Big_Bear
10 years ago
Acer online store hacked: Customers' credit card details and private data exposed

= = = = = = = = = =

Taiwanese consumer electronics manufacturer Acer has revealed that its US online store Acer.com has suffered a data breach that potentially could have affected every single customer who accessed the website over the past 12 months.

Acer has sent a letter informing all users of its online store in the US that they have might have had their names, addresses, payment card numbers, card expiry dates and card security CCV three digit numbers comprised if they accessed the website between 12 May 2015 and 28 April 2016.

The firm is not revealing how many users have been impacted by the data breach, but it says that following an investigation by its staff and a team of outside cybersecurity experts, it can confirm that no evidence was found of the attackers gaining access to user login credentials like usernames and passwords.

= = = = = = = = = =

http://www.msn.com/en-us/money/technology/acer-online-store-hacked-customers-credit-card-details-and-private-data-exposed/ar-AAhitcR?ocid=ansmsnmoney11 


= = =

"it can confirm that no evidence was found of the attackers gaining access to user login credentials like usernames and passwords."

The FTC said that years ago. In a legal brief against a very popular idtheft company, the FTC said that id theft cannot be detected nor prevented.


.
Big_Bear
10 years ago
GoToMyPC hit with hack attack; users need to reset passwords

= = = = = = = = = =

If you use Citrix’s GoToMyPC remote desktop access service, you need to change your password. According to a post published to GoToMyPC’s system status page, the service experienced a hack attack this weekend, and it’s now requiring all users to reset their passwords before logging in to the service.

“Unfortunately, the GoToMYPC service has been targeted by a very sophisticated password attack,” the update reads. “To protect you, the security team recommended that we reset all customer passwords immediately.”

According to GoToMyPC, it wasn’t immediately clear that it was experiencing an attack: On Saturday, users reported being unable to log into their accounts, and were being forced to reset their password. Several hours later, GoToMyPC warned users of the attack.

= = = = = = = = = =

http://www.pcworld.com/article/3085434/security/gotomypc-hit-with-hack-attack-users-need-to-reset-passwords.html 
Big_Bear
10 years ago

The Chinese government likely hacked computers at the Federal Deposit Insurance Corporation in 2010, 2011 and 2013, according a congressional report on Wednesday that cited an internal investigation by the banking regulator.

"Even the former Chairwoman's computer had been hacked by a foreign government, likely the Chinese," staff at the U.S. House of Representatives Committee on Science, Space and Technology said in the report.

The Chinese Embassy in Washington did not have immediate comment on the allegations.

China has long been a prolific hacking adversary for the United States, although intelligence officials believe Beijing has decreased its hacking activity since signing a pledge with Washington last September to refrain from breaking into computer systems for the purposes of commercial espionage.

The congressional report provided the latest example of how deeply Beijing has penetrated U.S. government computers.

- - - - -

http://www.msn.com/en-us/money/markets/china-likely-hacked-us-banking-regulator-report-finds/ar-BBuiu7c?ocid=ansmsnnews11 
gmelhaff
10 years ago
Anyone had their credit card number stolen just after using cigarbid.com? Its the only place I'd used my card for awhile and the only site that had it stored at their site and then the other day my CC company notified me that someone in Turkey was racking up charges on it. Could be cigarbid.com got hacked and they don't know it.
Big_Bear
10 years ago
Interesting post.

The FTC said that id theft can't be detected so we don't know. I am sure that CigarBid uses the best technology they have available to them. But frankly that wouldn't matter because the FTC also said that id theft can't be prevented. If you think CBid's systems are more robust than the FDIC systems (see thread before yours) then I wouldn't worry much.

It's interesting that the article above was posted recently (07/13/2016), but it was reporting on hacks that happened 3, 5, and 6 years ago. It sometimes takes awhile fore the hacked info to be used.

Sometimes folks will tell me that they haven't been affected by hackers. I ask them "How do you know?"

The fact is that the vast majority of the people on this forum have had their personal info compromised. But they won't find out about it for a year or two from now.





.
DrafterX
10 years ago
Wow.. clean-up on isle 4... talk about potential reputation damage... 🤔
Big_Bear
10 years ago
To be clear, I'm not saying that most of us have had our personal identification compromised BECAUSE we are active in this forum. I'm saying it because your odds of having your identity stolen is 1 in 30 (children it's 1 in 10). Some people have their info"out there" but no one is using it to impersonate them. Having your info "out there" is not the same as identity theft.

Compromised - someone has your identifying data

Identity theft - someone uses that data to impersonate you.

So more than 1 in thirty have their identifying info compromised. And I'm comfortable guessing that, in light of the numbers of high-level high-government secured servers hacked (almost weekly), the vast majority of us have our info "out there."

I've had my LinkedIn account compromised. So far, to my knowledge, no person is using the info to say they're me.

https://haveibeenpwned.com/  and enter your e-mail address. It will check databases of breached content to see if you've been compromised.

It's free.



.
10 years ago

Anyone had their credit card number stolen just after using cigarbid.com? Its the only place I'd used my card for awhile and the only site that had it stored at their site and then the other day my CC company notified me that someone in Turkey was racking up charges on it. Could be cigarbid.com got hacked and they don't know it.

gmelhaff wrote:



PM sent Gmelhaff
Big_Bear
10 years ago
The Morning Download: Bitcoin Hack Underscores Persistent Challenge of Securing Digital Currency

By Steve Rosenbush | Aug 3, 2016 8:01 am ET

Good morning. Bitfinex, the Hong Kong-based exchange where bitcoin is traded, said it was hacked, sending the price of the digital currency lower, the WSJ reports. The possible theft of $65 million in bitcoin follows the $60 million theft in June of rival digital currency ethereum, which together constitute something of a digital currency crime wave. “Securing the bitcoin trading platform has proved elusive,” the WSJ notes.

There’s plenty of incentive to close the security problems, given that blockchain, the underlying technology, can make markets more efficient by removing the middleman. (See our CIO Explainer: What Is Blockchain?) International Business Machines Corp. said it is using blockchain to resolve customer disputes, as CIO Journal reported.

Perhaps it’s unreasonable to expect digital technology to eliminate crime as we know it. But there’s something uniquely disarming about the risk of theft in cyberspace, where vulnerabilities can appear to be more systemic in nature.




= = = = = = = = = = = = = = = = = = = =

http://blogs.wsj.com/cio/2016/08/03/the-morning-download-bitcoin-hack-underscores-persistent-challenge-of-securing-digital-currency/ 





- - -

Anybody using ApplePay or PayPal?


.
Big_Bear
10 years ago
Reporters at New York Times, other U.S. media, hacked - CNN

http://www.msn.com/en-us/news/us/reporters-at-new-york-times-other-us-media-hacked-cnn/ar-BBvYeqD?OCID=ansmsnnews11 

WASHINGTON, Aug 23 (Reuters) - The FBI and other U.S. security agencies are investigating cyber breaches targeting reporters at the New York Times and other U.S. news organizations that are thought to have been carried out by hackers working for Russian intelligence, CNN reported on Tuesday, citing unnamed U.S. officials.

"Investigators so far believe that Russian intelligence is likely behind the attacks and that Russian hackers are targeting news organizations as part of a broader series of hacks that also have focused on Democratic Party organizations, the officials said," CNN said.

Reuters could not immediately confirm the report. The FBI declined to comment, and representatives for the U.S. Secret Service, which has a role in protecting the country from cyber crime, did not immediately reply to a request for comment.

The intrusions were detected in recent months, according to CNN. Citing the U.S. officials, it said the Times had hired private security investigators to work with national security officials in assessing the breach.

Representatives for the Times could not be immediately reached for comment.






.
Mr. Jones
10 years ago
I recently got a very small car loan to buy a
Used car...
Lifelock never even called me to check if it was legit...
The only time I hear from them is 3-4 times a year when they say everything is ok...
But they always tell me when I get billed
$99.00 per year for the service.

Big bear, what company-nies? Do you like or use?

I know you have mentioned a few,
But can you
Refresh their names again...
And yearly fees?

Thanks,
Mr. Jones
Covfireman
10 years ago
Depending on who your homeowners insurer is some of those have coverage for it and their coverage is alot broader than these specialty companies like life lock .


Why worr about it just keep a few identities. If one gets to dirty change to a new one . Never use your own identity then it can't be stolen
Big_Bear
9 years ago
Report: Yahoo may confirm massive data breach

SAN FRANCISCO — Internet portal and search firm Yahoo may confirm this week a massive data breach that exposed information about tens of millions of its users, according to the technology news website Recode.

The confirmation would follow a Yahoo investigation into claims that surfaced in early August that a hacker using the name "Peace" was trying to sell the usernames, passwords and dates of birth of Yahoo account users on the dark web — a black market of thousands of secret websites.

A Yahoo representative was not immediately available to comment on the report.

The breach may affect up to 200 million user accounts, Recode reported.

= = = = = = = = = = = = = = = = = = = = =


http://www.usatoday.com/story/tech/2016/09/22/report-yahoo-may-confirm-massive-data-breach/90824934/ 




.
Big_Bear
9 years ago
Arrested Russian linked to theft of 117 million LinkedIn passwords

▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃

A Russian citizen arrested in Prague was wanted in connection to the theft of 117 million LinkedIn passwords and login credentials, the social networking firm confirmed.

"Following the 2012 breach of LinkedIn member information, we have remained actively involved with the FBI's case to pursue those responsible," LinkedIn said in a statement. "We are thankful for the hard work and dedication of the FBI in its efforts to locate and capture the parties believed to be responsible for this criminal activity."

Czech police, who announced the Russian's arrest on Wednesday, said that he was wanted by the FBI on suspicion of hacking U.S. targets. Interpol had also issued a international warrant -- or "red notice" -- for his arrest.

▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃



http://money.cnn.com/2016/10/20/technology/russian-hacker-arrested-linkedin-password/index.html 





.
Big_Bear
9 years ago
Suspected JP Morgan hacker arrested after returning from Moscow

NEW YORK -- A U.S. citizen living in Moscow was arrested Wednesday after he flew to the United States to surrender to face charges he stole contact information for over 100 million customers of U.S. financial institutions, brokerage firms and financial news publishers, authorities said.

Joshua Samuel Aaron, 32, was arrested at Kennedy Airport on Wednesday. He pleaded not guilty to a 22-count indictment charging him with conspiracy, computer hacking, securities fraud and wire fraud, among other charges.

▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃▃

http://www.cbsnews.com/news/joshua-samuel-aaron-suspected-jp-morgan-hacker-arrested-after-returning-from-moscow/ 



.
Big_Bear
9 years ago
So by now most of us are pretty comfortable when we see the word "hacked" in the news.

Back when fender started this thread, incidents were few and far between. Nowadays you can't use a search engine without cybersecurity being in the headlines.

It seems to be the new normal.

If you're reading this you've very likely been hacked (although your identity may not have been stolen yet).

Since I'm in the business, I often get asked about some basic steps that people should consider.

Some of my advice can't be posted because of forum rules.

If you'd like to find out more you can e-mail me at [email protected]

Please don't PM me. That's a really awkward system and a PITA to use.

Hope this helps!



.
Big_Bear
9 years ago
QuestDiagnostics
3 Giralda Farms
Madison, New Jersey 07940

December 12, 2016

[Patient Name]
[Patient Address line one]
[Patient Address line two]

Dear [Patient Name]:

Quest Diagnostics regrets to notify you of a breach of your Protected Health Information (PHI) which we became aware of on November 28, 2016. Here are the details of the breach:

On November 26th an unauthorized third party accessed the MyQuest by Care360® internet application and obtained PHI of approximately 34,000 patients. The data included name, date of birth, lab results, and, in some instances, telephone numbers.

The affected information did not include Social Security numbers, credit card information, insurance or other financial information.

When the intrusion was discovered, we immediately took steps to stop any further unauthorized activity. We are taking steps to prevent similar incidents from happening in the future, and are working with a leading cybersecurity firm to assist with our investigation and to further evaluate our systems. We have also reported the incident to federal law enforcement authorities.

Quest Diagnostics has no evidence that any information has been misused in any way, so we do not believe that you need to take any steps at this time to protect yourself in response to this breach.

We sincerely apologize for this breach of your information. We have established a dedicated toll free number for you to call if you have any questions regarding this incident. The number is (888) 320-9970 and can be reached Monday through Friday, between 9:00 a.m. and 7:00 p.m. Eastern Time.

Sincerely,
Carl A. Landorno
Executive Director, Compliance Operations & Privacy Officer

= = = = = = =

from wikipedia
https://en.wikipedia.org/wiki/Quest_Diagnostics 

Quest Diagnostics Incorporated is a Fortune 500 company providing clinical laboratory services with headquarters in Madison, New Jersey. Founded in 1967 as Metropolitan Pathology Laboratory, Inc., it became an independent corporation with the Quest name on December 31, 1996. In addition to the United States, Quest Diagnostics also runs operations in United Kingdom, Mexico, Brazil, Puerto Rico and a laboratory in India and also has collaborative agreements internationally with various hospitals and clinics. It is a member of the Fortune 500 and the S&P 500, with corporate headquarters located in Madison, New Jersey. The company has approximately 44,000 employees, generates more than $7 billion in revenue and offers access to diagnostic testing services for cancer, cardiovascular disease, infectious disease and neurological disorders.


= = = = = = =

This begs a lot of questions.






.

Big_Bear
9 years ago
This is in follow up to #113 above:

Yahoo says one billion accounts exposed in newly discovered security breach

= = = = = = =

By Jim Finkle and Anya George Tharakan

(Reuters) - Yahoo Inc warned on Wednesday that it had uncovered yet another massive cyber attack, saying data from more than 1 billion user accounts was compromised in August 2013, making it the largest breach in history.

The number of affected accounts was double the number implicated in a 2014 breach that the internet company disclosed in September and blamed on hackers working on behalf of a government. News of that attack, which affected at least 500 million accounts, prompted Verizon Communication Inc to say in October that it might withdraw from an agreement to buy Yahoo's core internet business for $4.83 billion.


http://finance.yahoo.com/news/yahoo-says-1-billion-accounts-002200349.html 




.
delta1
9 years ago
I've had three credit card accounts jacked this past year...could be worse...didn't lose anything but time and aggravation having to close accounts, fill out affidavits, open new accounts.
deadeyedick
9 years ago
I was just notified that my card was used for two $50 charges for phone calls from a prison in Alabama. Iff'n it was Cali I would blame MACS.
Users browsing this topic