Breach forces payroll service provider PayChoice to shut down again

Article

Breach forces payroll service provider PayChoice to shut down again

SearchSecuirty.com Staff

Payroll service provider PayChoice shut down its online service for the second time in less than a month on Wednesday in response to another data breach by hackers.

Brian Krebs of Tthe Washington Post reported the breach in his SecurityFix column. PayChoice chief executive Robert Digby confirmed the breach in an email reply to Krebs, saying that the site, Online Employer, was briefly taken offline and reopened with limited functions. As of Friday afternoon, the site was displaying the message, "**Attention** Employee Services is temporarily unavailable."

The company notified clients Thursday after some customers noticed phony employees beinig added to their payroll, according to Krebs.

"After investigation, we determined that valid user credentials for an OoOnline eEEmployer user were used in an unauthorized manner to add these fictitious employees in an attempt to have payments made to fraudulent bank accounts," the company wrotesaid in an e-mail alert to their clients sent Thursday."

This appears to be the second stage in an attack on the site, according to Krebs. Last month, hackers broke into PayChoice's servers and stole customer user IDs and passwords. The attackers included that information in emails to customers, tricking them into downloading malware that would steal their usernames and passwords, in the guise of a browser plug-in which was purportedly needed to continue to

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

have access to the site.

The company told clients that the hackers had exploited a weakness in the site's self-service password change function, which has been shut down until the vulnerability is fixed.


Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.