Google Search

Showing posts with label system. Show all posts
Showing posts with label system. Show all posts

Monday, June 9, 2014

Storage system for 'big data' dramatically speeds access to information

As computers enter ever more areas of our daily lives, the amount of data they produce has grown enormously. But for this "big data" to be useful it must first be analyzed, meaning it needs to be stored in such a way that it can be accessed quickly when required.

Previously, any data that needed to be accessed in a hurry would be stored in a computer's main memory, or dynamic random access memory (DRAM) -- but the size of the datasets now being produced makes this impossible.

So instead, information tends to be stored on multiple hard disks on a number of machines across an Ethernet network. However, this storage architecture considerably increases the time it takes to access the information, according to Sang-Woo Jun, a graduate student in the Computer Science and Artificial Intelligence Laboratory (CSAIL) at MIT.

"Storing data over a network is slow because there is a significant additional time delay in managing data access across multiple machines in both software and hardware," Jun says. "And if the data does not fit in DRAM, you have to go to secondary storage -- hard disks, possibly connected over a network -- which is very slow indeed."

Now Jun, fellow CSAIL graduate student Ming Liu, and Arvind, the Charles W. and Jennifer C. Johnson Professor of Electrical Engineering and Computer Science, have developed a storage system for big-data analytics that can dramatically speed up the time it takes to access information.

The system, which will be presented in February at the International Symposium on Field-Programmable Gate Arrays in Monterey, Calif., is based on a network of flash storage devices.

Flash storage systems perform better at tasks that involve finding random pieces of information from within a large dataset than other technologies. They can typically be randomly accessed in microseconds. This compares to the data "seek time" of hard disks, which is typically four to 12 milliseconds when accessing data from unpredictable locations on demand.

Flash systems also are nonvolatile, meaning they do not lose any of the information they hold if the computer is switched off.

In the storage system, known as BlueDBM -- or Blue Database Machine -- each flash device is connected to a field-programmable gate array (FPGA) chip to create an individual node. The FPGAs are used not only to control the flash device, but are also capable of performing processing operations on the data itself, Jun says.

"This means we can do some processing close to where the data is [being stored], so we don't always have to move all of the data to the machine to work on it," he says.

What's more, FPGA chips can be linked together using a high-performance serial network, which has a very low latency, or time delay, meaning information from any of the nodes can be accessed within a few nanoseconds. "So if we connect all of our machines using this network, it means any node can access data from any other node with very little performance degradation, [and] it will feel as if the remote data were sitting here locally," Jun says.

Using multiple nodes allows the team to get the same bandwidth and performance from their storage network as far more expensive machines, he adds.

The team has already built a four-node prototype network. However, this was built using 5-year-old parts, and as a result is quite slow.

So they are now building a much faster 16-node prototype network, in which each node will operate at 3 gigabytes per second. The network will have a capacity of 16 to 32 terabytes.

Using the new hardware, Liu is also building a database system designed for use in big-data analytics. The system will use the FPGA chips to perform computation on the data as it is accessed by the host computer, to speed up the process of analyzing the information, Liu says.

"If we're fast enough, if we add the right number of nodes to give us enough bandwidth, we can analyze high-volume scientific data at around 30 frames per second, allowing us to answer user queries at very low latencies, making the system seem real-time," he says. "That would give us an interactive database."

As an example of the type of information the system could be used on, the team has been working with data from a simulation of the universe generated by researchers at the University of Washington. The simulation contains data on all the particles in the universe, across different points in time.

"Scientists need to query this rather enormous dataset to track which particles are interacting with which other particles, but running those kind of queries is time-consuming," Jun says. "We hope to provide a real-time interface that scientists can use to look at the information more easily."


View the original article here

Sunday, October 27, 2013

Students under arrest after hacking into computer system to change grades

Friday 3:45 p.m. – Update

Court records outline details of three students accused of changing grades in an elaborate case. 

With a total of 58 charges between the three students, Roy Sun received 13 counts of charges, Mitsutoshi Shirasaki received 20 and Sujay Sharma received 13. 

The charges were a combination of Class C and D felonies and Class A misdemeanors.

It is alleged that Shirasaki's girlfriend Xiaonan Jing, an undergraduate in the College of Science, may have been involved in the case. Jing's grades were also changed as one of her classes, a Japanese class from Fall 2012, from an A to an A+, by Shirasaki, according to court records. 

The students are of accused breaking into a number of classrooms and computer labs from October 2009 to March 2013, but they also purchased locks from Wal-Mart and practiced picking them.

Court documents indicate, the students took turns practicing picking locks, standing as lookouts, breaking into the computer labs, placing keyloggers into keyboards and cutting wires in keyboards. They then are accused of accessing keystroke information from the keyboards and use this to enter professors' login information into computer systems. 

In March of 2013, Sun and Shirasaki exchanged telephone calls expressing the possibility of the police tracing the crimes back to them and the need to get rid of evidence, which is believed they did around Tippecanoe County. Sun was also concerned the Sharma had too much information and "coudn't keep his mouth shut." 

Sun graduated in 2010 with a Bachelor's of Science in Electrical Engineering and is currently at Boston University as a graduate student.  

A number of professors were involved in the grade changes from several colleges in the University: Liberal Arts, Engineering and Science. 

--

Three students have been involved in hacking into a professor’s computer and changing the grades they had received, which has resulted in two arrests and a lengthy investigation.

Two current engineering students, Sujay Sharma and Mitsutoshi Shirasaki, have been arrested by the Purdue University Police Department (PUPD) on a lengthy list of charges from burglary, to computer tampering, to forgery. Former student, Roy Sun, is also involved in the case. Sun is now a graduate student at Boston University. He is currently in his home country of Japan and his future has yet to be determined.

The case arose in January when a Purdue professor alerted Information Technology at Purdue (ITaP) that his University account password had been changed, along with the security question he had set. This is when he also noticed that grades had been changed from previous semesters.

The three students somehow switched the keyboards in an ITaP computer lab that a professor used received information from there to change the grades. The exact methods the student used to hack into the system and change the grades is still under investigation.

Grade changes were as subtle as A to A+ and as drastic as D’s to A’s, yet the motives behind these actions are unclear.

John Cox, police chief for PUPD, said the police have been working with ITaP, the FBI, Boston University Police Department and the case prosecutor Pat Harrington to investigate the situation since January. Cox said that this case was the first of this magnitude.

“This was no outside attack,” Cox said. “This was (done by) some students who were very smart and used their knowledge and wisdom to do something they shouldn’t have.”

Cox said there has been an internal audit to check for “anomalies” to make sure this was an isolated event over the last few years.

“There are thousands of grade changes every year in the system,” Cox said. “To see there were 30-something grades that were changed that’s unfortunate, you don’t want one grade changed like that ... It was the biggest case like that, that we’ve ever seen so far.”

Sharma and Shirasaki are no longer enrolled at Purdue and their grades have been changed back to reflect what each student had originally received. They also face local and state charges for the grade changes.

According to Jeff Stefancic, associate dean for the Office of Rights and Responsibilities, the University is still looking at Roy’s status as he is no longer a Purdue student.

“We can examine a student’s graduation status and potentially revoke a degree that was granted if the situation warrants it. That’s currently under our administrative review right now,” Stefancic said.

Cox said that ITaP is working to increase security and make it more challenging to get into the system, but that work is done every day by ITaP, not in response to this case.

“It gets a little tougher when you start having things like iPads and laptops floating around out there ... working wirelessly. We’ve done an awful lot with ITaP and ITaP has done a really nice job of working with that,” Cox said.


View the original article here

Friday, September 27, 2013

Cyber security in US power system suffering from reactive, self-policed rules

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Power failureNorth America’s electricity generation and distribution network is a vital piece of infrastructure, and is rightly considered a major potential target for attack from terrorists, activists or corporate snoops.

Its cyber defences seem to be inadequate though, with regulation mainly self-imposed and minimally enforced. Policy in the area also appears to focus on reacting to emerging threats, rather than setting up proactive barriers against potential problems.

A major report on the subject has been produced by the offices of two US Congressmen, Ed Markey (D-Mass.) and Henry A. Waxman (D-Calif.). They found that most power companies were under heavy cyber attack, but that few had done more than the minimum to implement protective processes.

A run-down of the report’s major findings can be found at The Register – there are plenty of juicy, scary stats based on responses to a survey sent to over 150 organisations.

The main point the study’s authors are trying to make is that there are many rules in place for how networks and systems should be protected, some mandatory and some optional, and not everyone’s applying all the mandatory steps yet, let alone the optional ones.

The rules are laid out by a non-profit body called NERC, the North American Electric Reliability Corporation. This is a cross-industry group focussed on keeping America’s lights on, generating standards and best practices for electricity generation and infrastructure. They’re overseen by FERC, the Federal Energy Regulatory Commission.

To create a new rule for the power companies to follow, a NERC committee (of which there seem to be many) will draft a guideline, which must then be approved by the membership – which is the power companies. If approved, the guideline is then passed to FERC for further approval before becoming an enforceable standard.

Obviously, this is a slow process, with any rule which is thought likely to cause difficulties to the people it’s supposed to be imposed upon likely to be vetoed, by those very same people.

The complexities of the system, and the highly distributed nature of the US power infrastructure, make it hard to monitor and enforce compliance, even when guidelines do become rules.

NERC publicationNERC produce some epic documents – their full run-down of standards makes for an eye-watering 1800-page read.

The (relatively) juicy bit concerning cyber security is section CIP-007, about a quarter of the way down.

Just keeping up with the latest tweaks and additions must be a tough task, let alone trying to apply or enforce them.

Even if the standard creation process can be sped up and made more enforceable, as the report’s authors are urgently suggesting, there’s another problem here.

The emphasis seems to be heavily on responding to threats – how did people respond to 9/11, what have people done in the wake of Stuxnet, what was their reaction to Aurora.

They need to be thinking much more proactively, predicting new attack vectors and implementing protection against new vulnerabilities before they are discovered, let alone put to use by the bad guys.

At least some people at NERC are thinking along the right lines, with another detailed report, released last year by their Cyber Attack Task Force, emphasising the importance of attack trees and other predictive approaches.

What seems to be needed here is a combination of the two vectors, with carefully considered generally defensive strategies combined with fast responses to new, unforeseen vulnerabilities. Sadly when government and big business intersect, pragmatism and speedy reactions are rarely in evidence.

Follow @virusbtn
Follow @NakedSecurity

Image of Power failure cartoon courtesy of Shutterstock.


View the original article here

Sunday, May 26, 2013

High-rolling gambler uses casino's own surveillance system to scoop $32 million...

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A high-rolling gambler has allegedly won $32 million at a casino in Melbourne, Australia, thanks to a little network hackery carried out by accomplices.

Games like poker are much easier to win if you know some or all of your opponents' cards.

After all, it's hard to sustain a bluff if the person you're bluffing has actually seen your hand.

In this case, the un-named "whale" - casino argot for a player who wagers large amounts of money, often on giant-sized individual bets - is said to have relied on his accomplices to feed him information about what other players at his table were holding.

His accomplices were able to snoop on the other players because they had remote access to the casino's own surveillance system, giving them a bird's eye view from CCTV cameras right inside the high-rollers' room.

The $32 million was apparently scooped in the course of eight big-stakes hands.

To increase their chance of catching cheaters (and thereby, no doubt, to discourage gamblers from trying to cheat in the first place), casinos typically have substantial networks of cameras giving high-quality, real-time video feeds.

So, this is an excellent reminder that the modern trend towards "big data" - where you hoover up as much information as possible, in as much detail as you can manage, about as many of your customers as you can - cuts both ways.

"Big data" can not only help to uncover patterns that expose fraud and criminality, but also end up enabling it.

(Why would you needs a miniature camera cunningly mounted on an ATM to skim PINs from unsuspecting users, if you could just hack into a shopping mall's CCTV system and let someone else's camera do the work?)

By the way, do you have video surveillance in your workplace?

If so, how well do you protect your own CCTV network, which may very well include proprietary software and equipment, from prying eyes?

It's not just your employees' privacy that's at stake, but possibly also (as the Melbourne casino found out) the financial health of your business...

Follow @duckblog


View the original article here

Friday, May 10, 2013

Jailed cybercriminal hacked into his own prison's computer system after being put in IT class

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Here's a piece of advice for those running classes training prisoners about information technology.

It's probably not a good idea to let notorious hackers join the course - or, if you do, to keep a very close eye on what they're up to.

Teenager Nicholas Webber ran the infamous GhostMarket.Net cybercrime website, which sold stolen credit card details and offered tutorials to budding criminals about how to commit identity theft and online scams.

Nicholas Webber

With 8,500 members, GhostMarket was the biggest criminal website ever uncovered by the British authorities.

It's said that GhostMarket's activities can be linked to frauds around the world which saw £8 million stolen from 65,000 bank accounts.

Media reports have detailed the playboy lifestyle enjoyed by Nicholas Webber, GhostMarket's founder, who had only just turned 18 at the time of his arrest in October 2009.

Webber was sentenced to five years imprisonment in May 2011, and found himself at HM Prison Isis, a Category C male Young Offenders Institution, in South East London.

Cells at HM Prison Isis

Normally you would expect (and hope) a hacker's criminal career to end there, but sadly that wasn't to be.

As the Daily Mail reports, Webber somehow managed to sign-up for the prison's IT class, and from there managed to hack into the prison's mainframe computer.

According to the report, a spokesman for the prison service has confirmed that Webber was involved in the hack, but has downplayed the significance of the hack:

"At the time of this incident in 2011 the educational computer system at HMP Isis was a closed network. No access to personal information or wider access to the internet or other prison systems would have been possible."

The story of the 2011 prison hack has only come to light now because Michael Fox, the IT class's teacher, is claiming unfair dismissal. Fox says that it was not his decision to admit Webber to the class, and that he was not aware of Webber's history of cybercrime.

Earlier this year, an official report claimed that HM Prison Isis was "bedevilled" by technological problems, including a breakdown in its biometric thumbprint security system.

Let's hope that they didn't ask Webber to help them fix that...

Follow @gcluley

View the original article here

Wednesday, January 4, 2012

Hackers work on satellite system, aim for the moon - ZDNet UK (blog)

Hackers have announced work on a ground station scheme that would make amateur satellites more viable, as part of an aerospace scheme that ultimately aims for the moon.

The Hackerspace Global Grid (HGG) project hopes to make it possible for amateurs to more accurately track the home-brewed satellites. As these devices tend to be launched by balloon, they are not placed at a precise point in orbit as professional satellites deployed by rocket usually are.

Armin Bauer, one of the three German hobbyists involved in the HGG, said at the Chaos Communication Congress in Berlin that the system involved a reversal of the standard GPS technique. The scheme was announced at the event, which is Europe's largest hacker conference.

"GPS uses satellites to calculate where we are, and this tells us where the satellites are," Bauer said on Friday, according to the BBC. "We would use GPS co-ordinates but also improve on them by using fixed sites in precisely-known locations."

According to the HGG website, enthusiasts would site the ground stations using coordinates not only from the US's GPS system, but also those from the EU's Galileo, Russia's GLONASS and ground surveys.

A major aim of the wider 'Hacker Space Program' is to create a satellite system for internet communication that is uncensorable by any country. The hackers also want to put someone on the moon by 2034 — something that has not been done since the Apollo 17 mission 39 years ago.

Bauer described the moon mission as "very ambitious". As for the anti-censorship aspects of the scheme, the HGG team said on their site that they are "not yet in a technical position to discuss details".

They also noted that the modular ground stations, which are intended to work out at a non-profit sales price of €100 (£84) each, would be able to work without the internet.

"Then you will have to deploy four receiver stations and connect them to your laptop(s) or collect all storage media added to them, where all received data is stored on," the team wrote. "Then you have to manage the data handling and processing by your own."

However, internet connectivity is the plan for most of the HGG's usage. The team is working on the project alongside Constellation, an German aerospace research platform for academics that would use the distributed network to derive crucial data.

According to Bauer and his colleagues, the internet connectivity would be of "bare minimum" bandwidth that would be enough to keep basic communications going if needed.

"The first step is establishing a means of accurate synchronisation for the distributed network," the team explained. "Next up are building various receiver modules (ADS-B, amateur satellites, etc) and data processing of received signals. A communication/control channel (read: sending data) is a future possibility but there are no fixed plans on how this could be implemented yet."

The HGG team hopes to have working prototypes in the first half of the year, with production units ready for distribution by the end of 2012. These would be sold, but people would be able to build their own as well.

If the Hacker Space Program really does take off, the satellites would be out of any country's legal jurisdiction, but this would also leave any country that is capable of doing so free to disable them in some way.

The HGG team admitted on their site that there would nothing they could do to stop this happening.

"Since we don't have actual satellites yet, this falls in the category of problems we're going to solve once they occur," they wrote. "We're doing this because we want to and because it's fun. We're trying to concentrate on reasons why this will work, not why it won't."


View the original article here

Monday, November 21, 2011

Foreign hackers attack Springfield water plant system

Foreign hackers broke into a water plant control system in Springfield last week and damaged a water pump in what may be the first reported case of a malicious cyber attack on a critical computer system in the United States, according to an industry expert.

On Nov. 8, a municipal water district employee noticed problems with the Curran-Gardener Township Public Water District's water pump control system, and a technician determined the system had been remotely hacked into from a computer located in Russia, said Joe Weiss, an industry security expert who obtained a copy of an Illinois state fusion center report describing the incident.

Problems with the system had been observed for two to three months and recently the system “would power on and off, resulting in the burnout of a water pump,” the Nov. 10 report from the U.S. Department of Homeland Security, according to Weiss, who read the report to The Washington Post.

“This is a big deal,” said Weiss. The report stated it is unknown how many other systems might be affected.

According to the report, hackers apparently broke into a software company's database and retrieved user names and passwords of various control systems that run water plant computer equipment. Using that data, they were able to hack into the plant in Illinois, Weiss said.

It's not the first time that two-step technique — hack a security firm to gain the keys to enter other companies or entities — has been used.

Earlier this year, hackers believed to be working from China stole sensitive data from RSA, a division of EMC that provides secure remote computer access to government agencies, defense contractors and other commercial companies around the world. Armed with that data, they breached the computer networks of companies, including Lockheed Martin, whose employees used RSA “tokens” to log in to the corporate system from outside the office. Lockheed said that no sensitive data were taken.

“RSA is the gold standard” for remote access security in industry, said Gen. Keith Alexander, head of U.S. Cyber Command and director of the National Security Agency, at a conference in Omaha this week. “If they got hacked, where does that leave the rest?”

Alexander noted his concern about “destructive” attacks on critical systems in the United States.

The Department of Homeland Security, whose job is to oversee the protection of critical infrastructure such as water utility computer systems in the United States, said that DHS and the FBI are investigating the Illinois incident. “At this time there is no credible corroborated data that indicates a risk to critical infrastructure entities or a threat to public safety,” DHS spokesman Peter Boogaard said in an emailed statement.

According to the fusion center report obtained by Weiss, the network intrusion of the software company “is the same method of attack recently used against a Massachusetts Institute of Technology server” used to “aid and initiate an attack on other websites.”

For Weiss, though, the incident has significance. “It was tracked to Russia. It has been in the system for at least two to three months. It has caused damage. We don't know how many other utilities are currently compromised.”

Senior U.S. officials, including Alexander, have recently raised warnings about the risk of cyber attacks on critical infrastructure. Questions persist about the readiness and capabilities of DHS to respond to a major attack, and the scope of authority of the U.S. military, which has the greatest cyber operational capabilities, to respond.


View the original article here

Tuesday, August 23, 2011

Bay Area transit system sets meeting about cutting off cell service - CNN

BART suspended cell service in spots July 11 to thwart demonstratorsThe move elicited harsh criticism from civil liberty advocates and othersThe transit system calls the move necessary to ensure public safetyBART's board plans to meet on Wednesday to discuss the matter

(CNN) -- Board members of San Francisco's rapid transit system will convene a special meeting next week to discuss the controversial decision this month to cut off cell service in selected stations.

The August 11 move by the Bay Area Rapid Transit System (BART), in an apparent attempt to head off protests against its police officers, drew sharp condemnation from free speech advocates and spurred hackers to launch attacks on the system's website and internal network.

In a letter to passengers sent Saturday and signed by the board's president, Bob Franklin, and interim general manager Sherwood Wakeman, BART defended the decision in claiming it was done "out of an overriding concern for our passengers' safety."

The letter referenced a July 11 protest, in which people railed against the system after several shootings involving its police officers -- the latest coming last month and resulting in the death of 45-year-old Charles Hill.

That spirited and largely peaceful rally at the city's Civic Center stop was organized by a group called "No Justice, No BART," which formed after the 2009 shooting of an unarmed passenger by a BART police officer.

But at the demonstration, video shows one person climbing atop a subway train, before being pulled down. BART also noted in its letter that the protesters blocked doors and generally delayed roughly two-thirds of trains running during the rush-hour commute.

"These actions violated the law by creating a serious threat to the safe operation of the BART system," wrote the agency.

BART police department members learned of another planned protest about a month later, deciding to suspend cell phone service for three hours at select locations in hopes of preventing demonstrators from organizing.

That decision elicited criticism from civil liberty organizations, the San Francisco Chronicle's editorial page and others.

"All over the world people are using mobile devices to organize protests against repressive regimes, and we rightly criticize governments that respond by shutting down cell service, calling their actions anti-democratic and a violation of the rights to free expression and assembly," Rebecca Farmer from the ACLU's northern California office wrote on the advocacy group's website. "Are we really willing to tolerate the same silencing of protest here in the United States?"

Online messages attributed to Anonymous took credit for the apparent hacking last Sunday of myBART.org, a link off BART's website that showed a page featuring, among other items, the hacking group's logo -- a smirking mask above two crossed swords, all on a black background.

In addition, Twitter traffic related to Anonymous boasted that hackers had been able to get into BART's internal network.

"By (cutting cell service), you have not only threatened your citizens' safety, you have also performed an act of censorship," a seemingly computer-generated voice -- speaking over dramatic music and images -- said in a video posted online Sunday afternoon. "By doing this, you have angered Anonymous."

The Federal Communications Commission is collecting information on the matter, with agency spokesman Neil Grace saying Monday by e-mail that "any time communications services are interrupted, we seek to assess the situation."

"We ... will be taking steps to hear from stakeholders about the important issues those actions raised, including protecting public safety and ensuring the availability of communications networks," Grace said.

BART closed, then reopened stations to thwart demonstrators when they gathered again Monday but -- while its officials did not rule out the possibility before -- there was no indication that the suspended cell service again.

In its letter Saturday, BART spoke to First Amendment concerns, stating it recognized people's right to protest "where it can be done safely and without interference with BART's primary mission of providing safe, efficient and reliable public transportation service."

But the letter insisted that suspending cell phone service "did not affect any First Amendment rights of any person to protest in a lawful manner in areas at BART stations that are open for expressive activity. The interruption did prevent the planned coordination of illegal activity on the BART platforms, and the resulting threat to public safety."

The special board meeting to discuss the matter will occur Wednesday, the letter stated.


View the original article here

Thursday, June 23, 2011

Hackers break into computer system at Conor O'Neills Irish pub in Ann Arbor ... - Detroit Free Press

Ann Arbor police say hackers broke into the computer system of a popular Irish restaurant, stealing numerous credit card and debit card numbers to make purchases.

The case came to light after the credit and debit cards were fraudulently used in the state of Texas between April 22 and June 10, police said.

Local banks traced the fraud back to Conor O?Neills Restaurant at 318 S. Main St. in Ann Arbor, and management there contacted police.

?The banks were receiving information about these fraudulent transactions and did a little digging and discovered the common point of purchase between the cases was Conor O?Neills,? Ann Arbor Police Det. Sgt. Pat Hughes said.

According to police, the restaurants? credit card processing computer was vulnerable to computer hackers, possibly from Europe, allowing them to infiltrate the system and gain access to all of the credit/debit card numbers that had been used at the business.

Police say it?s not yet known how many customers? credit and debit cards were accessed. Because the charges have taken place in other states, Ann Arbor police don?t know the total number of fraudulent credit card purchases involved, Hughes said.

Hughes said police have tracked some of the fraud to Europe and Texas and are working with authorities in other jurisdictions on the case. But, he said, these types of cases are typically complex and difficult to solve.

According to police, Conor O?Neill?s has taken the necessary measures to protect and ensure the security of its customers? credit and debit card account numbers from any future hacking attempts.

Among the numbers stolen were credit and debit cards issued by the Bank of Ann Arbor and the University of Michigan Credit Union, police said.

Ann Arbor police say the investigation is continuing.

Hughes said people should be vigilant in checking their monthly credit card statements for suspicious charges. If they discover any charges they didn?t make, they should contact the bank or credit card company, he said.


View the original article here