Google Search

Showing posts with label 800000. Show all posts
Showing posts with label 800000. Show all posts

Wednesday, September 25, 2013

Cybercrooks siphon $800,000 from US fuel distribution firm

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Cybercriminal image from ShutterstockThieves drained $800,000 from a fuel distribution company in the US state of North Carolina earlier this month - a loss that the company thinks might have something to do with its bank having recently upgraded its security system.

According to security journalist Brian Krebs, the loss could have been a lot less if the bank or the targeted company - Mooresville, N.C. based J.T. Alexander & Son Inc. - had noticed the penetration earlier.

As it is, the attackers drained money for five days before a reporter notified either business of what was going on. Krebs didn't identify the reporter.

On the morning of May 1, the cyber thieves started carving out sub-$5,000 and sub $10,000 chunks of cash from J.T. Alexander's bank, Peoples Bancorp of North Carolina Inc.

They then sent the money via automated clearing house (ACH) payment to about a dozen money mules who laundered the stolen funds.

On top of the funds stolen from the bank, the ACH payments themselves were deducted from J.T. Alexander's payroll account, Krebs writes.

David Alexander, J.T. Alexander & Son’s president, told Krebs that the loss was “pretty substantial” and “painful” for the small company, which employs a staff of only 15.

The company typically spends less than $30,000 on its total payroll every two weeks. In five days, the crooks managed to steal more than a year's worth of salaries.

While J.T. Alexander & Son may be able to get some financial relief for cyber fraud losses from its insurer - Employer’s Mutual Casualty Company (EMC) - it will be far less than what the company lost, according to what EMC adjuster Jim Mitchell told Krebs:

"They’ve got some specific coverage, but unfortunately the amount of coverage they’ve got is not going to cover anywhere near the amount of money they lost."

According to the victimized company, its bank upgraded its security system a mere month before the theft.

Prior to the upgrade, J.T. Alexander & Son's controller was required to enter a login ID, password, and a six-digit code to be read by an automated system at the bank. That automated system would then call the company.

Kristie Williams, who works in accounting and finance for J.T. Alexander, told Krebs that the security change - of which she wasn't aware - entailed transforming what was once a single-IP-controlled process into something a whole lot more promiscuous:

"... It used to be we could only access the bank’s site from my computer. … The way [the bank] changed it, anybody anywhere could access it as long as they had my login, and apparently that’s what happened because the logins came from a different IP address than our normal one. I think they made it more convenient, but less secure. I wasn’t aware all of that had changed.”

The bank didn't return Krebs's calls requesting comment.

At first blush, it looks like both the bank and the business might share the blame for the loss, but as Brian notes, it's the victim who tends to bear the liability.

Krebs includes a link to a set of online banking best practices for businesses that should help to protect businesses from being victimized in this manner.

Source BostonLast year, I attended a great talk at Source: Boston about cyber liability insurance, given by Jake Kouns, director of cyber security and technology risks underwriting at insurer Markel Corp.

I was lucky enough to get him in front of a camera so as to glean some tips on buying such policies. Here's a link to the video.

There's a lot to know about these insurance policies, but here's a good first lesson: a general liability policy won't cover your organization.

The costs can be devastating, as J.T. Alexander & Son is now experiencing.

Hopefully, your business won't suffer the same fate. But in case it does, be prepared.

Now is the time to learn about the ins and outs of insurance, not after your business gets drained and your insurer tells you that you really don't have much in the way of coverage.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Wednesday, July 4, 2012

Spokeo "people search" site has until next week to cough up $800,000

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Imagine you're trying to find a long lost friend.

Or someone you haven't seen for ages but whom you know will be a soft touch to lend you money.

Or the bloke who used to live next door until he suddenly moved interstate with your prized collection of 1960s Beatles vinyl.

Instead of spending hours using every search engine you could think of, and trawling through dozens of who-knows-how-accurate links and false trails, what if there were a sort of meta-search-engine which would do all the trawling for you and summarise the results?

Better yet, what if it did the trawling anyway, for everyone out there, and accumulated social profiles on them just in case you ever decided to go looking for them in the future?

That is the promise of Pasadena-based social aggregator site Spokeo, which, like Google, was created by classmates at the prestigious Stanford University. They started the site so they could "better keep up with their friends online", but it has become a search engine about anyone and everyone on a vast scale:

Spokeo is the most popular free people search engine in the United States. Spokeo aggregates and organizes vast quantities of people-related information from a large variety of public online and offline sources. The public data is amassed with lightning speed, and presented almost instantly in an integrated, coherent, and easy-to-follow format. With Spokeo's revolutionary people finder, you can locate virtually any one of the 300 million people living in the United States within seconds.

It sounds creepy, but on the positive side, Spokeo only collects data which is already publicly available. (Some people may be surprised to hear this, but pronouncements made on Twitter, and status updates published on Facebook aren't exactly private declarations.)

In fact, sites like Spokeo may be useful for helping you to see just what information about you is lying around online already.

On the negative side, however, Spokeo got into hot water with the US FTC (Federal Trade Commission) back in 2010.

A search engine business isn't much use if you can't monetise it, and Spokeo went to market by offering paid subscribers features such as "Credit Estimates" and "Wealth Level" ratings. This didn't sit well with everyone.

The Center for Democracy and Technology (CDT) in Washington DC, for example, filed a detailed FTC complaint against Spokeo in July 2010.

The CDT alleged that Spokeo was acting as a credit reporting agency without subjecting itself to the controls of the Fair Credit Reporting Act.

Spokeo, claimed the CDT, was guilty of "unfair and deceptive practices", knowingly selling inaccurate data to its paid subscribers:

In general, the data provided in [Spokeo's] consumer profiles is unreliable. An informal review of profiles associated with CDT employees revealed significant inaccuracies in every single profile. Similarly, Dori Marlin, a consumer protection reporter for the CBS affiliate in Albany, New York conducted a similar review of people in her office and also found serious errors in the majority of profiles. Numerous other writers have detailed similar problems in Spokeo’s database.

Two years on, and the FTC has come down on the CDT's side, concluding that Spokeo's marketing of consumer profiles to companies in the human resources, background screening, and recruiting industries did not comply with the Fair Credit Reporting Act.

As a result, the FTC has now obtained an order requiring Spokeo, amongst other things, to cough up a civil penalty of US$800,000 by next week.

As the FTC notes, "This is the first Commission case to address the sale of Internet and social media data in the employment screening context."

Sadly, though, I rather doubt it will be the last.

Follow @duckblog
-

Images of Spokey the Hedgehog mascot from the Spokeo blog.


View the original article here