Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Monday, March 1, 2010

4 charged with hacking into concert ticket sites

Federal prosecutors in New Jersey say four California men made more than $25 million reselling tickets to concerts and sporting events they acquired by hacking into Ticketmaster.com and other Web sites.

Prosecutors say the men fraudulently obtained more than a million tickets. Authorities in Newark charged 40-year-old Kenneth Lowson, 37-year-old Kristofer Kirsch, 36-year-old Faisal Nahdi and 37-year-old Joel Stevenson on Monday.

The indictment charges the men with multiple wire fraud counts and gaining unauthorized access to computer systems. AP

Monday, February 1, 2010

Study: Of All Breaches, Those Caused by Hacking Are the Costliest

The cost of data breaches rose slightly last year, but breaches resulting from computer hacking incurred by far the highest losses, according to a new report from privacy and data-security research firm Ponemon Institute LLC.

The average cost per compromised customer record rose to $204 in 2009 from $202 in 2008 and $138 as recently as 2005, according to Traverse City, Mich.-based Ponemon’s “2009 Annual Study: Cost of a Data Breach.” Some 24% of breaches were caused by placement of so-called malware or botnets or related criminal attacks on computer systems, double the 12% rate for such attacks in 2008. Forty percent of 2009’s breaches resulted from negligence, and 36% come from system glitches, according to the study.

The study, sponsored by Menlo Park, Calif.-based data-protection technology provider PGP Corp., is based on the actual breach experiences of 45 companies in 15 industry sectors. The firms agreed to complete detailed surveys about their breaches, including discovery, response, and effects on their businesses. Respondents included eight financial firms, eight retailers, five services firms, and four technology companies. None was identified specifically. Breaches affected 5,000 to more than 101,000 records. Forty-two percent of the breaches in the 2009 study involved mistakes by outsourcers.

Of the $204 overall loss per record, some $60 came from direct costs to find and fix the breach and resolve problems such as legal matters. Ponemon says direct costs rose in 2009 by $10 because of higher legal expenses. The other $144 consisted of indirect costs, including abnormal customer turnover. Indirect costs declined an estimated 5% in 2009 but breach-related customer churn still accounts for 40% of incident expenses, the report says.

Malicious attacks are the most costly, with resulting expenses of $215 per compromised record, the study says. That’s 39% higher than the $154 per-record breach expenses from negligence. Breaches from system glitches cost an average of $166 per compromised record.

Citing figures from the San Diego-based Identity Theft Resource Center, Ponemon noted that the number of reported breaches fell to 498 in 2009 from 657 in 2008. But the average cost per incident rose to $6.75 million last year from $6.65 million the year before.

Merchant acquirer Heartland Payment Systems Inc., which in January 2009 announced a data breach that a federal prosecutor later said may have compromised 130 million cards, apparently the biggest ever, was not part of the study. But Ponemon Institute chairman and founder Larry Ponemon tells Digital Transactions News by e-mail that, “For merchant processors, or any company … collecting, managing, and securing sensitive consumer information, the number-one lesson is, poor information security comes at a steep price. Given the rising dollar costs and the cost to reputation, we believe that more and more companies will begin to embrace security as a strategic competitive differentiator, which will ultimately make the cost that much greater in terms of lost business for those organizations that fail to address this issue seriously.”  digitaltransactions

Monday, January 11, 2010

Hacking Takes Lead as Top Cause of Data Breaches


Hacking has topped human error as the top cause of reported data breaches for the first time since such tracking began in 2007, according to the Identity Theft Resource Center's 2009 Breach Report.

In its report, titled "Data Breaches: The Insanity Continues," the non-profit ITRC found that 19.5 percent of reported breaches were due to hacking, with insider theft as the second most common cause at 16.9 percent. For the past two years, "data on the move," a typically human-error loss of a portable devices such as laptops or even briefcases, was the most common reported cause.

The ITRC is careful to note that its statistics are based on incomplete data, as differing laws and practices among different states mean that some breaches are not reported publicly, and the cause of the breach is not listed for about one third of those that are reported.

But according to the data available, the number of reported data breaches dropped since 2008, but was still more than in 2007. Last year, there were 498 breaches recorded by the ITRC, with 657 in 2008 and 446 in 2007.

With 41.2 percent of reported breaches, the business sector was the most likely to suffer a breach. But "the financial and medical industries, perhaps due to stringent regulations, maintain the lowest percentage of breaches," according to the report. pcworld

Thursday, December 3, 2009

Cisco, Juniper gear vulnerable to hacking: U.S. govt


BOSTON (Reuters) - The U.S. government has identified flaws in equipment from four companies, including Cisco Systems Inc (CSCO.O), that hackers can exploit to break into corporate computer networks.

The Department of Homeland Security's U.S. Computer Emergency Readiness Team, US-CERT, said on its website on Wednesday that the warning applies to certain networking products from Cisco, Juniper Networks Inc (JNPR.K), SonicWall Inc (SNWL.O) and SafeNet Inc.

The flaw applies to equipment with technology known as SSL VPN that companies use to set up secure communications systems for safely accessing internal computer systems over the Internet.
Reuters