BankInfoSecurity.com - Banking Information Security News, Regulations, & Education
BankInfoSecurity.com Banking Information Security Careers Banking Information Security Training Banking Information Security Blogs

Username:
Password:
Remember Username?
Register | Help
Agency Releases
Articles
Handbooks
Podcasts
Webinars
White Papers

Take the 2010 Banking Information Security Today Survey

Results to be Unveiled at RSA Conference on March 2
Bank Information Security RSS Syndication Bank Information Security Articles

Credit
Eligible
As a BankInfoSecurity.com annual member, this content can be used toward your membership credits and transcript tracking. Click For More Info
Top 10 Security Breaches of 2008
Ghost of Christmas Past (TJX) Still Casts Specter on Present and Future
December 22, 2008 - Linda McGlasson, Managing Editor


Comment on this article

From Hannaford to Countrywide to the Bank of New York Mellon, 2008 has been a year of high-profile security breaches in or impacting the financial services industry. Here's our list of the top 10 - and lessons that should be learned, so we aren't back revisiting these issues in '09.

1. TJX Case Winds Up, Arrests Made

Earlier this year, The TJX Companies (parent of retailer TJ Maxx) settled in federal court and paid out millions to its federal regulator, the Federal Trade Commission, banking institutions, credit card companies and consumers to bring to a close the court cases that had threatened to overwhelm the company.

The August arrest of 11 alleged hackers accused of stealing more than 40 million credit and debit cards brings law enforcement closer to closing what is still the largest hack ever. The U.S. Department of Justice brought charges against 11 alleged hackers from around the globe. Some of the hacking gang were nabbed and brought to the U.S. to face trial alongside three U.S.-based defendants. Two of the defendants, Christopher Scott and Damon Patrick Toey, have already pled guilty in the case. Others including the ringleader, Alberto Gonzalez, await trial.

Lesson Learned: The wide-range of the perpetrators brings to light something that those in the cyber intelligence realm have known for some time: Criminal hackers are part of a very mature and multi-billion dollar industry that reaches around the world. No organization is immune to the threat.

Click to Get Updates on the Latest Information Security News

2. Bank of New York Mellon

An unencrypted backup tape with 4.5 million customers of the Bank of New York Mellon went missing on Feb. 27, after it was sent to a storage facility. The missing tape contains social security numbers and bank account information on 4.5 million customers - including several hundred thousand depositors and investors of People's United Bank of Connecticut, which had given Bank of New York Mellon the information so it could offer those consumers an investment opportunity.

Lesson Learned: For Bank of New York Mellon, know that when data is released to a third-party that their security is as good or better than yours. Encryption isn't just something that is good for the data held at an institution; it's also something to consider for data that leaves the institution.

3. Hannaford Data Breach

In March, the Maine-based Hannaford Brothers grocery store chain announced that 4.2 million customer card transactions had been compromised by the hackers. More than 1800 credit card numbers were immediately used for fraudulent transactions.

The affected banks and credit unions were forced to reissue the credit and debit cards. Within two days of the breach announcement, two class action suits had been filed on behalf of customers against the retailer. The retailer claims its systems were PCI-compliant and had passed a PCI assessment shortly before the hack was discovered.

Lesson Learned: The case is still open, and forensic reports by security investigators brought in by Hannaford have not been made public. The PCI Security Council has pledged that if the PCI requirements are found to be wanting in light of the report, they will make changes to tighten the requirements. Cases such as Hannaford may be the impetus behind legislation to require prompt notification of a data security breach.

4. Countrywide Insider Theft

In August, a former Countrywide Financial Corp. senior financial analyst, Rene Rebollo, was arrested and charged by the FBI for stealing and selling sensitive personal information of an estimated 2 million mortgage loan applicants. How he did it over a two-year period was to download about 20,000 customer profiles each week onto flash drives, working on Sunday nights, when no one else was in the office. Rebollo then took the excel spreadsheets to business center stores to email to buyers.

Countrywide, now owned by Bank of America, was already facing money and reputation issues because of the subprime loan meltdown before it faced the insider threat of Rebollo.

Lesson Learned: While Countrywide and Bank of America now know firsthand what a rogue insider can do, other institutions need to do a better job of monitoring their employees and creating asset controls. As the economy continues to produce layoffs, this threat may become even more so, as fearful employees look to cash in on their trusted status and take data just in case they face unemployment.

5. GE Money Backup Tape Goes AWOL


1 | 2 | 3



Question
Question
?What do you see as the worst security breach of 2008?
Here's your chance to be heard by your peers in the banking and finance industry! Your comments will be kept anonymous. Just enter your comment to the right and click submit to send it to our Editor.
Please login if you would like to post a comment on this question.

"Until we start encrypting sensitive information at the "data level" as it's collected, used and stored through end of life (such that no "insider" can access it, let alone download or otherwise take it) we'll continue to see more of these types of breaches. Technologies like format-preserving encryption are available now to effectively address the problem.
"With all these break-ins being reported, are there any plans to move to an EMV (chip card) environment to protect the consumers? Is this a viable security solution in this time of economic crunch?
"I'd like to hear more on the alleged World Bank break-ins. http://www.foxnews.com/story/0,2933,435681,00.html

How about the hacking of computers belonging to the McCain and Obama campaigns?

Or what the real story is on the Department of Defense USB device ban?

I'll bet the worst security breach of 2008 hasn't been discovered yet or publicly reported if it has been discovered.

Search for Articles
in

 More on this Topic:

  Recent   Popular   Research  



Blogs Related Blog Entries
Linda McGlassonSocial Networking's 17 Golden Rules
"The agency outlines a number of risks and threats associated with using social networking sites, and has come up with a list of 17 golden rules to follow when visiting or posting anything."



BankInfoSecurity.com is your one-stop portal for the latest news, insights and education on the top information security issues facing U.S. financial institutions today. Through articles, webinars, podcasts, customized training and sponsored content, our team is committed to providing up-to-date information on the security regulations, threats, solutions, training and career trends that most impact banks, credit unions and other related enterprises. Also, please check out our companion site, CUInfoSecurity.com.
Terms of Service | Advertise | Archive | Site Map | Contact | Bank Information Security RSS Syndication RSS Syndication
Copyright © 2010 BankInfoSecurity.com an ISMG Corp. company.