Register

To become a member of ITProPortal Register here.

Already a member? Login here

Please register below. All we need is a valid email address and a password.

Please use a real email address as we need to email you to confirm your account.
Must be at least 6 characters long.

Benefits of joining ITProPortal:

  • Unlimited Access to Special Reports and White Papers
  • Exclusive offers and discounts
  • Free entry to all competitions
  • Access to beta sections of ITProPortal.com

Login to your account



Forgot your password?


Kidnapping your Data : The case of Cyberextortionists

Kidnapping your Data : The case of Cyberextortionists
  • Digg del.icio.us reddit Facebook

Why do people rob banks? According debonair American bank robber Willie Sutton, “because that's where the money is." Cybercriminals think the same way about the enterprise database, and they do not need a gun.

 

The Cyberextortionist Case of Express Scripts


BankThere are different ways cybercriminals can attempt to monetize their theft. In a current case involving St. Louis-based Express Scripts, a breacher is demanding an undisclosed ransom for the company’s data. Express Scripts has put the pressure back on the thief by offering a $1 million dollar reward for his or her capture.

How did Express Scripts find out about the breach? According to its web site, the extortionist sent Express Scripts a letter with a sample of 75 customer records back in October of 2008. The letter also threatened to publicly expose millions of the company’s members’ records if an extortion threat was not met.

Read the Full Story

Lessons Learned

It is unclear which data security policies were in place at Express Scripts. No security system is perfect. As a best practice, this story paints a picture of why organizations can't be proactive enough about assessing data vulnerabilities and monitoring for breaches.

By assessing vulnerabilities, enterprises can see where the security holes exist. You can bet that when a bank robber is looking for the easiest way to rob a bank, he or she looks for the weak spots. A data thief does the same thing. And by monitoring for threats, organizations can be alerted about any breaches as it happens.

As a side note, I wonder where Willie Sutton would focus his efforts today.

Team Applicationsecurityinc

Posted by Team Applicationsecurityinc on 28 Nov. 2008

Application Security, Inc. provides database security solutions for the enterprise and was named to Inc. Magazine's 2007 list of America's Fastest Growing Private Companies (Inc. 500). Its products proactively secure databases and delivers up-to-date database protection that minimizes risk for companies.

Tags: Encryption, Phishing