Wednesday, January 26, 2011

2010 DATA BREACH STATISTIC FROM SECRET SERVICE



* 98% of all data breached came from hacked servers.
* 96% of these breaches were avoidable through simple intermediate controls.
* 85% of these attacks were not considered highly difficult.

CIOs See Smartphones As Data Breach Time Bomb

Eight out of 10 CIOs think that using smartphones in the workplace
increases the business's vulnerability to attack, and rank data
breaches as their top related security concern. Yet half of
organizations fail to authenticate their employees' mobile devices,
among other basic security measures.

Those finding come from a report released Wednesday conducted by
market researcher Ovum together with the European Association for
e-Identity and Security (EEMA).
The study found that the so-called consumerization of enterprise IT,
meaning employees who bring ostensibly consumer devices to work,
continues at full pace. According to the report, 48% of employees are
allowed to use mobile devices that they own to connect to corporate
systems. Meanwhile, 70% of employees can currently use corporate-owned
computing devices for personal activities.

"Employees will want to use their devices, no matter who owns them,
for both their work and personal lives," said Graham Titterington, a
principal analyst at Ovum, in a statement. "It is unrealistic to
delineate between these uses for employees who are mobile and working
out of the office for a large part of their time."
Interestingly, 90% of organizations provide -- or will soon offer --
mobile devices to their employees. A majority said those devices would
be BlackBerry smartphones, which mirrors the continuing market
dominance of the BlackBerry platform -- with a 37% market share, ahead
of Apple (24%) and Android (21%).

But mobile device security controls remain a weak point, with only
half of organizations authenticating their mobile device users. Among
those, about two-thirds rely on usernames and passwords, while 18% use
public key infrastructure (PKI) certificates, and only 9% employ
two-factor authentication with one-time passwords. Furthermore, only
about 25% of organizations ensure that employees' mobile devices are
running antivirus and anti-malware software.

"As this new study bears out, putting a smartphone security strategy
in place is now a business imperative," said Roger Dean, director at
EEMA, in a statement. "But how many organizations have the in-house
expertise required to develop and implement a mobile strategy that
fits seamlessly with their overall security profile?"
According to Titterington, "organizations must establish a holistic
security strategy that addresses the consumerization of this
fast-growing channel into corporate networks and data."

Google, UK Reach Deal Over Street View Wi-Fi Data

The UK Information Commissioner's Office (ICO) signed an agreement
with Google Friday that requires the search engine giant to implement
more security training for employees and data protection requirements
for new features in the wake of Google's Wi-Fi data collection breach.

Google already announced that it would make these changes to its
internal policies, however, so the agreement is somewhat of a
formality, though the ICO said it would conduct a "full audit of
Google's internal privacy structure, privacy training programs, and
its system of privacy reviews for new products" sometime in the next
nine months.

The agreement was signed by Alan Eustace, senior vice president at Google.

"I am very pleased to have a firm commitment from Google to work with
my office to improve its handling of personal information,"
information commissioner Christopher Graham said in a statement. "We
don't want another breach like the collection of payload data by
Google Street View vehicles to occur again."

The agreement comes almost a month after the ICO re-opened its
investigation into Google's Wi-Fi data collection. That came days
after Google said that it collected entire e-mails, URLs, and
passwords when its Street View cars accidentally sniffed unencrypted
Wi-Fi networks. The company first admitted the misstep in May, but had
not yet determined whether personally identifiable information was
included among the data. In July, the ICO said the issue was closed,
but re-opened its case after Google's admission.

In the U.S., the Federal Trade Commission closed its investigation on
the issue after Google implemented its privacy changes, but the
Federal Communications Commission announced recently that it would
conduct its own inquiry.

After FTC Settlement, LifeLock Refund Checks Going out

More interesting SSN factoids from the Dataloss Database. Do you remember
those [obnoxious?] Todd Davis commercials? At least 13 identity theft
incidences occurred.....

"LifeLock drew attention after CEO Todd Davis published his Social
Security number in company advertisements, saying he was so confident in
his company's services that he was making it public. It was later
discovered that Davis had become the victim in at least 13 cases of
identity theft."

Two charged in BECU ID theft thought to impact 100s

Prosecutors have filed charges against two men believed to have defrauded hundreds of BECU members by "skimming" debit cards at
Seattle-area ATMs. Having filed ID theft-related charges against the men, King County prosecutors contend Seattle resident Claudiu
Flaviu Tudor and Mihai Podaru stole the account information of hundreds of BECU users during a sophisticated scheme that saw cameras
and debit card skimmers attached to a Renton ATM.
...
For short periods over four days in September, the thieves attached a credit card skimmer to a BECU ATM at 4250 N.E. Fourth St. in
Renton, Carroll told the court. At least 55 BECU members who used the ATM while the skimmer was in place have since experienced
fraud on their accounts; the bank has lost $170,442 due to fraud on those accounts.

The thieves, Carroll continued, also had placed a camera over the ATM PIN pad to capture the personal identification numbers of
those using the machine.

Using stolen SSN isn't criminal impersonation, court says

This head-scratcher happened a couple of weeks ago but hasn't gotten
anywhere near the attention it deserves.

The Colorado Supreme Court by a vote of 4-3 has overturned the
conviction of a man who used a woman's Social Security number to apply
for a car loan. The action did not constitute criminal impersonation,
says the court's majority, because the man provided his real name,
address and place of employment, in addition to the purloined Social
Security number.

>From a story in the Greeley (Colo.) Gazette:

In the decision the court ruled, "The defendant (Felix
Montes-Rodriguez ) did not assume a false or fictitious identity or
capacity," and that he "did not hold himself out to be another person
when he used another person's social security number to obtain an
automobile loan."

During the trial, representatives from Hajek Chevrolet testified a
social security number was required as part of their application
process in order to conduct a credit check.

The court ruled that was irrelevant as it was a lender requirement,
not a legal requirement. They stated that even though Montes-Rodriguez
may have "lacked the practical capacity to obtain a loan ...because
they could not check his credit without a social security number" he
did not lack the legal capacity to receive a loan. The court went on
to state there is "no evidence a social security number is a legal
requirement to obtain a loan."

Justice Nathan Coats, writing in the dissent, said, "The defendant's
deliberate misrepresentation of the single most unique and important
piece of identifying data for credit-transaction purposes" was
"precisely the kind of conduct meant to be proscribed as criminal."
Coats went on to say that an individual's credit history is often only
available through their social security number and when a person is
using someone else's social security number that person is assuming
the other's credit history.

That would seem to be as clear as the digits on my Social Security card.

As might be expected, the majority's ruling is not getting a lot of
support among experts in the fields of law, privacy and common sense.
Writes Adam Levin, co-founder of Credit.com and Identity Theft 911:

So while the defendant walks away a free man, after knowingly using a
Social Security number that was not his own to obtain credit, Colorado
consumers, ironically enough, wind up feeling less free.

While I understand the narrowness of the majority's viewpoint, you
can't make the case that a man using a Social Security number that
belonged to someone else wasn't engaging in what Colorado law cites as
"criminal impersonation". More so, I categorically reject the notion
that Social Security numbers should take a back seat to any piece of
personal financial information when seeking to establish credit, as
the court suggests. On the contrary, the Social Security number is the
most critical piece of data when obtaining a loan, far more important
than a name or address.

Another expert noted that when it comes to identity theft, a Social
Security number can be the "key to the kingdom:"

The Colorado ruling highlights an underlying misunderstanding about
identity theft, criminal impersonation and the ease with which
criminals can access and exploit Social Security numbers, (attorney
and information privacy expert Mari) Frank says, who adds that several
of her clients have had their Social Security numbers stolen,
including a 7-year-old victim.

"He is 21 now, and last year he tried to get a car loan from his
credit union; but they did not want to give it to him," she says. "His
credit union purchased a Social Security search from Experian and
found that three other people were using his credit and his Social
Security number." Frank later learned from credit bureau Experian
Information Solutions Inc. that her client's Social Security number
had been used by those three individuals to build individual credit
profiles. In each case, the Social Security number was affiliated with
a separate individual's name.

The good news is that Colorado's laws against the misuse of Social
Security numbers have been stiffened since this case was initiated,
according to this report.

After FTC Settlement, LifeLock Refund Checks Going out

The check is in the mail for nearly a million LifeLock customers,
after the provider of identity-theft protection services settled
accusations of deceptive advertising.

The checks, for US$10.87, started going out Wednesday, according to
the U.S. Federal Trade Commission, which is managing part of the $12
million settlement.

LifeLock drew attention after CEO Todd Davis published his Social
Security number in company advertisements, saying he was so confident
in his company's services that he was making it public. It was later
discovered that Davis had become the victim in at least 13 cases of
identity theft.

The FTC and 35 state attorneys general accused LifeLock of making
false claims, saying it didn't protect against some of the most common
types of identity theft, such as theft from existing bank accounts.
They reached a little settlement with LifeLock in March and the checks
are being mailed as part of that settlement.

In March, LifeLock said it was pleased with this agreement because it
set advertising guidelines for the entire identity-theft protection
industry.

The checks are being sent to 957,928 people who signed up for
LifeLock's $10-per-month identity-theft protection service. Customers
will have 60 days to cash their checks. The refund's administrator has
set up a toll-free number for people with questions at 1-888-288-0783.