This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Security breach breakdowns...

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.idtheftcenter.org/breaches.shtml
> "Q: How many large breaches have there been and how many people have been potentially affected?
A: …In 2006, there were in excess of 315 publicized breaches affecting nearly 20 million individuals. Based on ITRC's categorization, the breaches break down as follows:
29% government/military agencies,
28% from educational institutions,
22% from general businesses,
13% from health care facilities/companies, and
8% from banking/credit/financial services entities…
> Q: Are all breaches alike?
A: No- security breaches can be broken down into a number of categories. What they have in common is that they contained personal identifying information in a format easily read by thieves, in other words, not encrypted.
* Lost or stolen laptops, computers or other computer storage devices
* Backup tapes lost in transit because they were not sent either electronically or with a human escort
* Hackers breaking into systems
* Employees stealing information or allowing access to information
* Information bought by a fake business
* Poor business practices- for example sending postcards with Social Security numbers on them
* Internal security failures
* Viruses, Trojan Horses and computer security loopholes
* Info tossed into dumpsters- improper disposition of information …"


(More resources and detail at the URL above.)

:(
FYI…

Tracking Publicly-Announced Data Breaches
- http://isc.sans.org/diary.html?storyid=2501
Last Updated: 2007-03-24 18:12:45 UTC ~ "…Although it's difficult to link breaches to confirmed cases of identity fraud–such details are rarely made public–here are a few ways you can keep track of announced data breaches.
# Attrition.org maintains a Data Loss Archive and Database*, which records many potential instances of data breaches. The information is available as an RSS feed and in a CSV file.
# Privacy Rights Clearing house maintains a list of data breaches**, sorted in chronological order for 2005, 2006 and 2007…
According to the 2006 Annual Study: Cost of a Data Breach, conducted by The Ponemon Institute and sponsored by PGP Corporation and Vontu, the cost of responding to a data breach "averaged $182 per lost customer record." "The average total cost per reporting company was $4.8 million per breach and ranged from $226,000 to $22 million"…"

(More detail available at the URL above.)


* http://attrition.org/dataloss/dldos.html

** http://www.privacyrights.org/ar/ChronDataBreaches.htm#2005

:ph34r: :ph34r:
FYI…

- http://preview.tinyurl.com/2y94q2
April 18, 2007 (Computerworld) - "A database intrusion by foreign hackers may have compromised Social Security numbers and other sensitive data belonging to more than 14,000 current and former employees at Ohio State University. The break-ins occurred on March 31 and April 1 and were detected the following day by university IT staffers. Access to the compromised database was immediately shut down so the school could asses the extent of the breach and prevent further compromises, a spokesman said. The university also contacted local, state and federal law enforcement authorities and hired security vendor Cybertrust Inc. to help with the investigation, the spokesman said. The breached database contained employee data including names, Social Security numbers, employee ID numbers and dates of birth, but no salary or other financial information. In total, the database contained more than 190,000 records out of which only 14,000 or so are believed to have been compromised, the spokesman said. Preliminary investigations have shown that the attacks were launched from at least three separate IP addresses from outside the country, he said…"

.