Review of 2007: Lost in translation
- Article 12 of 33
- SC Magazine, February 2008
Large-scale data breaches across both the private and public sectors dominated the news throughout the year. Rob Buckley looks back.
Page 1 | Page 2 | Page 3 | Page 4 | Page 5 | All 5 Pages
Security breaches were everywhere. Monster.com suffered a malware attack that exposed over 1.6 million customer records, then waited five days before telling its users. And the UN's website was hacked.
Fortunately, there was some good news, with “pharmacy spam king” Christopher Smith sentenced to 30 years in the US.
SEPTEMBER
With the new High Speed 1 Eurostar breaking the speed record for a journey from London to Paris, September was a truly international month. The Bank of India website was discovered to have been hacked and serving 30 different types of malware to unsuspecting readers. Meanwhile, Chinese hackers turned out to have been busily breaking their way not just into the Pentagon but British government systems, including the Foreign Office.
Not that the British government was incapable of losing data all by itself: HMRC suffered what would turn out to be a relatively minor loss when one of its laptops went missing with 400 personal data records on it.
Private companies proved more than capable of losing their data, too. Pharma giant Pfizer revealed that it had had three security breaches over the previous year, losing 34,000 staff profiles through internal theft, more employee information from two laptop thefts, and thousands more employees' details through peer-to-peer software.
A survey by the Computer Security Institute revealed the average annual loss for US businesses from computer crime had doubled in 2007 to $350,424 (£169,000), with almost a fifth of those that had suffered a security breach experiencing a targeted attack.
OCTOBER
Angelina Jolie was being blamed for surges at the start of October - this time, the surge was in malware, which was using promised images of her to attract double-clicks. A new exploit for Acrobat led to PDF-based spam once again spreading like the Californian wildfires, while YouTube turned out to be a handy mechanism for spam propagation.
The alleged owner of a botnet network was arrested for attacking organisations including anti-phishing community CastleCops.
October also saw McAfee make moves on ScanAlert, Oracle agreeing to buy LogicalApps and Trend Micro acquiring Provilla.
The data breach at TJX, which had had its customer records hacked over 2005 and 2006, returned to haunt the retailer: investigations revealed that 94 million customer account numbers may have been compromised, the biggest loss in history. HMRC, clearly looking for bigger and better data losses of its own, managed to lose a disk in the post containing the pension details of 15,000 Standard Life customers. But it wouldn't be until November that it achieved its full potential.
Page 1 | Page 2 | Page 3 | Page 4 | Page 5 | All 5 Pages
