Atlanta-based SunTrust Bank is the 12th largest bank in the US. They have a major problem, and so do roughly a million and a half of its customers. According to CEO William Rogers, an unidentified employee of the firm printed a vast amount of private customer information, including their names, addresses, phone numbers and account balance information.
Rogers stressed that social security numbers, account numbers, driver’s license numbers, user IDs, and passwords were not exposed. In a recent press release, he had the following to say:
“In conjunction with law enforcement, we discovered that a former employee while employed at SunTrust may have attempted to print information on approximately 1.5 million clients and share this information with a criminal third party.
We and third parties have done forensic analysis on these accounts and we have not identified significant fraudulent activity regarding the effect of the accounts.”
Even so, this is a blow to the company’s image, and the lost trust won’t be easily regained. It also underscores how vulnerable companies are to internal threats.
In response to the attack, SunTrust is offering ongoing IDnotify identity protection (offered through Experian) to all its current and new clients at no cost.
The company’s handling of the issue so far has been about as good as can be expected. The unfortunate reality is that there aren’t many good ways of stopping a rogue employee from making off with sensitive customer data or proprietary company information. Better auditing protocols and controls can help, but only to a certain extent. While those kinds of policies make it easier to detect when an internal theft has occurred, they do nothing to actually prevent them.
This puts management in a tricky spot. Employees have to be trusted with sensitive data in order to do their work, which also increases risk. There aren’t many good solutions here beyond better vetting of employees, but of course, that is by no means a magic bullet either.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Do you do your banking online? If so, there’s bad news in the form of a report recently released by the security firm “Positive Technologies.”
Score one for the good guys. A researcher from BrilliantIT was recently able to figure out how infected computers would connect to EITest’s command and control server, and using that information, was able to bring down their entire network.
Panera Bread company is the latest to find itself in hot water. Recently, security researcher Dylan Houlihan discovered that the company had failed to encrypt (or otherwise protect) a file containing usernames, email addresses, physical addresses, phone numbers and loyalty account numbers for a staggering thirty-seven million of its customers.
The bad news just doesn’t seem to stop where Intel and the Speectre vulnerability are concerned. The latest bit of news comes directly from Intel, as the company admits that it’s just not possible to address the Spectre vulnerability in some of its older hardware. This means that nine families of chips and more than 230 models of computers (mostly manufactured between 2007 and 2011) will remain vulnerable to Spectre forever.
Microsoft recently made small but significant changes to its Office 365 subscription service and to OneDrive, which are often used in tandem. The goal is to make it easier for users whose files have been encrypted by ransomware (or otherwise corrupted) to recover them.
Congratulations to Adobe Flash Player for not being the software most targeted by hackers. Security vendor “Recorded Future” has just published their annual list of the software hackers most commonly focus on when targeting computers and handheld devices for attack.
There are some big changes coming to Facebook, which may have some serious unintended consequences.
Another week, another high-profile data breach. This time, it’s Under Armour in the hot seat. Under Armour acquired the MyFitnessPal app back in February 2015, and the company recently announced that their new acquisition was hacked in late February 2018.
There’s a new type of hacking attack to be concerned with, and it’s growing by leaps and bounds. Called “Crypto-Jacking,” it’s a process by which malicious code is placed on websites. When the sites are visited, the code secretly siphons off a portion of the affected user’s PC, laptop, or smartphone’s processing power and uses it to mine for various cryptocurrencies so that the hackers can profit from it.