Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« If People Aren't Trained The Best Security Will Go For Naught | Main | New Tennessee Law Prohibits Using Federal Individual Taxpayer ID as Proof of Immigration Status »

Web Hackers Fined $15 Million by SEC

I remember reading in an issue of 2600 The Hacker Quarterly magazine several years back about how easy it is to commit crime, without being noticed, by hacking poorly secured web sites.

Hacking is often viewed to be a safe, almost anonymous, type of crime that is often very hard to pin upon one individual.

Well, think again. Electronic actions leave electronic trails in many, many different areas that computer forensics experts, such as my friend Dr. Peter Stephenson, has taught about and written about in many different books and articles, such as in his great book, "Investigating Computer-Related Crime." These trails can lead to the hackers.

Three cybercriminals learned this lesson very vividly this past week.

The U.S. Securities and Exchange Commission (SEC) reported in a May 31, 2007 statement that Oliver Peek must pay restitution of $13 million plus a $1.35 million fine, and co-defendant Lohus Haavel & Viisemann (LHV) must pay a $650,000 fine.

In August 2006, a final judgment was entered against a third defendent, Kristjan Lepik, a former partner of LHV.

The SEC charged that the defendants started hacking into the Business Wire web site starting in January 2005, and over an extended period of time stole over 360 confidential press releases issued by more than 200 companies in order to trade ahead of yet-to-be-made public news.

Wonder what vulnerability, or vulnerabilities, in the Business Wire site allowed for these long-term hacks to take place in the first place? Perhaps it involved an insider? Has Business Wire improved its web site security to help prevent this from happening again?

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/427

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.