Subscribe free to our newsletters via your
. 24/7 Space News .




INTERNET SPACE
Stolen data may be sold on cyber black market
by Staff Writers
Washington (AFP) April 6, 2011


Sophisticated cyber thieves behind Epsilon attack
Washington (AFP) April 6, 2011 - An online marketing firm hit by what may be one of the biggest data thefts ever was the victim of "highly sophisticated cyber thieves," its parent company said Wednesday. Alliance Data Systems Corp. also reiterated that only the names and email addresses of customers were stolen in the attack on its subsidiary, Epsilon, and not credit card information or social security numbers. Alliance Data said Epsilon is investigating the "unauthorized entry" into its email system with federal authorities and outside forensics experts and implementing additional security protocols.

"We will leave no stone unturned and are dealing with this malicious act by highly sophisticated cyber thieves with the greatest sense of urgency," Alliance Data chief executive Ed Heffernan said in a statement. "We fully recognize the impact this has had on our clients and their customers, and on behalf of the entire Alliance Data organization, we sincerely apologize," Heffernan said. Major US banks, hotels, retail outlets and other companies have been warning customers to be wary of fraudulent emails after Epsilon acknowledged last week that hackers had gained access to the Texas-based company's email system.

Epsilon, which sends out over 40 billion emails a year on behalf of 2,500 companies, has not identified the firms whose customers' names and email addresses were stolen but dozens of US companies have come forward. They include Hilton and Marriott hotels, telecom giant Verizon, drugstore chain Walgreens, the Home Shopping Network and retailers Best Buy, Kroger, New York & Co. and Target. Among the banking and financial firms that have notified customers of the breach are Citigroup, JPMorgan Chase, Capital One, US Bank, Barclays Bank of Delaware and Ameriprise Financial.

Computer security experts said tens of millions of names and email addresses may have been stolen in what they said was one of the largest data thefts in US history. Epsilon president Bryan Kennedy also issued an apology. "We are extremely regretful that this incident has impacted a portion of Epsilon's clients and their customers," Kennedy said. "We take consumer privacy very seriously and work diligently to protect customer information. "We apologize for the inconvenience that this matter has caused consumers and for the potential unsolicited emails that may occur as a result of this incident," he said.

Hackers behind what computer security experts believe could be the biggest data theft in US history may be planning to sell the information to cyber criminals for targeted scams.

And while the tens of millions of names and email addresses swiped from online marketing firm Epsilon do not appear to have been used yet for cyber crime, the experts said it may just be a matter of time.

Major US banks, hotels, retail outlets and other companies have been warning customers to be wary of fraudulent emails after Epsilon acknowledged last week that hackers had gained access to the Texas-based company's email system.

Epsilon, which provides email services for some 2,500 companies around the world, has said that customer data for about two percent of its total clients was exposed in what it called an "unauthorized entry."

Epsilon, which sends out over 40 billion emails a year, did not identify the firms whose customers' names and email addresses were taken but dozens of US companies have come forward over the past few days.

"It's basically a who's who from the retail and banking space," said Nicholas Percoco, head of Trustwave's SpiderLabs. "Some of the top brands in the world."

They include Hilton and Marriott hotels, telecom giant Verizon, drugstore chain Walgreens, the Home Shopping Network and retailers Best Buy, Kroger, New York & Co. and Target.

Among the banking and financial firms that have notified customers of the breach are Citigroup, JPMorgan Chase, Capital One, US Bank, Barclays Bank of Delaware and Ameriprise Financial.

Security experts said the data theft at Epsilon could be the largest ever in terms of sheer volume, comparable to the exploits of Albert Gonzalez, one of the most prolific US commercial hackers ever.

Gonzalez is serving 20 years in prison for stealing tens of millions of debit and credit card numbers from firms supporting major US retailers and financial institutions.

Percoco said the Epsilon data theft may involve as many as 100 million unique email addresses and "could end up being the largest breach ever of raw personal data, consumer data."

Marian Merritt, Internet Safety Advocate at Symantec, the maker of Norton anti-virus software, said data breaches occur frequently but "all indications are this could be the biggest one in history."

It is unlikely to prove as damaging, however, as the Gonzalez scams.

"The good news is it's just the names and the email addresses and the affiliation of the company that you did business with," said Joris Evers, a security expert at McAfee.

"It's not your credit card number or your social security card number or your home address... information that could be more personal and used in more nefarious ways immediately," Evers said. "There's a lot of work to do before you can convert this into cash."

The Epsilon data does not appear to have been used yet for any cyber crime.

"We have been looking around since this news broke for spam and scams and scammy websites that potentially take advantage of this breach and we haven't seen anything just yet," Evers said.

That may be because the hackers who carried out the Epsilon attack intend to sell the information to other cyber criminals, the experts said.

"They may be people who are buying and selling stolen data bases of user names and email addresses," said Symantec's Merritt.

"There are marketplaces on the Internet, underground markets, where people sell bulk bunches of email addresses and names," Evers added. "You can buy a million email addresses for 20 dollars or something like that.

"But that's just email addresses, mailing lists that you can then start spamming."

The information stolen from Epsilon is more valuable because it links names and email addresses with particular companies that an individual already has a trusted relationship with.

"They've got your name, not your user name, but your actual name, your email address and brands that you regularly do business with and trust in an email relationship," Merritt said.

"You've already identified yourself as willing to receive communications from those brands," she said. "So the cybercriminals have pretty good information to use against you."

Evers said such information can be a "treasure trove" for cyber attackers because now they can start personally targeting individuals, a tactic known as "spear phishing."

For example, "you might have bought something from LL Bean recently," he said. "You receive an email that says 'We want to confirm your order, please click here.'

"And you end up on a website that infects your computer with something. Or you're asked to type in your credit card number again to make sure the order goes through," he said. "And now, boom, I have your credit card information."

Whatever form the attacks take, experts are certain they're coming.

"They didn't go get these email addresses and names just to get them," Percoco said. "They're going to use them."

.


Related Links
Satellite-based Internet technologies






Comment on this article via your Facebook, Yahoo, AOL, Hotmail login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle








INTERNET SPACE
Microsoft to power Toyota cars on Internet highway
San Francisco (AFP) April 6, 2011
Microsoft and Toyota Motor Corp. (TMC) on Wednesday announced they will work together to infuse the Japanese auto maker's cars with digital capabilities hosted in the Internet "cloud." Microsoft and Toyota planned to jointly invest $12 million (one billion yen) in a Toyota subsidiary devoted to automotive digital information services. Navigation, energy management, and other "smart" feat ... read more


INTERNET SPACE
NASA Announces Winners Of 18th Annual Great Moonbuggy Race

84 Teams To Compete In NASA Great Moonbuggy Race

A New View Of Moon

Super Full Moon

INTERNET SPACE
Next Mars Rover Nears Completion

Mars In Spain

Study Of 'Ruiz Garcia' Rock Completed

Next Mars Rover Gets A Test Taste Of Mars Conditions

INTERNET SPACE
Key dates in the history of space exploration

Life And Physical Sciences Research Program Helps Human Space Missions

New heights for Australian beer lovers

Branson unveils 'flying' sub to plumb ocean depths

INTERNET SPACE
What Future for Chang'e-2

China setting up new rocket production base

China's Tiangong-1 To Be Launched By Modified Long March II-F Rocket

China Expects To Launch Fifth Lunar Probe Chang'e-5 In 2017

INTERNET SPACE
Space Debris No Threat To ISS

Astronauts head to ISS on spaceship Gagarin

Station Fires Engines To Avoid Orbital Debris

Successful First Mission For Aerospace Breakup Recorder

INTERNET SPACE
Mitsubishi Electric's ST-2 Satellite Arrives In French Guiana

Jugnu Set To Go Into Space In June

SpaceX Antes Up With Falcon Heavy

India's GSAT-8 Delivered To French Guiana

INTERNET SPACE
White Dwarfs Could Be Fertile Ground For Other Earths

NASA Announces 2011 Carl Sagan Fellows

Report Identifies Priorities For Planetary Science 2013-2022

Planetary Society Statement On Planetary Science Decadal Survey For 2013-2022

INTERNET SPACE
Japan considers wider nuclear evacuation zone

Cobra Judy Replacement Team Completes Radar Delivery Milestone

Google to reorganize YouTube channels: report

Japan stems uncontrolled leak from nuclear plant




The content herein, unless otherwise known to be public domain, are Copyright 1995-2014 - Space Media Network. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA Portal Reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. Advertising does not imply endorsement,agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. Privacy Statement