LexisNexis and Other Major Data Brokers Hacked By ID Theft Service
gewalker writes "Have we reached the point where it is time to admit that the ID thieves are winning and will continue to win as long as their incentives are sufficient to make it lucrative for them? According to Krebs On Security an analysis of a database pilfered from commercial identity thieves identified breaches in 25 data brokers including the heavyweights Dun and Bradstreet and LexisNexis."
And they had access for months to most of them. From the article: The botnet’s online dashboard for the LexisNexis systems shows that a tiny unauthorized program called nbc.exe was placed on the servers as far back as April 10, 2013, suggesting the intruders have had access to the company’s internal networks for at least the past five months. The program was designed to open an encrypted channel of communications from within LexisNexis’s internal systems to the botnet controller on the public Internet." The companies compromised aggregated data for things like "credit decisions, business-to-business marketing and supply chain management. ... employment background, drug and health screening."
No real excuse for this. This is exactly what network IDS/IPS programs/appliances are for.
Any data center dealing with sensitive information should have an IDS/IPS installation which should have shut down nbc.exe's access out to the Internet, or at least raised a red flag in Splunk or whatever logging console application in use. Most data centers have a list of authorized IPs that internal sites communicate out to, and if some machine communicates to an IP repeatedly on a sensitive network, it would be investigated, or at the minimum, looked at. Multiple machines communicating encrypted data to site out on the Internet is something that IDS applications are designed to detect, and IPS offerings designed to cork until someone takes a look at it.
Security isn't rocket science. It is using basic concepts to compartmentalize information and applications to check for known/unknown attacks, and buying/using the tools needed.
Why do people trust these jokers again?
Why should the likes of Dun & Bradstreet or LexusNexus have any fun at all?
Laughter is the Spackle of the Soul.
Dot exe. I think I see the problem.
This might be a good thing. Once we have a major "privacy apocalypse" and millions of people get screwed over something might be done about it. Otherwise there will just be endless "minor" breeches where a few hundred thousand people get ripped off and no-one really cares.
const int one = 65536; (Silvermoon, Texture.cs)
SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
Lexis Nexis has a database of all united states citizens compete with full address history, SSN, DOB, associations such as relatives and neighbors, and you can cross reference and search the different relationships. They purchase the info from the government and then banks use them to verify information on credit applications by paying for the service and simply accessing a web interface via ssl over the public internet. I know this because I used to work for a large bank doing just that.
Face it, NSA has zero day exploits from the vendors, has a $10 billion budget for hacking and both them and GCHQ using their tools have form on hacking. (See Belgacom and the Belgium foreign minister, oh and Brazil and every network on planet earth....)
If it was April, it was probably NSA.
Remember Stuxnet? The wakeup call from Russian hackers.... except it turned out to be NSA and Israel?
You know I'm right!
This is true. Windows makes a fine desktop. Microsoft's IDE is quite nice.
Windows is not a server operating system, and printing "server" on the box doesn't make it one.
So how do I opt-out? Where do I get away from companies releasing my information to third parties that track my identity or other things to allow other corporations to peruse at their leisure? Not only do you not get to tell companies where they can and can't store your personal information, you also can't dispute that information when someone uses it for the wrong reasons or enters things that you're not allowed to know about.
For example, let's say LexisNexis had an entry that said I caused a major auto accident involving 15 cars, because an insurance clerk pressed the wrong button that said I was at fault rather than being involved in the accident? How do I correct that data? How do I dispute that entry? How do I even find out about that information?
And how do I get them to delete my personal data rather than allowing their poor network security policies to expose my life to risk? Answer: I can't. I have no agreement with them to host my personal data. I'm not just upset about the breach, I'm upset about the lack of ownership and consequence of such regarding my own life.
Seems like the only way to combat identity theft now is just "loose" your credit card every few months and get a new number. I don't see any other way to mitigate identity theft as long as places like Heartland Payment Systems and LexisNexis are going to just give away the keys to the kingdom through gross negligence, apathy or ignorance.
Join the Slashcott! Feb 10 thru Feb 17!
This should have been easy to catch with their IPS. Why is their an encrypted data stream going from a server to a server outside the organization? Even without using an SSL decryption device to look at the contents of the stream, the mere fact that an encrypted stream of data was going to an unauthorized destination should have set off alarm bells by it's own right.
I've seen any number of environments that simply blocked encrypted data sessions until they had been white-listed. It's something that ought to be in your change management system along with all of your other firewall rules. The fact that a major credit agency got owned by this tells me that they probably outsourced their security to India along with the rest of their staff.
Let's stop calling it that. These numbers we call our identity is not our identity. The whole notion of doing things like this were an invention of mega-business interests who wanted to expand their business range without having to employ a whole bunch of people. You see, long ago, people were given credit by a process which involved references... actual people who could vouch for your reputation. But this is too much of a hassle and involves the use of people and people, of course, are very expensive. So much better to track a whole bunch of people with a computer system where they are tagged with a unique number -- say a social security number which we were promised would never ever ever be used for anything but social security account tracking. Several legal filings surrounded the controversy long ago but the serfs of the USA lost out and here we are.
Stop feeding the machine. Stop being in debt. Stop relying on credit and build a savings instead. It's harder to get started if you're already accustomed to the debt financing game, but it's the difference between LIFO and FIFO where your money is concerned. Stop spending money you don't have. Of course, this message goes out to people who aren't reading this... everyone here has "good reasons" for using credit instead of cash.
How would it be easy to identify a single SSL stream coming form a server with hundreds/thousands/millions or other SSL streams flowing in and out.
Just because you operate in a walled garden with 10 users doesn't mean the rest of us do. The few external servers presently active on my screen are showing 3,124 active SSL connections. How easily could you tell me which one is bad? Those external servers in turn connect to myriad internal systems. Being careful and thorough in your security is not easy! It's especially difficult for national or multinational companies with tens of thousands of employees and remote workers, servers, workstations, hundreds/thousands of partners, millions of customers, hundreds of points of presence...
Easy? My ass!
Identity can be stolen and you can be seriously and negatively impacted by that theft, even if you have no debt and no need for credit.
When some fuck steals your identity and racks up huge debt in your name, the creditors come for you! You must then defend against the creditors and it is not an easy fight at all. In many cases you cannot win, despite have done nothing wrong!
You're right that it is a contrivance of the large corporations, but the individual cannot simply choose to not participate. If an individual is impersonated, it can have severe repercussions through absolutely no fault of their own.
My guess: 'nbc' here is short for "NSA Botnet Communicator."
Then again, it might never have been found if they'd been smart enough to name it "svhcost.exe" [sic] or "winupdate475YWHV63275278592,bat"
https://app.box.com/WitthoftResume Code: https://github.com/cellocgw
The NSA has left a serious hole called Microcode in all our CPU's. The NSA has demanded and caused to be built deterministic methods of cracking our encryptions such as PGP and Eliptical Curve. The worm isn't the criminals who steal us. They are merely using the holes that the US Government under the NSA demanded be built into our security frameworks. When will they be tried for being accomplice to the crimes!?
If you were making a hiring decision or evaluating a stranger for some other sort of relationship that might make you financially, legally or physically vulnerable to their misbehavior, would you pass up credit reports and other background checks, flawed as they are?
Is why does LexisNexis, which has been around since at least the 1970's, trust the use of Microsoft Windows to their server infrastructure. Sounds like they really dropped the ball here. Hopefully heads will roll on this one.
The profits gets smaller per unit but bigger trough the aggregation. Process started after first farmer noticed that it can skim cream off of milk and it still had milk but he also had butter. The process get complex and sophisticated - we have now skimmers being corporations controlled by skimmers i.e. CEOs that skim corporations and shareholders alike. It is not all that bad tho - I have now pr0n served from the cloud for free that I would have to spend thousands on if I wanted to purchase the dvds. I see progress there. I just have to resist of requests by hot women from intrantes - come to think of it had Turing had a chance too look at the xxx and dating pages he would probably invent a bit more difficult tests for bots....