• On mySimon: Inside the World of Charm City Cakes
September 28, 2007 2:38 PM PDT

Personal details show up in a recent spam attack

by Robert Vamosi

For this week's Security Watch column and Security Bites podcast, I spoke with Tod Beardsley, lead counter fraud engineer for TippingPoint, a provider of network-based intrusion prevention systems. The column and podcast talk about how social networking can be used for targeted attacks. Toward the end of the interview, I asked Beardsley what was the most interesting case he's worked on in the last six months.

"In the last six months, there was a case involving the Better Business Bureau. This is public. The story there is that the Better Business Bureau keeps these databases of all the complaints they ever get. That's the big sell for them. If I complain to my local Better Business Bureau about some national company, someone else in Spokane, Washington, can reference that, through the Better Business Bureau up there.

"The problem is there wasn't a whole lot of control on these complaint forms. They were accessible over the Internet using a pretty easy brute-force mechanism. So you can get the ID numbers. They're all sequential, they're not random or anything like that. The attack was that a spamming group had enumerated all these complaint forms, and those complaint forms ranged from national corporations to small family practitioners--you know doctor's offices.

"The deal with doctor's offices is that now you run into HIPAA compliance problems because somebody may be complaining about the medication they got prescribed and stuff like that. The interesting part about this is that the attackers were able to correlate the real names with e-mail addresses with particular business complaint numbers.

"What we saw happen was a whole run of spamming campaigns where the victims were identified personally, which hardly ever happens, and information personally about them about a very recent and usually a personally emotional event in their life that was used as kind of a hook for a phishing campaign. 'Come here and log in here and by the way what's your credit card number?' So it ended up being a very effective, very wide-spread, pseudo-spear phishing attack. This is, as far as I know the first time anything on this scale has ever happened."

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Add a Comment (Log in or register)
Solutions abound
by enscorp September 29, 2007 4:21 PM PDT
I heard recently about a startup called SuretyCom who is working on a new communications platform that will make these sorts of attacks impossible. I anxiously await their beta release.
Reply to this comment
How the data is leaked
by drapetomaniac October 1, 2007 7:29 AM PDT
I've detailed how the Better Business Bureau data might be accessed on line. I reported the problem to them last month.

http://tinyurl.com/yrqwnk
Reply to this comment

After 5 years, Firefox faces new challenges

Mozilla helped reshape the Web since releasing Firefox 1.0 five years ago. Now it's got a reawakened Microsoft and Google Chrome to reckon with.

There's a map for that: GPS or smartphone?

Almost every handset comes with mapping software these days, but standalone GPS devices are becoming more affordable than ever.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right