top Ad Widget

Collapse

Announcement

Collapse
No announcement yet.

Nearly 400,000 Credit Cards Exposed in South Carolina Breach

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Nearly 400,000 Credit Cards Exposed in South Carolina Breach

    Monday, October 29, 2012

    An estimated 387,000 credit cards and 3.6 million Social Security numbers have been exposed after the breach of a server holding taxpayer and card information for South Carolina residents.

    Officials with the state's Department of Revenue confirmed the breach and the fact that, of the credit cards, 16,000 were stored without encryption. State Law Enforcement Division Chief Mark Keel said during a press conference late Friday that the investigation so far had revealed the breach occurred as early as August 27, and had confirmed that the IP address through which the attack originated was foreign.

    With the investigation ongoing, Keel said "no further information regarding specifics of the investigation will be released at this time," as the disclosure of more information could hinder efforts to bring the hacker to justice.

    South Carolina Gov. Nikki Haley appointed Inspector General Patrick Maley to examine the state's information security measures. The first move will be to establish a full time task force to examine each of the state's systems.

    Haley stated that she wants the person held accountable for their actions, and "slammed against the wall."

    "It's no longer about just inside hackers, it's about international hackers," she said. "Our state will respond with a big, large-scale plan that is somewhat unprecedented, to take care of this problem."

    As part of the response, independent information security company Mandiant was hired to provide advice on how to proceed. Mandiant Director Marshall Heilman said that its first steps were to remove the attacker's known access, deter the attack with additional security measures and enhance the systems' logging to enable law enforcement to detect if the attacker returned.

    By Darren Waggoner


    This website is for sale! collectionscreditrisk.com is your first and best source for all of the information you’re looking for. From general topics to more of what you would expect to find here, collectionscreditrisk.com has it all. We hope you find what you are searching for!
    All information contained in this post is for informational and amusement purposes only.
    Bankruptcy is a process, not an event.......

    #2
    Lazy IT policies should probably be criminal

    We now live in a time where the negligence or oversight of one or a few individuals can expose millions of people to financial risk. Until we start to institute stiff penalties on the organizations and individuals who mismanage our data, we're going to continue to see these types of breaches. With the amount of money that these organizations, including state and federal agencies, go through, you'd think we'd at least spend some cash on an IT audit to identify these types of lax security measures. I mean, tens of thousands of credit card numbers un-encrypted? That's insane.

    Comment

    bottom Ad Widget

    Collapse
    Working...
    X