Second attack on Monster website discovered
By Rene Millman,
The attack on job website Monster.com has left more than 1.3 million users of the site open to identity theft. Monster's chief executive admitted that a second hack of the site went unnoticed.
Sal Iannuzzi said that further investigations by the company unearthed the second hit and said that the company had no idea how much information had been taken during the cyber onslaught or how many times the database had been accessed by criminals.
"We are assuming that it is a large number," he told Reuters. "It could easily be in the millions."
The company is promising to invest £40 to £50 million in traffic monitoring equipment to detect such breaches, but admitted that the website may never be safe.
"I want to be clear and I want to be frank: there is no guaranteed fix," Iannuzzi said. "I wish I could say there will be absolutely no way that the Monster site can be compromised. I cannot ever make that promise, and no internet company can."
While the information stolen from the site can't be used to siphon off money from victims it can be used in social engineering scams in order to get such sensitive financial information directly from the victim.
There have already been cases reported on the internet of phishing gangs sending out emails pretending to be recruitment companies asking for bank details within fake job application forms. The false emails also harbour malware designed to compromise a victim's computer and turn it into part of a botnet.
As reported by IT PRO, Monster had known about the attack five days before it went public with the breach. Around 73 million CVs are held on the website's database, but Iannuzzi claimed that only a handful of accounts were cancelled by users and employers.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Apple iPad 3 vs iPad 2 head-to-head review
- Hutchison denies it will pull plug on Three UK
- EMC World 2012: Tucci declares Documentum is here to stay
- ICO: Fines for cookie law breakers
- EMC World 2012: EMC talks up cloud, security and big data
- Dell PowerEdge R820 review
- Sony Vaio T13 Ultrabook review: First look
- BlackBerry 7 OS certified to carry 'Restricted' UK government information
- Facebook floatation marred by Nasdaq glitch
- CIO: Career is over?
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





