SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Data theft highlights user privilege flaws

Data theft highlights user privilege flaws

By:  Kathleen Lau  On: 04 Jul 2007 For: ComputerWorld Canada Creator

One data administrator is responsible for stealing millions of customer records at a U.S. firm. Canadian security experts weigh in on what went wrong and how the bad guy pulled it off.

A recent data security breach of 2.3 million customer records from a U.S. financial processing company brought into question the seeming lack of control organizations have over so-called power users in the enterprise, IT security experts said.

Fidelity Information Services has reported a data breach through its Tampa, Fl.-based subsidiary Certegy Check Services Inc. An investigation into the incident has revealed it was committed by a senior-level database administrator at Certegy, who likely stored data on a device and subsequently walked out the door with it.

Information included names, addresses, phone numbers, bank account and credit card information, which was then sold to a data broker, who in turn sold it to marketing firms.

Internal data theft is a "hot topic" in the IT industry not just because of legislation and privacy concerns, but from a governance standpoint as well, said Tom Slodichak, chief security officer at WhiteHat Inc., a Burlington, Ont.-based IT security provider.

Traditionally, he said, companies were primarily concerned with external threats like malware, but that focus has since shifted.

"Now, the flip side of the coin is a lot of attention is being paid to human policies and also technological controls that would prevent the removal of information," Slodichak said.

Another Canadian security expert hypothesized that ‘iPod slurping” could have been what enabled the database administrator to steal such massive amounts of Fidelity data.

A handheld iPod drive with the capacity to download up to 80 gigabytes of data can easily be connected to the USB port of a computer on a network, explained Eugene Ng, vice-president of technical services at NCI Secured Intelligence in Mississauga, Ont.

"It takes maybe 15 minutes to fill up 80 gigabytes; you stick it in your pocket and walk out the door," he said.

Most companies don't have good governance control over their database administrators because of the high-level privileges required to do their job, said Francis Ho, executive committee member of the Federation of Security Professionals.

"It's difficult to protect against that kind of attack because database administrators have access to everything in the database," Ho said.

Ho suggests companies can encrypt their database and increase access monitoring as a risk mitigation measure. This can, however, present some tradeoffs to work performance, he added.

Just earlier this year, authorities were investigating a possible customer data breach at the Canadian outlets of clothing retailer Club Monaco, which was alerted of the incident by a third-party payment processor, according to news reports.

It’s not known to date whether the alleged breach was caused by an insider or by an external hacker.

Slodichak doesn't believe such crimes are due to lack of awareness as cybercrime reports have consistently relayed that 70 per cent of security threats are internal – some malicious while others purely of human error. It's merely an issue of putting policies into practice, said Slodichak, who believes there were multiple opportunities to prevent the breach from happening.


Sign up for our Newsletters












Print |  Views: 1217   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Kathleen Lau Kathleen Lau was a senior writer with ITWorldCanada.com and ComputerWorld Canada from December 2006 to August 2011.In her role as senior writer, she covered broadly technology news and issues r... more

Related Content

PIPEDA changes could boost IT security budgets
PIPEDA changes could boost IT security budgetsMandatory breach notification may be on the way for Canadian businesses before the year is up, which means IT and security professionals will need to act fast to get their policies and safeguards up to snuff. A consultant offers his advice
Aussies take their cue from Canada on breach notification
Aussies take their cue from Canada on breach notificationCanadian data breach notification guidelines - jointly created by the Information and Privacy Commissioners for British Columbia and Ontario - have made their way to the land down under. Last week, Australian Privacy Commissioner Karen Curtis released the Voluntary Information Security Breach Notification Guide, which aims to assist organizations in effectively responding to information security breaches.
Top 10 security traps
Top 10 security traps Many companies spend a small fortune and deploy a small army to secure themselves from the many security threats lurking these days. But all those efforts can come to naught when making any of these common mistakes.
Dan Swanson's Security Resources: #10
i generally highlight publicly accessible resources each week, pointing out leading articles, papers, studies, etc, to support your professional development. this week’s feature item (edpacs) is a subscription based publication which i have the honor to be the managing editor.
Dan Swanson's Security Resources: #14
risk management – where the rubber hits the road.
Dan Swanson's Security Resources: #15
project management helps to pull it all together.if your project management experience or expertise needs strengthening this week’s resources are just what the doctor ordered. neal’s efforts are world class, and his project management consulting advice is sought after by numerous organizations. learning from past experiences is always recommended and the “early waning signs of it projec

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.