June 11, 2008 5:46 AM PDT

Reports examine causes, victims of data breaches

On Wednesday, Verizon Business released a four-year study concluding that 9 out of 10 corporate data breaches could have been prevented, had appropriate security measures been taken. The Verizon report includes the results of more than 500 forensic investigations, including three of the largest data breaches ever reported.

Meanwhile, the Identity Theft Resource Center released its 2007 report on identity theft, offering comparisons to data it's collected over the last five years.

Verizon found that 73 percent of the data breaches were the result of outside sources, with only 18 percent from insider threats. Of the outside sources, 39 percent were attributed to business partners. Third parties, not victimized organizations, discovered 75 percent of the breaches.

Attack methods vary around the world, Verizon found. Attacks from Asia, China and Vietnam in particular, often involve application exploits. Attacks from the Middle East involve site defacements. And attacks from Eastern Europe and Russia involve point-of-sale compromises.

The ITRC report looks at the other side: the impact of identity fraud on its victims. In 2007, 57 percent of stolen information was used to open a new line of credit, while 13 percent was used to order cable and or other utility services.

Eighty-two percent of the victims learned of the theft through creditors or collection agencies, up from 76 percent a year ago. Only 10 percent found out through proactive measures, with 8 percent identifying something on their credit reports.

More disturbing, 62 percent of the respondents to the ITRC survey reported that thieves had committed crimes, such that warrants were issued in the victim's name.

Recent posts from Defense in Depth
Column: Raising Cain at Black Hat
Black Hat 2008: Notes from the field
Column: Finally, ID fraud protection that works
Column: Will you be ditching your antivirus app anytime soon?
A real simple answer to password protection
Add a Comment (Log in or register) 4 comments
by Lerianis June 11, 2008 7:51 AM PDT
The biggest problem with identity theft online or offline is that some people are stupid: leaving their personal information out in the open where anyone can get to it.
There is also the bigger problem in our society of using our Social Security numbers as 'catch-all personal identification numbers'.
Reply to this comment
by BenjaminWright June 12, 2008 7:53 AM PDT
Robert: Legally speaking, what is "reasonable security?" FTC fined TJX for not having it, but I disagree. Verizon says 9 of 10 data breaches could have been avoided if reasonable security were present. That implies 9 in 10 breach victims were in violation of law. The study's outlook is that the solution to identity theft is locking down corporate data. But a security consultant/solution provider like this Verizon unit naturally sets a high bar for what is reasonable. And when Verizon evaluates whether reasonable security could have prevented a break-in, it does so with the benefit of hindsight. Yet the study goes on to say that in modern systems knowing where all your data reside is "an extremely complex challenge." In other words, the shere problem of keeping up with the location of data (so you can apply security) is very expensive, and mistakes by data-holders who act in good faith are easy. The reasonable measures expected by FTC and Verizon are extravagantly hard to implement in practice. Hence, the portion of incidents preventable by FTC/Verizon's reasonable procedures is much lower than 90%. We need to focus more attention on other solutions to identity theft. --Ben http://hack-igations.blogspot.com/2008/03/ftc-treats-tjx-unfairly.html
Reply to this comment
by christophercnd June 12, 2008 5:50 PM PDT
LOL - so it took Verizon 4-years to discover that hindsight shows you
how to protect yourself? Man - I want *that* dudes job!!!

It's quite bothering though - what's with the 10% who, even with
hindsight, couldn't have fixed the problem?

And what about the "Application Exploit" attacks? He knows how to\
can figure out what an "appropriate security measure" is to
protect me against a buffer overflow mistake that nobody knows about
yet?? Why doesn't he do something useful with his talent, like
buy lottery tickets. If I could see the future, I wouldn't waste my time
doing security reports!!!

Cool - not only does he get 4 years pay to fartarse around doing what
he likes, he even eventually spews forth drivel, and still nobody
seems to notice...
Reply to this comment
by johnfranks1234 June 24, 2008 6:30 AM PDT
An excellent and timely article: It's amazing that breaches and thefts keep happening. There is something that is helping a lot of people, judging by the business blogs I?ve been reading. It?s a defined eCulture called "The Business-Technology Weave" - it helps to influence employee behaviour as regards security, use and integrity of data - as well as protection of hard assets (such as laptops). The book ?I.T. Wars? is the leading voice, and concentrates on the solution ? a proactive treatment and training of people, and reinforcements to their corresponding security awareness. This is particularly relevant: www.businessforum.com/DScott_02.html . Some good stuff here too: www.david-scott.net . We use his book at work - stupid mistakes like deleted and misplaced data have dropped tremendously. Our CEO even requires our vendors to read it.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

Featured blogs

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Google-focused satellite enters orbit

    The search titan has exclusive rights among online mapping sites to images from the new GeoEye-1 satellite, which launched Saturday.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crossfade

    The Standard, 'A Different Skin': Free MP3 of the Day

    Eschewing the danceable beats favored by many of its post-punk brethren, while opting instead for more ominous and insistent rhythms, is what makes the Standard visceral and engaging. Download a free MP3 of "A Different Skin" courtesy of CNET Download Mus

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.