected by this breach include:
Brookstone
Capital One Financial Corp.
Citigroup
J.P. Morgan Chase & Co.
Kroger Co.
Marriott International Inc.
McKinsey & Co.
New York & Co.
Ritz-Carlton
TiVo Inc.
US Bancorp
Walgreen Co.
The hackers were only able to access names and email addresses, and it is still unknown if the information has been used in any email based attacks aimed at obtaining credit card or social security numbers.
This attack reminds us to be vigilant and skeptical of all unsolicited emails or emails from unknown senders. Keep in mind the following tips next time you check your email:
- Under no circumstances should anyone respond to an email from an unknown or known party that asks for sensitive personal data.
- If you receive an email from an unknown sender, delete it and mark it as spam in your email client. If you receive an email asking for personal or financial information from an organization that you are a customer of, notify their customer service office immediately.
- Also, do not click on links in email or pop-up messages that may come up after clicking a link in an email that asks for your personal or financial information.
- Always use anti-spyware software and a firewall to protect your computer.
- Never open or download attachments from an email from an unknown sender.
Wednesday, March 30, 2011
Lost Laptop Exposes 13,000 Oil Spill Victims
According to a BP spokesman the laptop was lost on March 1 by an employee on routine business travel.
The laptop held unencrypted information including the names, Social Security numbers, addresses, phone numbers, and dates of birth of people who filed claims related to the Deepwater Horizon accident that occurred last spring.
"The lost laptop was immediately reported to law enforcement authorities and BP security, but has not been located despite a thorough search," BP said Tuesday. They added that the device was equipped with a tool that would allow them to disable the system under certain circumstances. No further details on the nature of the circumstances that would be required to be met were given.
Unfortunately lost laptops containing sensitive personal data are lost every day, and even more commonly when traveling. In Ponemon's "Billion Dollar Lost Laptop Study" the institution found that of laptops lost 46% contained confidential data, and only 30% of those laptops were encrypted, as shown below. Encryption is not the only method used to protect confidential data on a laptop, but it is one of the most easily implemented and trusted ways to protect your company's and customer's sensitive data.
The laptop held unencrypted information including the names, Social Security numbers, addresses, phone numbers, and dates of birth of people who filed claims related to the Deepwater Horizon accident that occurred last spring.
"The lost laptop was immediately reported to law enforcement authorities and BP security, but has not been located despite a thorough search," BP said Tuesday. They added that the device was equipped with a tool that would allow them to disable the system under certain circumstances. No further details on the nature of the circumstances that would be required to be met were given.
Unfortunately lost laptops containing sensitive personal data are lost every day, and even more commonly when traveling. In Ponemon's "Billion Dollar Lost Laptop Study" the institution found that of laptops lost 46% contained confidential data, and only 30% of those laptops were encrypted, as shown below. Encryption is not the only method used to protect confidential data on a laptop, but it is one of the most easily implemented and trusted ways to protect your company's and customer's sensitive data.
Subscribe to:
Posts (Atom)