SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Technology Stocks : Wave Systems (Bulls Board)

 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext  
From: OKnPV10/2/2008 1:04:46 PM
   of 196
 
By the time we see articles like this one, its old news. Never see where these companies have done anything to fix the problem even showing up as revenues to security companies. Maybe its happening, but sometimes I wonder if they care....the stress & disruption hits the customer. Does it matter to big brother?

money.cnn.com

Outsourcing aids many data thefts, Verizon says
IT outsourcing eases organized crime's theft of credit-card data from chains, Verizon says
October 02, 2008: 09:42 AM EST

NEW YORK (Associated Press) - The reliance of restaurant chains and retail stores on outside companies to handle credit-card processing and other information-technology functions is partly to blame for a rash of consumer data breaches over the last few years, according to data sleuths at Verizon Communications Inc.

Even a chain with thousands of restaurants might have only 100 employees in information technology, so it uses outside vendors for many IT functions, said Bryan Sartin, director of the investigative response team at Verizon Business.

"What happens is there's a lack of accountability on the third party," Sartin said.

Verizon's unit investigates a quarter to a third of the big, publicly announced data breaches that occur each year, and hundreds of smaller cases.

In recent years, restaurant and retail businesses have accounted for more than half of Verizon's 230 to 250 cases per year, according to a report Verizon issued Thursday. It often finds that insiders at service vendors are part of the heists.

Organized data-stealing gangs "go to the call centers, the Web development companies, the content development companies, the business partners, the people who pick up the backup tapes," Sartin said. "They say ... if you hate your boss and you're in financial straits, we're your solution. Give us access to your customers. Better yet, give us your data."

In a typical case Sartin was involved in, the team was approached by a large oil company in Canada, with thousands of gas stations. Customers were finding spurious charges on their credit cards after using them at the stations.

The team soon figured out that someone at a technology vendor was responsible, but couldn't pin it down. So the investigators set a trap in the system, to see who accessed customer data.

"The trap went off on Saturday morning," Sartin said. "Hackers always think nobody's looking on Saturday mornings."

A police car headed to the vendor's office, and the culprit turned out to be a 21-year-old who supported the software that operated the gas pumps. He had sold lists of customer data to organized crime.

Many breaches don't happen through outsourcing. In one of the largest cases in recent years, the gang that stole 41 million credit and debit card numbers from chains including TJX Cos. obtained access through unsecured wireless networks, not through subcontractors' systems.

Still, Verizon's report advises companies to keep a tighter rein on contractors, including by limiting partners' access to only the data they need.
Report TOU ViolationShare This Post
 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext