In 2009, the Identity Theft Resource Center Breach Report recorded 498 breaches, less than the 657 in 2008, more than the 446 in 2007. Are data breaches increasing or decreasing? That is the question no one can answer. This fact will not change until there is a single data breach list requiring mandatory public reporting. With some breaches not being reported publicly, and some state Attorneys General not allowing public access to reported breaches, we doubt that anyone is in a position to answer the question above. When we allow laws to be created requiring breach reporting but not disclosure, and provide minimal enforcement or penalty for non-compliance, we can expect a lack of public disclosure. Counting breaches becomes an exercise in insanity.
ITRC collects information about data breaches made public via reliable media and notification lists from various governmental agencies. There are breaches that occurred in 2009 that never made public news. So rather than focus on a question without an answer, ITRC used percentages to analyze the 498 breaches recorded this year looking for any changes or new trends. (Both raw numbers and percentages have been provided in all charts).
The main highlights are:
paper breaches account for nearly 26% of known breaches (an increase of 46% over 2008)
business sector climbed from 21% to 41% between 2006 to 2009, the worst sector performance by far
malicious attacks have surpassed human error for the first time in three years
Out of 498 breaches, only six reported that they had either encryption or other strong security features protecting the exposed data
In 2009, the business sector increased to 41% of all the publicly reported breaches. While there are some small statistical changes in the other sectors, business continues to increase for the fifth year in a row. The financial and medical industries, perhaps due to stringent regulations, maintain the lowest percentage of breaches.
The ITRC Breach Report recorded more than 222 million potentially compromised records in 2009. Of those, 200 million are attributed to two very large breaches. Before obsessing with record count, however, one should be aware that in more than 52% of the breaches publicly reported, NO statement of the number of records exposed is given. Therefore, it is unknown how many total records may have been exposed due to breaches in 2009.
The ITRC Breach Report also monitors how breaches occur. This task is made more difficult by the scarcity of information provided (publicly) for approximately 1/3 of the recorded breaches. For the remainder, those events that do state how the breach occurred, malicious attacks (Hacking + Insider Theft) have taken the lead (36.4%) over human error (Data on the Move + Accidental Exposure = 27.5%) in 2009. This was a change from all previous years, where human error was higher than malicious attacks. One theory for this change is that the organization and sophistication of crime rings has impacted the theft of information. For example, while the Heartland breach was only a single breach, it demonstrated how skilled technology-based thieves can access 130 million records from over 600 different entities.
Insanity might well be defined as repeating the same action again and again, and expecting a different outcome. With that in mind:
Insanity 1 - Electronic breaches: After all the articles about hacking, and the ever growing cost of a breach, why isn’t encryption being used to protect personal identifying information? Proprietary information almost always seems to be well protected. Why not our customer/consumer personal identifying information (PII)?
Insanity 2 - Paper breaches: Why aren’t more state legislators passing laws about rendering paper documents unreadable prior to disposal if they contain PII? Do we dare ask that those laws be actually enforceable? Perhaps we are waiting for paper breaches to reach 35% of the total.
Insanity 3 - Breaches happen: Deal with it! You will get notification letters. Breach notification does not equal identity theft. Let’s stop the “blame game” and instead require breached entities to report breach incidents via a single public website. This would allow analysts (and law enforcement) to look for trends and link crimes to a single ring or hacker faster.
Insanity 4 - A Breach is a Breach: Let’s not kid ourselves. “Risk of harm” is not a useful standard for determining if the public and consumers should be notified about a breach, especially if the company involved gets to define “risk of harm.” If it is your #$@%2 SSN that is out on the Internet, do YOU think there is “risk of harm?” Some companies might say “no.”
Insanity 5 - Data on the Move: You will notice that statistically this is a bright spot, with a decreasing incidence in the past 3 years. But, really! This is 100% avoidable, either through use of encryption, or other safety measures. Laptops, portable storage devices and briefcases full of files, outside of the workplace, are still “breaches waiting to happen.” With tiered permissions, truncation, redaction and other recording tools, PII can be left where it belongs – behind encrypted walls at the workplace. idtheftcenter
Tuesday, January 12, 2010
Hackers take aim at Facebook users
Kimberly Potts calls Facebook her "lifeline" to her son Justin, who is serving in Iraq with the 101st Engineer Battalion of the Army National Guard. It's helped her stay in contact with him, to see photos of his Thanksgiving dinner and Christmas.
But late last month it also served as a gateway to scammers, who attempted to steal access to credit cards and bank accounts from the Potts family and many of Justin's friends. Justin's Facebook page had been hacked by criminals.
In West Newbury, friends of Pentucket High School senior Matt McCarthy, who died suddenly during a hockey practice, did what thousands of people do — they set up a Facebook page to honor their friend's memory. Within days it had been savaged by posters from other parts of the country who posted swastikas, racial epithets and vicious comments. The page, which had been open to all, was quickly shut off from the public and the hurtful posts were stripped.
With more than 200 million users, Facebook has become a wildly popular forum for people to find old friends, learn about their personal information and keep in touch. But it's also been heavily mined by scammers and used for bullying and taunting.
Users like Kimberly Potts and investigators like Newburyport Police Inspector Brian Brunault say people should be cautious.
"Everything is dark on the Internet," Brunault said, noting he's investigating a case of a Newburyporter whose Facebook account was hacked and identity was stolen. Facebook is inundated with complaints and subpoenas from those who have had problems on the site, he said.
"It takes virtually weeks if not months to get returns on these things," Brunault said. "There is harassment on there, cyber bullying, people post as other people to start trouble and then the thread gets connected and more people jump on board." eagletribune
But late last month it also served as a gateway to scammers, who attempted to steal access to credit cards and bank accounts from the Potts family and many of Justin's friends. Justin's Facebook page had been hacked by criminals.
In West Newbury, friends of Pentucket High School senior Matt McCarthy, who died suddenly during a hockey practice, did what thousands of people do — they set up a Facebook page to honor their friend's memory. Within days it had been savaged by posters from other parts of the country who posted swastikas, racial epithets and vicious comments. The page, which had been open to all, was quickly shut off from the public and the hurtful posts were stripped.
With more than 200 million users, Facebook has become a wildly popular forum for people to find old friends, learn about their personal information and keep in touch. But it's also been heavily mined by scammers and used for bullying and taunting.
Users like Kimberly Potts and investigators like Newburyport Police Inspector Brian Brunault say people should be cautious.
"Everything is dark on the Internet," Brunault said, noting he's investigating a case of a Newburyporter whose Facebook account was hacked and identity was stolen. Facebook is inundated with complaints and subpoenas from those who have had problems on the site, he said.
"It takes virtually weeks if not months to get returns on these things," Brunault said. "There is harassment on there, cyber bullying, people post as other people to start trouble and then the thread gets connected and more people jump on board." eagletribune
Monday, January 11, 2010
Red Flags Compliance: 3 Common Deficiencies - Jeff Kopchik, FDIC
It's been over a year now since banking regulators began examining institutions for compliance with the Identity Theft Red Flags Rule. What have been the common deficiencies, and what will examiners be expected in year two?
Kopchik was the Team Leader of the FDIC's 2004 study "Putting an End to Account-Hijacking Identity Theft." He was the FDIC's primary representative on the FFIEC staff working group that drafted the 2005 guidance on Authentication in an Internet Banking Environment. Kopchik was also involved in interagency rulemaking efforts to comply with the Fair and Accurate Credit Transactions (FACT) Act, and was involved in the creation and implementation of the Gramm-Leach-Bliley Act (GLBA) interagency information security guidelines, supervisory guidance on customer notice, FFIEC Business Continuity Planning Booklet, and FDIC guidance on wireless networks. Read interview.
Kopchik was the Team Leader of the FDIC's 2004 study "Putting an End to Account-Hijacking Identity Theft." He was the FDIC's primary representative on the FFIEC staff working group that drafted the 2005 guidance on Authentication in an Internet Banking Environment. Kopchik was also involved in interagency rulemaking efforts to comply with the Fair and Accurate Credit Transactions (FACT) Act, and was involved in the creation and implementation of the Gramm-Leach-Bliley Act (GLBA) interagency information security guidelines, supervisory guidance on customer notice, FFIEC Business Continuity Planning Booklet, and FDIC guidance on wireless networks. Read interview.
Keeping a Step Ahead of the Virtual Enemy
Asked what worries him the most about safeguarding government IT systems, Philip Reitinger demurs. "It's not a question of what worries me most; it is a question of the opportunities we have got," Deputy Undersecretary Reitinger, the top cybersecurity official at the Department of Homeland Security, said in an interview with GovInfoSecurity.com (transcript below).
"We are connecting more and more systems, creating an increasingly complicated environment," Reitinger said. "The attackers are getting better and better and we are depending more on those systems from day to day to make sure that our very way of life can continue, that the ways we work and play will continue and we will be able to be successful."
Reitinger maintains the government's cyber defenses are getting better. "We need to continue to improve because the hackers and the bad guys have continued to improve and there are a lot of areas for improvement, but we are making significant efforts to do so," he said.
In the first of a two-part interview, Reitinger concedes the challenge will be tough because of a dearth of qualified information security experts, but explains steps the government is taking to eventually eliminate that skills gap. Also, Reitinger addresses:
•The need to develop innovative, collaborative approaches, not only among federal agencies, but between the government and the private sector to meet the human resources needs to safeguard government systems.
•How much risk the government faces by not having a sufficient number of cybersecurity professionals.
•Why, even when the government didn't have a permanent cybersecurity coordinator, the White House addressed the government's information security needs. govinfosecurity
"We are connecting more and more systems, creating an increasingly complicated environment," Reitinger said. "The attackers are getting better and better and we are depending more on those systems from day to day to make sure that our very way of life can continue, that the ways we work and play will continue and we will be able to be successful."
Reitinger maintains the government's cyber defenses are getting better. "We need to continue to improve because the hackers and the bad guys have continued to improve and there are a lot of areas for improvement, but we are making significant efforts to do so," he said.
In the first of a two-part interview, Reitinger concedes the challenge will be tough because of a dearth of qualified information security experts, but explains steps the government is taking to eventually eliminate that skills gap. Also, Reitinger addresses:
•The need to develop innovative, collaborative approaches, not only among federal agencies, but between the government and the private sector to meet the human resources needs to safeguard government systems.
•How much risk the government faces by not having a sufficient number of cybersecurity professionals.
•Why, even when the government didn't have a permanent cybersecurity coordinator, the White House addressed the government's information security needs. govinfosecurity
Judge Approves Settlement Of Data-Breach Claims Vs Countrywide
A U.S. District Court judge in Kentucky on Wednesday gave preliminary approval to a settlement between Countrywide Financial Corp. and millions of customers whose financial data was exposed in a security breach, the Associated Press reports Thursday. The settlement calls for Countrywide, now owned by Bank of America Corp. (BAC), to give as many as 17 million victims of the breach free credit monitoring--includng anyone who obtained a mortgage and anyone who used Countrywide to service a mortgage before July 1, 2008. A consumer would be allowed up to $50,000 in reimbursements from Countrywide for each instance of identity theft. A "fairness hearing" in the case is scheduled for July in Louisville, Ky.
A Bank of America spokeswoman said the settlement is "in the bank's best interest" to avoid additional legal expenses. WSJ
A Bank of America spokeswoman said the settlement is "in the bank's best interest" to avoid additional legal expenses. WSJ
E-mail passwords easy prey for hackers
There's not much authorities can do to prevent hackers from determining computer users' e-mail passwords, U.S. experts say.
Hacker services, usually based overseas, openly advertise that for as little as $100, they can find out what someone's e-mail password is and provide it to buyers, who can then use it to monitor the private communications of estranged spouses, family members or whomever they choose, the Washington Post reported Monday.
Orin Kerr, a law professor at George Washington University and a former trial attorney in the Justice Department's computer crime section, told the Post that while U.S. law prohibits hacking into e-mail, it's only a misdemeanor without further criminal activity. And as such, it is a low priority item for the FBI. US News
Hacker services, usually based overseas, openly advertise that for as little as $100, they can find out what someone's e-mail password is and provide it to buyers, who can then use it to monitor the private communications of estranged spouses, family members or whomever they choose, the Washington Post reported Monday.
Orin Kerr, a law professor at George Washington University and a former trial attorney in the Justice Department's computer crime section, told the Post that while U.S. law prohibits hacking into e-mail, it's only a misdemeanor without further criminal activity. And as such, it is a low priority item for the FBI. US News
Personal data susceptible to hackers
Hackers are to blame for most thefts of credit card numbers, medical records and other information of a million Massachusetts residents, The Boston Globe said.
The newspaper, citing state documents, said all the breaches happened in the past two years.
"Many thousands" of them had been reported from June to November and included confidential information from major institutions such as Blue Cross Blue Shield of Massachusetts and JPMorgan Chase Bank, the Globe said
Some of the information ended up in the wrong hands because of the theft of a laptop computer or loss of computer data tape. But most breaches can be traced to hacker breaking into computer networks, the Globe said.
Businesses and other institutions must develop a "culture of security" to protect the sensitive documents they control, said Barbara Anthony, undersecretary of consumer affairs and business regulation.
All such institutions are required to inform customers and state regulators about any breaches in security that might cause identity theft. Breaches include the leak of names, and numbers for Social Security, driver's license, bank account, and credit or debit cards, the newspaper reported.
"In 60 percent of the cases, the breaches were due to criminal acts. Forty percent were negligence," said Anthony of 807 breach notifications received by the state by November. US News
The newspaper, citing state documents, said all the breaches happened in the past two years.
"Many thousands" of them had been reported from June to November and included confidential information from major institutions such as Blue Cross Blue Shield of Massachusetts and JPMorgan Chase Bank, the Globe said
Some of the information ended up in the wrong hands because of the theft of a laptop computer or loss of computer data tape. But most breaches can be traced to hacker breaking into computer networks, the Globe said.
Businesses and other institutions must develop a "culture of security" to protect the sensitive documents they control, said Barbara Anthony, undersecretary of consumer affairs and business regulation.
All such institutions are required to inform customers and state regulators about any breaches in security that might cause identity theft. Breaches include the leak of names, and numbers for Social Security, driver's license, bank account, and credit or debit cards, the newspaper reported.
"In 60 percent of the cases, the breaches were due to criminal acts. Forty percent were negligence," said Anthony of 807 breach notifications received by the state by November. US News
Subscribe to:
Posts (Atom)




.jpg)


