Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
ComputerWorldNetwork WorldCIO CanadaCIO Canada Governments' ReviewJobUniverse Canada
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Unlock the potential of data with the right data warehouse solutionUnlock the potential of data with the right data warehouse solution read more
IBM Multiform Master Data Management: The evolution of MDM applicationsIBM Multiform Master Data Management: The evolution of MDM applications read more
Closing the data privacy gap: Protecting sensitive data in non-production environmentsClosing the data privacy gap: Protecting sensitive data in non-production environments read more
Yuk it Up
IT Executive Development Series
Some of Canada's leading academics discuss the best leadership practices for a wide range of IT challenges. It's a "must read" for those senior managers and other professionals who spearhead the IT strategies within their organizations.
Featured IT Quiz
IT Quiz: Test yourself to see if you have the knowledge to fit into the open source world, and compare yourself with the rest of the respondents
Featured White Papers
This white paper details Intel's current and future energy-saving initiatives to reduce costs and support business goals. Learn how Intel IT is extending its efforts to be a role model enterprise IT organization by supporting the Climate Savers Computing Initiative, which aims to drive a 50 percent reduction in computer-related CO2 emissions worldwide. No registration required.
Sign-Up for
Information Architecture
eNewsletter Delivered Weekly
Click here
Page 1 of 1

Hacker hits Georgia state database

Advertisement

An unpatched flaw in a “widely used security program” was exploited by an unknown hacker to gain access to a Georgia Technology Authority (GTA) database containing confidential information on more than 570,000 members of the state’s pension plans.

The intrusion occurred sometime between Feb. 21 and Feb. 23 and involved a hacker who used “sophisticated hacking tools” to break through several layers of security after accessing the server hosting the database via the software flaw, said Joyce Goldberg, a GTA spokeswoman.

Goldberg refused to name the security vendor whose software was exploited, citing an ongoing investigation. She added, however, that the vulnerability exploited by the hacker had already been publicly disclosed by the vendor.

“We were in the midst of fixing the flaw that the software vendor had identified. But the hacker got in before we were able to do that,” she said. “Shortly after the breach, we saw some unusual activity, and in looking at that, we discovered the breach.”

Goldberg declined to elaborate on what that unusual activity was.

The breached server contained information on a total of eight pension plans administered by the state. The core database itself was managed by the state Employees Retirement System, though the server it was hosted on was administered by the GTA.

At this point, there is no evidence that confidential information, including names, Social Security numbers and bank-account details, have been misused, Goldberg said.

Even so, the GTA is sending out letters to 180,000 affected employees for whom it has contact information, she said. The state does not have current addresses for the remaining 373,000 individuals affected and is relying on media reports and its own outreach efforts to inform them of the potential compromise of data, Goldberg said.

Advertisement

The Georgia Bureau of Investigation is investigating the incident. The GTA is also bringing in outside security advisers to do a security assessment, the agency said in a note posted on its site.

This is the second major breach involving the GTA in the past year. In April 2005, the GTA disclosed that a state employee had downloaded confidential information belonging to more than 450,000 members of the state’s health benefit plan onto a home computer.

Since that breach, the GTA has implemented several measures to tighten security, including stricter password controls, more timely reviews of logs and alerts, more extensive employee background checks and stricter control of access confidential data, according to the GTA’s Web site.

Incidents such as this highlight the dangers companies face when the software they rely on to protect their data itself turns bad, said Lloyd Hession, vice president and chief technology officer at BT Radianz, a New York-based provider of telecommunications services to financial companies.

“The most important point to remember [from such incidents] is that you don’t want to be overly dependent on a single vendor’s product” for security, Hession said.

Earlier this month, a faulty antivirus update from McAfee Inc. mistakenly identified hundreds of legitimate programs as a Windows virus, resulting in the accidental deletion of significant amounts of data from company computers that had the faulty software installed on them.

Two years ago, the Witty worm, which was reported to have damaged 15,000 to 20,000 computers worldwide, took advantage of a flaw involving the BlackIce and RealSecure intrusion-prevention products from Atlanta-based Internet Security Systems Inc. The worm wrote random data onto the hard disks of vulnerable systems, causing the drives to fail and making it impossible for users to start up the systems.

Such incidents highlight quality lapses that sometimes occur when security vendors try to rush out products to keep up with security threats, Hession said. “Security vendors have to adapt very quickly to new threats,” resulting in very short development and testing cycles, he said.

With security products, “the perception is that it should be more reliable than other software,” which is not always the case, said Ken Dunham, director of the rapid response team at VeriSign Inc.'s iDefense Labs unit. IT managers need to remember that all software is susceptible to errors that pose security risks, he said.

Page 1 of 1
Send to a Friend  Rate This Page  Print This PageAdd a new comment

Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields


Related Content
Articles

Book Reviews

Special Advertising Partners
IDC Case Study: Identity And Access Management Buying Criteria.
IDC analyses IAM buying criteria and deployment at Coppin State University. Coppin State replaces "first generation" IAM solution to obtain benefits needed for today's agile enterprise: ease of integration, rapid deployment, simplified compliance, flexibility.
White Papers
Closing the data privacy gap: Protecting sensitive data in non-production environments
How can IT organizations protect sensitive data, including employee and customer information, as well as corporate confidential data and intellectual property? Industry analysts recommend "de-identifying" or masking data as a best practice for protecting privacy. This white paper explains the importance of closing the data privacy gap in non-production environments, and provides guidance on effective data masking. Complimentary with registration. Sponsored by IBM.
Unlock the potential of data with the right data warehouse solution
Once you've made the decision to implement a new data warehouse, you want to make sure you choose the one that's right for your organization. This buyer's guide provides checklists for starting points that you can use when evaluating vendors and their products. Complimentary with registration. Sponsored by IBM.
Prepare for a more efficient SAP implementation: Take data issues off the critical path
This white paper outlines how the Preliminary Data Assessment Appliance (PDAA) from IBM can help address the challenges of integrating data from different operational applications across the enterprise to an SAP platform. Complimentary with registration. Sponsored by IBM.
Address IT costs and streamline operations with IBM service request and asset management solutions.
This brochure describes how IBM service request and asset management solutions help IT integrate incident, problem, change and release management. Complimentary with registration. Sponsored by IBM.
Identify and leverage your existing service life cycles.
This executive brief illustrates the progression of service management since the 1990s, illuminates the hidden service life cycles and discusses how, once they are visible, we can start to make them work — to improve services and better align IT with business objectives. Complimentary with registration. Sponsored by IBM.
Deliver service excellence through the unique advantages of IBM Service Management solutions.
This brochure provides a comparative analysis of IBM's key differentiations in the area of IT service management. Complimentary with registration. Sponsored by IBM.