breach

Massive security breach leaves cardholders vulnerable

Some 50,000 credit and debit cardholders may have their information exposed following a security breach at Global Payments, according to The Wall Street Journal.

The full extent of the breach is still unknown, the Journal reported today, and it's unclear whether fraudulent charges on cardholders have been racked up yet.

Global Payments later released a statement saying the breach didn't involve its merchants or their customers. The company said it had determined early this month that card data may have been accessed, and alerted law enforcement.

"It is reassuring that our security processes detected an intrusion,&… Read more

Why 'data breach' isn't a dirty word anymore

Three years ago one of the largest payment processors in the country reported that hackers had accessed its computer system, exposing millions of credit card numbers in what is believed to be the largest hacking-related security breach ever.

Heartland Payment Systems' CEO said at the time that the breach had occurred in 2008, but had only been discovered in January 2009. According to the DataLossDB site, the Heartland breach involved 130 million credit and debit card numbers. The company was sued by shareholders, but the suit was dismissed. Meanwhile, after pleading guilty to that hack as well as a slew … Read more

Verizon: Hacktivists stole 100 million+ records in 2011

Financially motivated criminals were behind most of last year's data breaches, but hacktivists stole almost twice as many records from organizations and government agencies, according to the Data Breach Investigations Report being released by Verizon today.

While more than 80 percent of the data breaches in 2011 were due to organized criminal activity, the number of records pilfered from activist groups represented 58 percent of the total, the report finds.

In particular, hacktivists targeted corporations and big agencies, and consumer data. Activist groups accounted for more than 22 percent of the data breaches targeting large organizations. Meanwhile, 95 percent … Read more

AllClear ID offers free ID theft mobile app

A Texas company is releasing a free mobile app today that will alert people if their personal data has been stolen and makes it into the hands of criminals.

AllClear ID offers identity fraud protection services to consumers when their data has been exposed by an attack on a corporate database or other compromise. For instance, Sony hired the company to help its 75 million PlayStation Network customers after the system was hacked and their names, addresses, e-mail addresses and other information were exposed last April.

While very few of the data breach incidents actually result in harm to consumers, … Read more

FBI says $700K charged in Anonymous' Stratfor attack

When the Antisec branch of Anonymous hacked into security think tank Strategic Forecasting, or Stratfor, at the end of December, one of its claims was the theft 200GB worth of data, including e-mails and clients' credit card information.

Days after the hack, the group published 860,000 e-mail addresses and 75,000 unencrypted credit card numbers on the Web.

Now, the FBI's Milan Patel says that between December 6, 2011, and February 2012, "at least $700,000 worth of unauthorized charges were made to credit card accounts that were among those stolen during the Stratfor Hack," according … Read more

AntiSec dumps Monsanto data on the Web

Anonymous continued its ongoing attack on agricultural biotech giant Monsanto today by publishing an outdated database of the company's material. This is the newest in a barrage of strikes from hackers aligned with Anonymous who operate under the "AntiSec" banner.

In a statement posted with the database on a Pastebin site, the hacktivist group wrote it was aware that exposing the database would not do much harm to Monsanto but warned it would continue to target the company for what it sees as wrong.

"Your continued attack on the worlds food supply, as well as the … Read more

Hackers nip at LA police canine group

Hackers today released names, addresses and phone numbers of more than 100 officers whose information was pilfered from the Web site of the Los Angeles County Police Canine Association.

LACPCA President Tony Vairo confirmed to CNET that the group's site was hacked and said that the FBI had notified him of the breach. He said he could not comment further.

The hackers also claimed to have found what they described as a couple of objectionable photos of children in the private e-mails of a police officer whose account they were able to access because he purportedly used the same … Read more

Keeping up with the hackers (chart)

Editors' note: This story was originally published June 17, 2011.

The number of hacking events of late is making our heads spin at CNET. There were scores of computer attacks, network intrusions and data breaches in 2011 and the trend shows no signs of abating in 2012.

In previous coverage, we've noted that it seems to be open hacking season, written about some of the hackers and groups who are behind the attacks,and speculated on their motives, so we thought we'd provide a chronological chart listing the attacks so we could all keep up on them. We … Read more

Hackers stole data from VeriSign in 2010

Attackers repeatedly hacked VeriSign's network and stole information in 2010, the company revealed in a quarterly regulatory filing.

The Internet infrastructure provider did not disclose what information was stolen or other details of the attacks in its 10-Q report filed in October with the U.S. Securities and Exchange Commission that was reported on by Reuters today.

"In 2010, the Company faced several successful attacks against its corporate network in which access was gained to information on a small portion of our computers and servers," the company wrote. "Information stored on the compromised corporate systems was … Read more

New EU data protection rules due this week

Companies will be required to disclose security breaches within 24 hours of their occurrence under European Union proposals being made this week to strengthen data protection rules.

New rules are needed to protect consumers and reduce bureaucracy, EU Justice Commissioner Viviane Reding said in a speech at a conference today in Munich.

"Companies that suffer a data leak must inform the data protection authorities and the individuals concerned, and they must do so without undue delay," Bloomberg quoted Reding as saying at the DLD conference. "European data protection rules will become a trademark people recognize and trust … Read more