Salesforce.com phishing highlights security loophole
By Miya Knights,
Salesforce.com, the on-demand software company, this week admitted it and its customers were targeted by cyber-criminals, prompting security experts to call for extra measures to track potentially risky online behaviour.
In an open letter to customers, the software-as-a-service market leader confirmed it had been the target of a phishing exercise designed to get its end-using customers to divulge sensitive financial information.
It said the compromise occurred when a Salesforce.com employee fell victim of a phishing scam that allowed a Salesforce.com customer contact list to be copied.
"As a result of this, a small number of our customers began receiving bogus emails that looked like salesforce.com invoices," it warned.
Tier-3, the behavioural analysis IT security software specialist took the opportunity of this latest and increasingly sophisticated tactic in the armoury of cyber-criminals coming to light to warn companies of the need to install behavioural analysis software on their systems.
Geoff Sweeney, Tier-3's chief technology officer said: "The fact that the emails are addressed to specific customers and purport to come from Salesforce.com means that the chances of a customer's PC being infected are quite high."
Although the tactic seemed new, he said it capitalised on a classic situation where popularly deployed security technologies can't be relied upon to protect organisations against these types of threats.
"If the companies concerned have real time behavioural analysis software installed on their systems, even if they open the bogus emails, any unauthorised interactions with their PC, including the installation of Trojans other malware and data leakage, could have been locked down," he added.
advertisement
Latest Internet Features
Q&A: DNS inventor Paul Mockapetris
Four months after serious flaws in the internet’s addressing system were proven, its inventor is looking beyond the threats to help bolster web security.
- Q&A: Cuil co-founder Tom Costello
- What does Internet Explorer 8 mean for you?
- Blogging for business
- Social networking in business and branding
- Internet search secrets
- Big IT for CERN's particle smashing experiment
- The saga of Scrabulous
- Q&A: Motorola's enterprise VP John Coon
- IT around the world: Russia
Latest Internet Reviews
Fortinet FortiGate-3810A
Rating: ![]()
advertisement
Latest News Videos in Internet
Video: Q&A with Easynet Connect's Chris Stening
IT PRO spoke to Chris Stening, managing director of Easynet’s SME division, about whether ISPs are giving businesses the service they deserve.
White papers
Want more background on today's hottest IT trends?
Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



Social Bookmark this article: What is this?