Monster waited five days to disclose data breach
By Jim Finkle, Reuters and Rene Millman,
Monster.com took five days to tell users of its website that a security breach resulted in the theft of confidential data from around 1.3 million people, according to an executive of the company.
As reported by IT PRO, Hackers broke into the US online recruitment site's password-protected resume library using credentials stolen from victims using a trojan.
They launched the attack using two servers at a web hosting company in Ukraine and a group of personal computers that the hackers controlled after infecting them with a malicious software program known as Infostealer.Monstres, said Patrick Manzo, vice president of compliance and fraud prevention for Monster.
The company first learned of the problem on 17 August, when investigators with internet security company Symantec told Monster it was under attack, Manzo said.
"In terms of figuring out what the issue was, that was a relatively quick process," he said. "The other issue is you want to make sure exactly what you are dealing with."
His security team spent the weekend investigating, located the rogue servers, and got the Web-hosting company to shut them down some time either late in the evening on 20 August, or early in the morning of 21 August, he said.
Manzo said that based on Monster's review, the information stolen was limited to names, addresses, phone numbers and email addresses, and no other details including bank account numbers were uploaded.
On 21 August, Symantec published a report on its website that said it had found copies of scam e-mails that the engineers of the attack were using, with the aim of getting information that was more valuable than just the names and contact details of Monster.com users.
Pretending to be sent through Monster.com from job recruiters, the emails asked recipients to provide personal financial data, including bank account numbers. They also asked users to click on links that could infect their PCs with malicious software.
Their ultimate goal in taking the data from Monster.com was to gain enough personal information to lower the guards of target victims when they read the emails, said Patrick Martin, a senior product manager with Symantec's response team in Austin, Texas, which first identified the attack.
"It gives these spam emails just a little bit of credibility," Martin said. "These guys were trying to get financial information from people."
It wasn't until Wednesday, a day after Symantec issued the 21 August report, that Monster put a notice on its website warning users they might be the target of email scams.
Monster then announced on Thursday that the details of some 1.3 million job seekers had been stolen. Fewer than 5,000 of those affected are based outside the US, it said in a statement.
A company spokesman said Monster also posted letters to the 1.3 million affected users on Thursday in case the users were wary of opening email from the company after the breach. He said Monster's database has about 73 million resumes.
The security breach comes at a rough time for the company, which in July reported lower-than-expected quarterly earnings.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Apple iPad 3 vs iPad 2 head-to-head review
- Hutchison denies it will pull plug on Three UK
- EMC World 2012: Tucci declares Documentum is here to stay
- ICO: Fines for cookie law breakers
- EMC World 2012: EMC talks up cloud, security and big data
- Dell PowerEdge R820 review
- Sony Vaio T13 Ultrabook review: First look
- BlackBerry 7 OS certified to carry 'Restricted' UK government information
- Facebook floatation marred by Nasdaq glitch
- CIO: Career is over?
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





