Google Search

Showing posts with label theft. Show all posts
Showing posts with label theft. Show all posts

Wednesday, July 10, 2013

McCann Investigations Houston Computer Forensics Division Releases White Paper on Digital Intellectual Property Theft

McCann Investigations releases white paper which explores the complexities of digital intellectual property theft and methods by which a business can protect its data.

Houston, TX (PRWEB) April 11, 2013

McCann Investigations, a Texas-based computer forensics firm released a white paper titled Digital Intellectual Property Theft: Protecting your Organization. This paper explores the complexities of digital intellectual property. The sophistication of cyber assaults has increased at alarming rate allowing hackers to steal intellectual property from individuals and small companies, to large companies with a significant global presence.

In many cases, intellectual property theft occurs during a data breach which can often come from external sources such as hackers. But many times, intellectual property theft occurs when present for former employees (sometimes in collusion with one another) download or export proprietary company information such as engineering drawings, client lists or trade secrets. This is often done when those employees are seeking to create a competing company. In many intellectual property theft cases facilitated by employees, there is a component of non compete violations. Many companies have solid non compete agreements in place to prevent intellectual property theft and infringement issues.

“Intellectual property theft has become a big business for foreign countries looking to gain an edge in the global market.” Says Daniel Weiss, Managing Partner of McCann Investigations. “Smaller companies are more at risk given that they often do not have the resources as a larger company to secure their networks against such attacks.” Continued Weiss

McCann Investigations Houston Division specializes in several case types including fraud, embezzlement, theft, non compete enforcement, digital debugging, data breach incident response and complex family, civil and criminal.

About McCann Investigations

McCann Investigations is a Texas-based private investigations practice focused on comprehensive investigations incorporating digital forensics, surveillance, undercover work and backgrounds for clients in various case types. Case types include intellectual property theft, non compete enforcement, fraud, embezzlement and family law. McCann Investigators are experts in the latest computer forensics tools and are licensed with the state of Texas. McCann computer forensics examiners have provided expert testimony and reporting in hundreds of cases across the state.

Through digital investigations, McCann also delivers digital debugging and data breach and incident response services.    In cases where there is suspected external or internal hacking with the installation of malware of spyware or when data and privacy loss has occurred due to network breach, McCann investigations computer forensics and IT security experts use cutting-edge tools to document, evaluate and respond to the incident. McCann works with clients to analyze their IT networks and put protocols in place to secure the network.

McCann Investigations utilizes multiple tools in their comprehensive investigations including digital investigations, digital debugging, corporate investigations, litigation support, IT security audit and oversight, complex family, civil and criminal.

http://www.mccanninvestigations.com


Facebook: http://www.facebook.com/McCannInvestigations


Twitter: @mccanngi

Malisa Vincenti
McCann Investigations
800-713-7670
Email Information


View the original article here

Wednesday, December 12, 2012

IP theft attacks can hide on networks for years, unspotted by corporate victims, report claims

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Complicated blueprintOrganizations in the financial services and public administration sectors are the primary targets of sophisticated attacks aimed at stealing intellectual property, with attacks involving both external and internal agents and lasting for months or years, according to a new report.

A Verizon report [PDF] reports just 101 incidents of intellectual property theft - around 12 percent of the total data breach incidents it documented - during 2011, but attacks that stole intellectual property were both longer-lasting and more complex than other data breach incidents.

Attackers commonly relied on both external agents and insiders to carry out the attacks.

Professional criminal gangs, hacktivist groups, competitors and state-sponsored actors were "identified or suspected" in many of the IP theft crimes.

Threat agents. Source: VerizonTheir methods were both more sophisticated and determined than the average cybercriminals, the report noted.

Because intellectual property often resides deep within a company's network on protected systems, IP theft attacks frequently relied on insiders to facilitate.

Verizon found evidence of internal "threat agents" in 46% of the IP theft-related attacks, compared with just 4% of all data breach incidents in 2011.

And, in news that's bound to be disheartening to companies worried about sophisticated attacks, the report supports the notion that slow, secretive attacks are hard to spot and remove.

Once on a target network, attackers interested in stealing intellectual property hung around. Verizon claims that 17% of the IP-theft related incidents it reviewed persisted for "months" before discovery, while 31% took "years" to discover.

More than half took months, after discovery, to contain and recover from.

Timespan. Source: Verizon. Click for larger version

Database servers, file servers and finance and accounting systems were popular targets in IP-theft related attacks.

The information on intellectual property attacks ran counter to the overall trend in 2011, which found that "opportunistic" attacks by external agents against poorly protected systems were the cause of most data breaches.

In the population in general, attacks on the hospitality industry - including hotels and restaurants - accounted for more than half of the 855 incidents Verizon reported during 2011.

In contrast, targeted attacks to steal intellectual property were spread across just four verticals: financial services, public administration (e.g. government agencies), information technology and manufacturing.

Verizon said that there is no "silver bullet" for companies worried about intellectual property theft. Companies should "adopt a common sense, evidence-based approach" to security management and study incidents at organizations similar to them to see what kinds of threats and failures they are likely to encounter.

Companies should also look closely at the possibility of rogue insider acting in ways that could subvert security measures and address common security lapses such as weak passwords and vulnerable SQL server applications.

Follow @paulfroberts
Follow @NakedSecurity

Tags: data breach, verizon, government, Trojan, data theft, hacking, Malware, compliance, Advanced Persistent Threat, Data Breach Investigation Report, intellectual property theft, IP theft, insider threat, financial services


View the original article here

Thursday, May 24, 2012

State of Utah outlines mistakes made allowing theft of 780K records

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

SSN Thief photo courtesy of ShutterstockA little over a month ago the State of Utah discovered one of its servers was under attack, reportedly by Eastern European hackers.

That's almost one year to the day of a similar data loss incident suffered by the State of Texas of eerily similar circumstances.

The attackers gained access to a server used by the state to receive Medicare, Medicaid and children's health service claims.

Unfortunately it is a reasonably common practice for health care providers to submit information on other patients as well, simply to determine if they may qualify for coverage.

This means that the victims aren't limited to those receiving subsidized health services from the state.

On March 30 the attackers began siphoning the names, addresses, birth dates and other personal information of 500,000 Utah residents. The attackers were also able to exfiltrate that data and the social security numbers of 280,000 additional residents.

How did the attackers gain access to this highly sensitive information? The state's new CIO, Mark VanOrden,
Multiple mistakes led to massive health data breach, director says" href="http://www.deseretnews.com/article/865555954/Multiple-mistakes-led-to-massive-health-data-breach-director-says.html" rel="nofollow">spoke with the Deseret News and stated:

"Ninety-nine percent of the state's data is behind two firewalls, this information was not. It was not encrypted and it did not have hardened passwords."

The server had been originally installed by a third-party contractor and security audit procedures were not followed. In this case every mistake that could be made when handling personally identifiable information was made.

The data was not encrypted.
The data was preserved for longer than necessary, exposing more information when compromised.
Default passwords for service accounts were not changed/disabled.
Regular penetration tests and audits were not being performed to discover the mistake.

The state is offering one year of credit monitoring to victims of the theft, for more information and advice from the state please visit http://www.health.utah.gov/databreach/.

ID Theft protection padlock courtesy of ShutterstockOf course one year is not really much protection considering your social security number is with you for life, and most of us don't change addresses all that often. Utah Department of Health Director Dr. David Patton apparently doesn't understand that social security numbers are a far more critical thing to lose than credit card numbers.

Dr Patton suggested that one year was enough, because after one year the information "goes stale".

It is this kind of attitude that might contribute to bureaucrats making half-baked attempts at protecting the data to begin with, not considering that these incidents may haunt victims their whole lives.

Now that we have seen nearly identical incidents in two US states, let's hope this puts the other 48 on notice and triggers a response to ensure their residents are better protected.

Having processes and procedures is a start, but you must actually adhere to them to have a fighting chance against modern internet thieves.

Follow @chetwisniewski

Thief holding a Social Security Card photo and ID theft protection padlock courtesy of Shutterstock.


View the original article here

Wednesday, January 4, 2012

Data leaks at Stratfor and Care2 mark the end of a year riddled with data theft

function utmx_section(){}function utmx(){}(function(){var k='1156989329',d=document,l=d.location,c=d.cookie;function f(n){if(c){var i=c.indexOf(n+'=');if(i>-1){var j=c.indexOf(';',i);return escape(c.substring(i+n.length+1,j')})();Data leaks at Stratfor and Care2 mark the end of a year riddled with data theft | Naked Security /* */

Sorry, something happened and we couldn't sign you up. Please come back later and try again.

Congratulations, you've successfully signed up for our daily news! Check your inbox soon, we've sent you an email.

Sorry, that email doesn't look right to us so we haven't added it to our list.

We're adding your address to our list...

Join thousands of others, and sign-up for Naked Security's newsletter

Antivirus and Security Software from SophosGlobal websites    Press    About us    Contact us Naked SecuritySkip to contentSearch for:

Archive by date |author |category

Send us a tip | Subscribe by RSS

Follow us on TwitterJoin us on FacebookCheck out the SophosLabs YouTube channelConnect with us on LinkedInMalwareSpamSocial networksData lossLaw & OrderApplePodcastVideoMoreAbout Most Wi-Fi routers susceptible to hacking through security featureData leaks at Stratfor and Care2 mark the end of a year riddled with data theft

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Don't forget you can subscribe to the SophosLabs YouTube channel to find all our latest videos.

Hi there! If you're new here, you might want to subscribe to our RSS feed for updates.

Already using Google+? Follow Naked Security's Graham Cluley for the latest security news.

On LinkedIn? Join the Naked Security discussion group and connect with your peers in the security industry.

Sorry, something happened and we couldn't sign you up. Please come back later and try again.

Congratulations, you've successfully signed up for our daily news! Check your inbox soon, we've sent you an email.

Sorry, that email doesn't look right to us so we haven't added it to our list.

We're adding your address to our list...

Join thousands of others, and sign-up for Naked Security's newsletter

by Chester Wisniewski on December 30, 2011|1185982 Commentshttp%3A%2F%2Fnakedsecurity.sophos.com%2F2011%2F12%2F30%2Fdata-leaks-at-stratfor-and-care2-mark-the-end-of-a-year-riddled-with-data-theft%2FData+leaks+at+Stratfor+and+Care2+mark+the+end+of+a+year+riddled+with+data+theft2011-12-30+22%3A35%3A43Chester+Wisniewskihttp%3A%2F%2Fnakedsecurity.sophos.com%2F%3Fp%3D118598

Filed Under: Data loss, Featured, Podcast, Privacy

2012 aheadWas 2011 the year of the data leak? Could be, but it is hard to tell.

From my vantage point writing daily about the most important stories in information security, data theft may not have been the most important story of 2011, but it certainly impacted more regular people and raised their awareness about the problem of all of their data being "in the cloud".

I shared my thoughts on this today with John Moe on Marketplace Tech Report from American Public Media in the United States.

Marketplace logoYou can listen to my thoughts on 2011 alongside John Moe, Jonathan Zittrain, Susan Crawford and Danah Boyd in this four minute podcast.


(30 December 2011, duration 4:00 minutes, size 1.9 MBytes)

While Anonymous/LulzSec dominated the data breach headlines, what became clear was that more and more organizations are collecting data about us and doing a poor job of protecting that information.

Compliance rules like HIPPA/HITECH, PCI and others are not really having their intended impact as health records, credit cards, passwords, birth dates and more were all stored insecurely on often woefully unpatched systems.

Datalossdb.org logoThe number of records stolen was enormous. Sony alone was hacked more than 20 times and lost over 100 million records.

The bulk email marketing company Epsilon leaked names and email addresses from some of the world's most trusted brands like Best Buy, Marks & Spencer, Marriott Rewards, Walgreens and Chase Bank.

South Korean social media users were hit hard when Cyworld and Nate were compromised (both owned by SK Communications) and hackers made off with more than 35 million records.

Like video games that aren't related to Sony? Chances are your data was leaked when the Steam user forums were breached or when Square Enix was hit twice in 2011.

Citibank credit cardCitibank credit cards users had card information compromised affecting more than 200,000 people as well as customers of handmade cosmetics company Lush.

Of course the biggest story at the end of 2011, wrapping up the year of unsecured data has been the attack Anonymous made on Stratfor.

Stratfor, a company focused on security intelligence services, was attacked by Anonymous who have allegedly acquired 75,000 addresses, credit cards and names of their customers and then posted them publicly.

Sadly it seems companies still aren't learning the lesson of protecting their customers information, even after all of these headlines and millions of dollars in lost reputation to the companies involved.

It was brought to my attention that Care2.com's website was hacked revealing usernames and passwords for the sites nearly 18 million users.

Naked Security reader Bob emailed us to point out that Care2 is storing passwords insecurely.

Care2 logoRather than storing passwords as a salted cryptographic hash that would not reveal their customers passwords if stolen (or make it much more difficult) they are storing them either in plaintext or in a reversible format.

According to the companies own FAQ about the data breach "Q. What can I do to recover my password?
A. Visit http://www.care2.com/retrieve_password Enter your user name or email address in the green box titled “Forgot your password or log-in name?” Your password will be emailed to you."

Care2 FAQ

Really!? After the attackers made off with all of your customer information you still are following the same insecure practices that put your customers information at risk in the first place?

Where does this leave us? Think carefully about who you share personal information with, and before doing so carefully weigh whether they need that information or not.

And for the sake of all of your digital presence use unique passwords for every site you access. There are great tools to help you like Keepass or LastPass.

To quote American folk singer Pete Seeger "When will they ever learn? When will they ever learn?".

Follow @chetwisniewski

Tags: 2011, Care2, Citibank, Cyworld, DataLossDB, epsilon, Marketplace, passwords, Sony, Square Enix, Steam, Stratfor

Most Wi-Fi routers susceptible to hacking through security featureRelated PostsGuest blog: Ten tips for protecting sensitive data in your organisationTen tips for protecting sensitive data in your organisationHandcuffedDrive250What can you learn from the deluge of data leakage news?BP in troubled waters over Gulf oil spill data spillBP in troubled waters over Gulf oil spill data spillImage (1) hannaford.jpg for post 14780Three men charged in 130 million credit card identity theft2 Responses to Data leaks at Stratfor and Care2 mark the end of a year riddled with data theftJon W says:December 30, 2011 at 11:17 pm

Dear care2:
Instead of emailing our passwords back, why not just post a list of the email addresses & passwords on Facebook and we'll just pick out some to use...?

Replyjessi slaughter says:December 31, 2011 at 4:18 am

dropping the pete seeger reference in a stratfor story! well done chet, have a very happy new years!

ReplyLeave a Reply Cancel replyYour email address will not be published. Required fields are marked *

Name *

Email *

Website

Comment

You may use these HTML tags and attributes:
       

Notify me of follow-up comments via email.

About the authorChester Wisniewski is a Senior Security Advisor at Sophos Canada. He provides advice and insight into the latest threats for security and IT professionals with the goal of providing clear guidance on complex topics.You can follow Chester on Twitter as @chetwisniewski or send him an email at chesterw@sophos.com.View all posts by Chester WisniewskiPopularRecentRelatedTimHortons250Free coffee from Starbucks and Tim Hortons? No, it's a Facebook scamFacebook's ticker privacy scareFacebook's ticker privacy scare, and what you should do about itWant to see who has viewed your Facebook profile? Take care..Want to see who has viewed your Facebook profile? Take care..WiFiAllianceLogo250Most Wi-Fi routers susceptible to hacking through security featureFree Costco Gift Card for all Facebook users? Scam spreads quicklyFree Costco Gift Card for all Facebook users? Scam spreads quicklyiStock2012ahead250Data leaks at Stratfor and Care2 mark the end of a year riddled with data theftWiFiAllianceLogo250Most Wi-Fi routers susceptible to hacking through security featureno-30-dec-250Samoa moves to the other side of the world - and misses a day!HMRC250logoHMRC phishing scam promises end of year refund28c3logoLarge percentage of websites vulnerable to HashDoS denial of service attackGuest blog: Ten tips for protecting sensitive data in your organisationTen tips for protecting sensitive data in your organisationHandcuffedDrive250What can you learn from the deluge of data leakage news?BP in troubled waters over Gulf oil spill data spillBP in troubled waters over Gulf oil spill data spillImage (1) hannaford.jpg for post 14780Three men charged in 130 million credit card identity theftVideo posts

More videos this way

dragon-video-250VIDEO: How to solve the #dragontattoo #sophospuzzleTyposquatting - study reveals the real risks when you mistype a website's name [VIDEO]Typosquatting - study reveals the real risks when you mistype a website's name [VIDEO]laptop_250Identify your missing security patches this Christmasfb-stumble-video-250VIDEO: Awkward! Facebook VP stumped by BBC question60ss-20111128-250IHC, Mac malware, Nerd New Year, Conficker and Privacy à la Google - 60 Sec SecurityTwitter Feedgcluley: Facebook distributing White Hat Debit Card to Bug Bounty Winners http://t.co/MToOc2gmabout 1 hour agogcluley: Which passwords should you share with your girlfriend? http://t.co/AR8zNYoX Some interesting responses..about 4 hours agogcluley: Anonymous imposters: hiding behind the AntiSec identity http://t.co/VxaK2lOUabout 4 hours agogcluley: Hackers may have accessed Gordon Brown's emails http://t.co/czvtbH2Yabout 6 hours ago
© 1997-2012 Sophos Ltd. All rights reservedLegalPrivacyJobsRSSutmx_section("Test trigger")jQuery(document).ready(function($){ Gravatar.profile_cb = function( h, d ) { WPGroHo.syncProfileData( h, d );}; Gravatar.my_hash = WPGroHo.my_hash; Gravatar.init( 'body', '#wpadminbar' ); });

View the original article here