Showing posts with label Breach. Show all posts
Showing posts with label Breach. Show all posts

Monday, January 13, 2014

Target Breach Affected Up to 110 Million Customers

Log in to manage your products and services from The New York Times and the International New York Times.

Don't have an account yet?
Create an account »

Subscribed through iTunes and need an NYTimes.com account?
Learn more »

Monday, May 13, 2013

Privacy Breach on Bloomberg’s Data Terminals

The company confirmed that reporters at Bloomberg News, the journalism arm of Bloomberg L.P., had for years used the company’s terminals to monitor when subscribers had logged onto the service and to find out what types of functions, like the news wire, corporate bond trades or an equities index, they had looked at. Bloomberg terminals, which cost an average of more than $20,000 a year, are found in nearly every banking and trading company.

Bloomberg said the functions that allowed journalists to monitor subscribers were a mistake and were promptly disabled after Goldman Sachs complained that a Bloomberg reporter had, while inquiring about a partner’s employment status, pointed out that the partner had not logged onto his Bloomberg terminal lately.

The incident led to broader concerns about the line at Bloomberg between its lucrative terminal business and the hypercompetitive newsroom, threatening to undermine the credibility of both. In a secretive world that thrives on opacity, traders and financial firms jealously guard every speck of information about their activity to avoid tipping their hand on their trades and investments.

“On Wall Street, anonymity is critically important. Secrecy and the ability to cover one’s tracks is paramount,” said Michael J. Driscoll, a former senior trader at Bear Stearns who now teaches at Adelphi University. He added: “If Bloomberg reporters crossed that line, that’s an issue.”

The news gathering technique appears more widespread than the Goldman incident, which was first reported by The New York Post. A preliminary analysis at Bloomberg revealed that “several hundred” reporters had used the technique, a person briefed on the analysis said. (Bloomberg employs more than 2,400 journalists worldwide. A spokesman declined to comment on the analysis and said no reporters had been fired.)

There are also fears that the monitoring may have gone beyond Wall Street. Banking regulators at the Federal Reserve are examining whether their own employees were subject to tracking by Bloomberg reporters, according to people briefed on the matter. A spokeswoman for the Fed declined to comment.

There are now more than 315,000 Bloomberg terminal subscribers worldwide who rely on the desktop computer for research, trading, communication and a constant stream of financial information and news.

But as it turned out, what the subscribers were doing was not always confidential. Bloomberg reporters used the “Z function” — a command using the letter Z and a company’s name — to view a list of subscribers at a firm. Then, a Bloomberg user could click on a subscriber’s name, which would take the user to a function called UUID. The UUID function then provided background on an individual subscriber, including contact information, when the subscriber had last logged on, chat information between subscribers and customer service representatives, and weekly statistics on how often they used a particular function. A company spokesman said both of those functions had been disabled in the newsroom.

Terminals never allowed journalists to see specific securities or trades, but even general hints of what users are searching could provide a glimpse into Wall Street’s thinking — powerful currency in the competitive world of financial journalism. Daniel L. Doctoroff, chief executive of Bloomberg L.P. and a close confidant to the company’s founder, Michael R. Bloomberg, said in a memo to employees that “client trust is our highest priority and the cornerstone of our business.” Mr. Bloomberg stepped away from day-to-day operations when he became mayor of New York City.

Last month, the company further centralized its data security efforts, including appointing Steve Ross, a senior executive, to the newly created role of client data compliance officer.

“To be clear, the limited customer relationship data previously available to our reporters never included access to our trading, portfolio, monitor, blotter or other related systems or our clients’ messages,” Mr. Doctoroff said. He posted a damage control message to clients on the Bloomberg terminal and blog, calling the reporting practice a “mistake.”

Nathaniel Popper contributed reporting.

Friday, May 3, 2013

Bucks Blog: The Cost to Consumers of a Data Breach

A new analysis of a huge data breach last year in Utah estimates that more than 120,000 cases of fraud will occur as a result of information stolen.

Javelin Strategy & Research’s analysis also estimates that each incident will result in more than $3,300 in losses, on average, and each consumer who is ultimately victimized as a result of the breach will spend about 20 hours and $770 on lawyers and time lost from work to resolve the case.

Ripple effects from the incident in the spring of 2012 will also prove costly to banks and businesses that may also suffer fraud as a result of the stolen information, said Al Pascual, a security, risk and fraud analyst at Javelin.

“We all need to be aware that breaches are occurring,” he said. “Breaches lead to fraud, and fraud affects all of us.”

Using the specifics of the Utah breach, Javelin applied what it has learned from its prior research about the impact of such breaches — namely, that having your personal information compromised makes you more likely to become a victim of fraud. Javelin estimates that roughly one in four recipients of a data-breach letter ultimately become fraud victims. (The estimate is based on information provided by consumers themselves, rather than law enforcement.)

“These breaches are driving fraud,” Mr. Pascual said. Criminals, he said, are generally not digging through trash or stealing mail to obtain personal data. “They’re stealing it digitally,” he said.

In the Utah case, about 280,000 Social Security numbers belonging to participants in the state Medicaid and Child Health Insurance Program were stolen from a database maintained by the Utah Department of Health. In addition, less sensitive pieces of information on another 500,000 participants were stolen.

Social Security numbers are particularly dangerous in the hands of criminals, because they can be used in combination with other information about you to create or access bank accounts and obtain credit.

The Social Security numbers were used by the department to verify eligibility for the insurance programs. But a contractor did not safeguard the server where the data was stored. The information was not encrypted and was protected only by a weak password that was easily hacked, the Javelin report said.

There may be little that individual consumers can do to prevent such a breach. But there are steps they can, and should, take to protect themselves, if they are notified that their Social Security number has been compromised in a data breach, Mr. Pascual said.

First, you should contact your bank and explain what has happened because many banks still use Social Security numbers to verify customer identity. You can ask for an alternative means of verification, like a specially assigned PIN, or a series of questions known as “dynamic” authentication. For instance, the bank may ask you about the size of recent transactions, or other details that only you would be likely to know, before allowing access to your account online or over the phone.

If the bank isn’t willing or able to provide an alternate method of verification, “It may be worth looking at institutions that offer better protection,” Mr. Pascual said.

Even if you haven’t had your information compromised, you should make use of your bank’s automatic account alerts. Such systems send you an e-mail or text message if unauthorized changes are made to your account, like the addition of a new authorized user or a new bill payment account, or a change of address. They can also notify you of significant transactions, like large withdrawals or transfers. “The consumer is going to know first whether a transaction is valid or not,” he said.

If you’re the victim of a breach and are offered free credit monitoring, you should take advantage of the service, he said. In the Utah case, victims were offered two years of credit monitoring and identity theft insurance.

Ultimately, banks should stop using Social Security numbers as identifiers, he said.

Have you had your personal information stolen? Did fraud occur as a result?