| ||||
About This Vendor Webcast | ||||
The recent breach of Sony’s Playstation Network has left many scratching their heads. Even with all the commentary around the attack, there has been no real conclusion on how the network was infiltrated. View this engaging webcast as Chris Lytle, security researcher for Veracode, as he explores the rumors in the marketplace regarding the PSN breach and examines multiple theories of how the attack happened . | ||||
About the Speaker: Chris Lytle, Security Researcher Chris Lytle is a security researcher at Veracode. He holds a BS in Information Assurance and Security Engineering from DePaul University, where he was a frequent speaker. He spoke at BSides Las Vegas 2010 and BlackHat 2010 on the Collegiate Cyber Defense Competition. He also coordinated the puzzles at SOURCE Boston 2011. Chris enjoys solving puzzles. |
Thursday, September 1, 2011
Sony Breach: Indentifying the Possible Attack Vectors
Wednesday, August 31, 2011
Massachusetts Attorney General says you must practice what you preach
In May 2011, a Belmont employee left an unencrypted backup tape on a desk rather than storing it in a vault for the night, which was then inadvertently thrown away by the evening cleaning crew. Although Belmont had a WISP, which met the new Massachusetts data security standards, Belmont failed to comply with the WISP in practice. Specifically, Belmont failed to encrypt portable devices, such as the backup tape, which contained personal information.
The Attorney General’s settlement with Belmont provides for a civil penalty of $7,500 as well as injunctive relief to mitigate the risk of future data breaches at Belmont. Under the terms of the settlement, Belmont must comply with the provisions of its own WISP, including:
The Attorney General’s settlement with Belmont provides for a civil penalty of $7,500 as well as injunctive relief to mitigate the risk of future data breaches at Belmont. Under the terms of the settlement, Belmont must comply with the provisions of its own WISP, including:
- Ensuring the proper transfer and inventory of backup computer tapes containing personal information;
- Storing backup computer tapes containing personal information in a secure location; and
- Effectively training the members of its workforce on the policies and procedures with respect to maintaining the security of personal information.
Monday, August 22, 2011
Hacking Group Anonymous Breaches InfraGard
On August 18th hacking group Anonymous published documents stolen from Richard Garcia, senior vice president of Vanguard Defense Industries. The collection of documents contains internal meeting notes and contracts, schematics, non-disclosure agreements, personal information about other VDI employees, and several dozen 'counter-terrorism' documents classified as 'law enforcement sensitive' and 'for official use only.'
Mr. Garcia is also a director of U.S. defense contractor InfraGard, who was breached by one of Anonymous' affiliate hacking groups LulzSec. In the initial post by Anonymous, they state that Mr. Garcia's account was easily hacked because he had not changed some of his passwords after the InfraGard breach in June.
One of the most sensitive emails that was published contains a response from one of Vanguard's chief executives responding to a U.S. Department of Justice contact regarding the suitability of its ShadowHawk drones for use by U.S Marshals. There are also reports that there are documents that show evidence of a Merrill Lynch wealth management adviser giving private advance notice to Garcia about upcoming S&P US credit rating downgrades. This report has yet to be substantiated.
Mr. Garcia is also a director of U.S. defense contractor InfraGard, who was breached by one of Anonymous' affiliate hacking groups LulzSec. In the initial post by Anonymous, they state that Mr. Garcia's account was easily hacked because he had not changed some of his passwords after the InfraGard breach in June.
One of the most sensitive emails that was published contains a response from one of Vanguard's chief executives responding to a U.S. Department of Justice contact regarding the suitability of its ShadowHawk drones for use by U.S Marshals. There are also reports that there are documents that show evidence of a Merrill Lynch wealth management adviser giving private advance notice to Garcia about upcoming S&P US credit rating downgrades. This report has yet to be substantiated.
Labels:
Attevo,
Data Breach,
Data Loss Prevention,
DLP,
Encryption,
Hacked,
Legal,
Security,
Theft
Wednesday, June 22, 2011
Mansfield, Ohio -- Area Agency on Aging: Breached due to Lost Laptop
On June 3, an employee of the Area Agency of Agency in Mansfield, Ohio had a laptop stolen from their car. This resulted in the exposure of personal data related to 43,000 customers. The laptop was assigned to a Passport case manager. The personal data was health related in nature and also contained the personal contact information of 35,000 related clients' personal representatives.
According to a report in The Morning Journal the Area Agency on Aging had the following response to the Breach:
Unfortunately many organizations take a reactive approach to encrypting endpoint devices such as laptops and cell phones that may contain sensitive information.
Oil giant BP, had a similar incident this spring in which an employee lost their laptop during routine business travel. The laptop contained unencrypted personal data such as names, social security numbers, and dates of birth for over 13,000 people who submitted claims with the company after last years oil spill.
According to Ponemon's "Cost of a Lost Laptop" report, a lost or stolen, unencrypted laptop, will cost an organization $20,000 more than if an encrypted laptop is lost or stolen. Read the full Ponemon report here: Cost of a Lost Laptop Study - Ponemon
According to a report in The Morning Journal the Area Agency on Aging had the following response to the Breach:
“The Area Agency on Aging understands the importance of safeguarding our consumer’s personal information and takes that responsibility very seriously,” said Duana Patton, chief executive officer. “We deeply regret that this incident occurred, and we have already taken steps to ensure our laptops are properly equipped to secure personal information from unauthorized access in the future.”
Unfortunately many organizations take a reactive approach to encrypting endpoint devices such as laptops and cell phones that may contain sensitive information.
Oil giant BP, had a similar incident this spring in which an employee lost their laptop during routine business travel. The laptop contained unencrypted personal data such as names, social security numbers, and dates of birth for over 13,000 people who submitted claims with the company after last years oil spill.
According to Ponemon's "Cost of a Lost Laptop" report, a lost or stolen, unencrypted laptop, will cost an organization $20,000 more than if an encrypted laptop is lost or stolen. Read the full Ponemon report here: Cost of a Lost Laptop Study - Ponemon
77% Of Business Experienced Data Loss Last Year
A survey of over 2,400 IT security administrators conducted by Check Point and Ponemon reveals 77% of businesses experienced data loss last year. This number does not correlate with the number of reported breaches, but with increasing stringency of compliance regulations, we may begin to see more and more reported breaches.
The study’s research shows organizations are struggling with the growing set of security priorities and limited employee awareness about corporate security policies. Over 55 percent of companies surveyed are using more than seven vendors to perform security tasks. Because of this, organizations struggle with minimizing TCO and maximizing performance.
Approaching security with a holistic view of an organization’s technology is the first step in enforcing better protection. This helps to determine where risks can reside. Security is more than a simple technology solution. Aligning IT security with business needs requires a combination of policies, people and enforcement.
Monday, June 6, 2011
Sony Share Price in Tokyo Tumble
Sony's recent breach has affected the personal data of up to 100 million users. As one of the largest data breaches to date, Sony estimates that it will result in a $170 million hit to its operating profit.
The financial affects do not stop there. Brand "pain" or the financial losses experienced by loss of consumer confidence will likely be much greater than the $170 million hit on operational profits. The breach has already sent shares down more than 2% in Tokyo. Sony is not the only company to experience a drop in stock prices after a major data breach. The figure below is a sampling of other companies who experienced a similar drop.
The cost of a data breach will be detrimental to your organization. Develop a plan to protect your data to decrease the likelihood of a breach.
The financial affects do not stop there. Brand "pain" or the financial losses experienced by loss of consumer confidence will likely be much greater than the $170 million hit on operational profits. The breach has already sent shares down more than 2% in Tokyo. Sony is not the only company to experience a drop in stock prices after a major data breach. The figure below is a sampling of other companies who experienced a similar drop.
The cost of a data breach will be detrimental to your organization. Develop a plan to protect your data to decrease the likelihood of a breach.
Monday, May 23, 2011
Massachusetts Executive Office of Labor and Workforce Development Breached
Client names, social security numbers, email addresses and residential addresses and bank account detail of users of the Massachusetts Executive Office of Labor and Workforce Development claim system. The 1,200 system users were warned that their personal details may have been accessed by a data-stealing worm named W32.QAKBOT.
Symantec defined the W32.QAKBOT as a worm that is capable of keylogging, collecting cookie data, DNS, operating system, private keys from system certificates and URLs. The virus can spread through a computer network, open a back door on a compromised computer that would allow someone to control the machine and keep itself hidden.
Although the problem has been fixed, Executive Office of Labor and Workforce Development is hoping people continue to use the system. It has been communicated that all possible steps are being taken to avoid future recurrence.
Symantec defined the W32.QAKBOT as a worm that is capable of keylogging, collecting cookie data, DNS, operating system, private keys from system certificates and URLs. The virus can spread through a computer network, open a back door on a compromised computer that would allow someone to control the machine and keep itself hidden.
Although the problem has been fixed, Executive Office of Labor and Workforce Development is hoping people continue to use the system. It has been communicated that all possible steps are being taken to avoid future recurrence.
Subscribe to:
Posts (Atom)