Showing posts with label hack. Show all posts
Showing posts with label hack. Show all posts

Scottrade data breach, 4.6 Million Customers information at risk

The popular investment company Scottrade announced a data breach that affects approximately 4.6 million customers. Any customer with an existing Scottrade account before February 2014 may have had their contact details and social security numbers taken away by the hackers.


According to the announcement of Scottrade, data breach took place over several months between late 2013 and early 2014. They believe that the data that was accessed includes customer names, addresses, and other personal information. It is possible that the customers Social Security numbers were accessible as well, but they can not say for sure yet. No client funds, or trading platform itself were affected or accessed. All guest passwords were encrypted and there was no further sign of fraudulent activity.

Scottrade noted that contact information was the subject of the violation, and Brian Krebs on the blog KrebsOnSecurity suggests that intruders may use the information to facilitate fraud actions. This probably means an increase of spam to Scottrade customers, but fortunately not much else. If you believe you were affected by this breach of data, however, Scottrade offers the value of free credit monitoring service for one year. Just call AllClear ID at (855) 229-0083.

Medical Devices Are Prone To Internet Hacking

Security researchers say at least 68,000 medical systems - such as MRI scanners and infusion systems - from a "large anonymous group of health, in the United States" are available online for hackers to attack.


Researchers Scott and Mark Erven Collao in piracy Derbyco conference explained that they were able to access many medical devices interfaces using the search engine Shodan, which specifically hunting for Internet-connected devices. The pair explained that through further intelligent research they managed to build a detailed picture of the devices used by the organization of health in particular, including details on where medical devices were in a particular building.

There is no data on the unit while it is available, however: the team reported that they were able to identify "direct attack vectors," which could be used to steal data from patients devices, too.

The team also explained that for six months they ran software that claimed to be an MRI and defibrillator as a honeypot for hackers. During this period, they observed thousands of attempts to connect to devices and 299 attempts to install malicious software on them, suggesting the same thing happens in hospitals worldwide. This could be a problem because, as Collao told The Register, "[Medical Devices] are all running Windows XP or XP Service Pack two ... and probably do not have antivirus because they are critical systems."

It is not, of course, the first time the digital security of medical devices has been questioned. Malware is said to be "rampant" in hospitals, and earlier this year, it emerged that hackers could divert drug infusion pumps. Clearly something must be done - but knowing where to start is perhaps the biggest problem.

Kategori

Kategori