HOME     MENU     SEARCH     NEWSLETTER    
NEWS & INFORMATION FOR TECHNOLOGY PURCHASERS. UPDATED 5 MINUTES AGO.
You are here: Home / Network Security / Huge Hack Hits Vodafone Customer Data
Neustar, Inc.
Protect your website & network using real-time information & analysis
www.neustar.biz
Massive Hack on Vodafone Germany Affects 2 Million Users
Massive Hack on Vodafone Germany Affects 2 Million Users
By Jennifer LeClaire / NewsFactor Network Like this on Facebook Tweet this Link thison Linkedin Link this on Google Plus
PUBLISHED:
SEPTEMBER
12
2013



The personal details of about 2 million Vodafone Germany customers have been exposed in a hack that's making international headlines. According to the company, hackers tapped into an information pool of addresses, bank account numbers and dates of birth.

"Vodafone Germany has world-class security systems that are constantly updated and upgraded to block new emerging threats. However, this attack was highly complex and conducted with inside knowledge of our most secure internal systems," the company said in a statement.

"As soon as we discovered the incident we took all necessary steps to stop the attack, minimize any adverse impact for our customers and notify all relevant German authorities," company officials said. "We are sending our sincere apologies to everyone affected for any disruption caused."

We're All in Danger

We caught up with Chester Wisniewski, a senior security advisor at Sophos, to get his analysis on the latest breach. He told us whenever personally identifiable information is purloined by online criminals, it increases the risk to the victims, despite what the vendor might claim.

"This advice doesn't just apply to the two million who we know had their information stolen. It applies to everyone, all the time. Many criminals might try to use this information offline as well as online, so be cautious of any suspicious activity, like incoming phone calls claiming to be your bank," he added.

On-Premise Security Fails

We also asked Kevin O'Brien, an enterprise solution architect at CloudLock, for reaction to the Vodafone hack. He told us it reveals as yet another example of how and why on-premise data security models have failed to keep up with an increasingly interconnected world: Servers that contain critical data, such as personally identifiable information that was stolen in the Vodafone hack, should not be accessible on the public Internet.

"The problem is that organizations cannot keep up with the ever-changing set of vulnerabilities, patches, and zero-day exploits that leave this kind of information at risk," O'Brien said. "While we don't yet know the details of how this particular server was compromised, it is fair to guess that a known issue was used to gain access -- an outdated version of either the OS or some piece of software running on the system, through which the attacker was able to gain adequate permissions to read and ultimately get away with high-value information." (continued...)

1  2  Next Page >

Tell Us What You Think
Comment:

Name:

Charles:
Posted: 2013-09-17 @ 5:36am PT
Disappointing that you didn't do any fact checking on this article and allowed a vendor to take control of the article. Now the article is an advertisement for cloud storage - but that wasn't the issue on this compromise. It was an outsourced admin who did the damage. He would have had access to cloud storage too. Privileged users simply shouldn't have access to data. They don't need it to do their jobs. Even more so in the cloud. Cloud is great and has its place - just not relevant to this story.

Like Us on FacebookFollow Us on Twitter
TOP STORIES NOW
MAY INTEREST YOU
ISACA® offers a global community of more than 115,000 IS/IT constituents in over 180 countries. We develop and deliver industry-leading certifications, education, research and business frameworks. We equip individuals to be leaders in the fast-changing world of information systems and IT - Learn More>
MORE IN NETWORK SECURITY
Product Information and Resources for Technology You Can Use To Boost Your Business

NETWORK SECURITY SPOTLIGHT
Sony is no stranger to breaches. Sony’s PlayStation Network was hacked in 2011 and attackers obtained 77 million user accounts. The latest attack comes against Sony Pictures Entertainment.

ENTERPRISE HARDWARE SPOTLIGHT
Chinese computer maker Lenovo got creative with the marketing campaign around its Yoga 3 Pro. Lenovo hired the Upright Citizens Brigade, a comic troupe, to help drum up visibility for its new device.

MOBILE TECHNOLOGY SPOTLIGHT
In its bid for the wearables market, Sony is reportedly developing a watch made out of electronic paper for release as soon as next year. The e-paper watch will emphasize style over tech innovations.

© Copyright 2014 NewsFactor Network, Inc. All rights reserved. Member of Accuserve Ad Network.