Home > Security News > Guidance turns investigative tools on itself
Security News:
EMAIL THIS

Guidance turns investigative tools on itself

By Anne Saita, News Director
21 Dec 2005 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Yet another company this week added its name to the litany of firms that sent out data breach notifications in 2005. But this time, the victim was a security vendor that failed to thwart hackers from stealing thousands of customers' credit card data -- including verification codes that should have already been deleted.

"A person compromised one of our servers," Pasadena, Calif.-based Guidance Software Inc. CEO John Colbert told CNET News.com yesterday. The company is best known for its popular EnCase line of digital forensic tools. "The incident…highlights that intrusions can happen to anybody and nobody should be complacent about their security."

Published reports indicate hackers accessed credit card data on 3,800 Guidance customers, comprised primarily of law enforcement personnel and security professionals. Stolen data included names, addresses and card verification codes found on the back of credit cards to prevent fraud. Such codes are supposed to be deleted after each completed transaction, according to Visa and MasterCard merchant guidelines.

The company elected to notify all 9,500 customers and called in the U.S. Secret Service to investigate the attack that occurred in November. It was discovered Dec. 7, and letters were sent to customers the following week.

For more information

Opinion: 'The rise of dataflation'

CardSystems admits stolen data violated policy

Laptops lifted right under corporate noses

The stolen information apparently already is in use. Michael Kessler, president of the New York-based investigative firm Kessler International, reported receiving a $20,000 American Express bill for bogus online advertising charges almost immediately after receiving a notice from Guidance in the mail.

Kessler criticized Guidance for using postal mail, rather than e-mail. Colbert defended the company's communications mode in the press as the quickest means, given the customer e-mail list was incomplete.

Guidance isn't the only firm having a bad week because of a data disclosure. This weekend Chicago-based LaSalle Bank Corp. reported a tape containing confidential data on 2 million residential mortgage customers was lost in shipment by a Texas-bound DHL International carrier. The tape contained Social Security numbers and account information belonging to customers of ABN AMRO Mortgage Group Inc. The company has begun notifying victims.

These latest lapses bring to a total 53.7 million consumers victimized by thieves since February, when Alpharetta, Ga.-based data broker ChoicePoint Inc. was forced to inform 145,000 impacted citizens that conmen had duped employees into turning over their confidential files. The number was revised to 167,000 revised when the company filed its annual SEC report this year.

Among the year's biggest security breaches was Charlotte-based Bank of America Corp. losing an unencrypted backup tape with private information on 1.2 million customers -- many of them government credit card holders. Hackers made off with debit, check and credit card information on 1.3 million customers of shoe store retail chain DSW, headquartered in Dublin, Ohio. And Atlanta-based CardSystems Inc. was forced to admit it was hacked and 40 million credit card transactions it should never have held onto were stolen.

In addition numerous university and hospital systems lost control of their customer and employee data through laptop thefts and network and server hacks, according to the San Diego-based Privacy Rights Clearinghouse Web site.

Tags: Database Security ManagementIdentity Theft and Data Security BreachesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Database Security Management
What is the best database patch management process?
Unpatched vulnerability discovered in Microsoft SQL Server
SQL injection continues to trouble firms, lead to breaches
Oracle issues quarterly patches, fixes database flaws
Database monitoring, encryption vital in tight economy, Forrester says
Oracle to buy Sun Microsystems for $7.4 billion
Oracle issues 43 updates, fixes serious database flaws
Imperva assigns security risk levels to databases
How to create configuration management plans to install DLP
Information security book excerpts and reviews
Database Security Management Research

Identity Theft and Data Security Breaches
Chip and PIN adoption serves lesson for U.S. payment industry
Group to shed light on secure identity management threats
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization
Heartland CIO on PCI, E3 project
Visa probes tokens, encryption for PCI card data protection
University data breach exposes 163,000 women to identity theft
TJX thrives following breach, bucks sour economy
Security expert's PCI analysis misguided, says PCI Council GM
External attacks start with unintentional mistakes, survey finds

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
data encryption/decryption IC  (SearchSecurity.com)
International Data Encryption Algorithm  (SearchSecurity.com)
link encryption  (SearchSecurity.com)
MD2  (SearchSecurity.com)
MD4  (SearchSecurity.com)
MD5  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts