US government website hit by Monster breach
By Reuters,
About 146,000 users of a US government jobs website had their personal information stolen by cybercriminals who hacked into computers at Monster, according to a government spokesman.
The theft on the USAjobs.gov site, which has about 2 million users, was part of a hacking operation apparently run out of Ukraine that Monster disclosed last week, said Peter Graves, a spokesman for the US Office of Personnel Management.
Monster runs the site on behalf of the government.
On Wednesday, the government temporarily restricted recruiters from accessing the database until Monster completes efforts to ensure its computer system is secure, Graves said.
"We disabled it yesterday as an extra precaution on our part to best protect our users," he said by telephone late on Thursday.
He said the government expected to restore that access by Friday.
The information stolen from the USAjobs.gov database included names, mailing addresses, phone numbers and email addresses. Social security numbers, which are encrypted in the database, were not compromised, Graves said.
The government found out the site had been compromised on 20 July, when a subscriber submitted what appeared to be a fraudulent email, Graves said.
Officials with the US agency immediately passed the information on to Monster, the government spokesman said.
That appeared to differ from an earlier statement from Monster Worldwide. Chief Executive Sal Iannuzzi said on Wednesday that the company only learned that its systems might have been compromised on 18 August, when researchers with security company Symantec notified it of the matter.
Officials with Monster could not be reached for comment on Thursday.
A Symantec response team in Austin, Texas, had found that the hackers had managed to get unsuspecting PC users to download malicious software on to their computers so that the culprits could gain control of their PCs.
Such software is generally distributed via spam email attachments and by compromised websites. When users open those attachments or click on links on those sites, their PCs become infected.
From a command and control centre hosted on a server at a web hosting company in Ukraine, the thieves took control of those PCs and used them to access Monster's site using stolen credentials of job recruiters. The malicious software then sent the information to a second server in Ukraine, which Monster said was shut down on about 23 August.
The hackers' ultimate goal was to launch so-called phishing attacks on the job seekers whose data was taken, according to Monster and Symantec. In such schemes, hackers use the stolen data to persuade their targets to provide financial information or download malicious software.
In the case of the Monster theft, these fraudulent emails were sent by people purporting to be job recruiters.
What makes phishing schemes particularly damaging, compared with other scams over the centuries, is that, through the internet, criminals have quick access to millions of targets and an easier time evading justice.
It was not till Wednesday that Monster notified the US jobs agency how much data had been stolen from the USAjobs database, Graves said. "We didn't know the extent," he said. "We learned the extent yesterday."
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
Do British police get cyber security?
Davey Winder listens to telephone conversations between the FBI and the Metropolitan Police, courtesy of Anonymous, and isn't impressed.
- Who to trust after the VeriSign hack?
- Striving to solve the security skills crisis
- Would you employ a hacker or malware writer?
- Q&A: Raj Samani, CTO McAfee
- Erase and rewind: the EU and privacy
- My email address is [CENSORED]
- Is there such a thing as a secure tablet?
- 2011: The year in news
- BYOD: Old or new, good or bad?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Ubuntu vs. Windows 7 on the business desktop
- York researchers heat storage to speed up data
- BlackBerry Bold 9790 review
- OneNote hits Google?s Android
- O2 trials Olympic-scale remote working
- Will someone rid me of these troublesome Macs?
- Lenovo beats expectations again
- Who to trust after the VeriSign hack?
- Google to promise fairness after Motorola buy
- Report: Google cloud storage coming soon
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





