Wednesday December 3, 2008 2:59 AM AEST
Latest Comments
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM

Phishing scams await Ameritrade breach victims

  • Email a Friend
  • Print Page
Phishing scams await Ameritrade breach victims
By Dan Kaplan
Sep 20, 2007 9:49 AM
Tags: Phishing | scams | await | Ameritrade | breach | victims
The US-based brokerage revealed on Friday that the names and contact details for 6.3 million customers was exposed when hackers infiltrated a database.

No Social Security numbers, account information or other sensitive information was hijacked in the attack, discovered by the company several weeks ago.

But the information taken could still be used to propagate identity theft, experts from Sophos said

"Hackers are now in possession of 6.3 million email addresses for people that they know are interested in trading shares," Graham Cluley, senior technology consultant for Sophos, said. "This knowledge alone could spur the creation of highly targeted spam emails, such as pump-and-dump scams.”

Carl Banzhof, vice president and chief technology evangelist at McAfee, said that the cyberthieves likely used SQL injection tactics to infiltrate the database, harvesting email addresses

"Once you have that information, you can craft an email message that looks very convincing to a customer and trick them into giving up more information," he said.

TD Ameritrade said it discovered the breach after customers told the company they had received spam offering unsolicited investment advice.

Company spokeswoman Kim Hillyer said that a small number of clients notified Ameritrade about the junk mail.

"Through the course of investigating that, a few weeks ago, we discovered unauthorized code on our system," she said.

This multi-stage attack is similar to the recent theft at Monster.com in which thieves stole the email credentials of some 1.3 million job seekers.

Ray said controls should have been in place to prevent the Ameritrade compromise

"One would assume that in this day and age of Sarbanes-Oxley and other regulations, [Ameritrade] would have human beings and physical hardware and software in place to detect this sort of thing," he said.


Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Messaging Whitepapers