Outsourcing aids many data thefts, Verizon says, HFR, TEC

By Anonymous  Add a new comment

NEW YORK (AP) _ The reliance of restaurant chains and retail stores on outside companies to handle credit-card processing and other information-technology functions is partly to blame for a rash of consumer data breaches over the last few years, according to data sleuths at Verizon Communications Inc.

Even a chain with thousands of restaurants might have only 100 employees in information technology, so it uses outside vendors for many IT functions, said Bryan Sartin, director of the investigative response team at Verizon Business.

"What happens is there's a lack of accountability on the third party," Sartin said.

Verizon's unit investigates a quarter to a third of the big, publicly announced data breaches that occur each year, and hundreds of smaller cases.

In recent years, restaurant and retail businesses have accounted for more than half of Verizon's 230 to 250 cases per year, according to a report Verizon was set to issue Thursday. It often finds that insiders at service vendors are part of the heists.

Organized data-stealing gangs "go to the call centers, the Web development companies, the content development companies, the business partners, the people who pick up the backup tapes," Sartin said. "They say ... if you hate your boss and you're in financial straits, we're your solution. Give us access to your customers. Better yet, give us your data."

In a typical case Sartin was involved in, the team was approached by a large oil company in Canada, with thousands of gas stations. Customers were finding spurious charges on their credit cards after using them at the stations.

The team soon figured out that someone at a technology vendor was responsible, but couldn't pin it down. So the investigators set a trap in the system, to see who accessed customer data.

"The trap went off on Saturday morning," Sartin said. "Hackers always think nobody's looking on Saturday mornings."

A police car headed to the vendor's office, and the culprit turned out to be a 21-year-old who supported the software that operated the gas pumps. He had sold lists of customer data to organized crime.

Many breaches don't happen through outsourcing. In one of the largest cases in recent years, the gang that stole 41 million credit and debit card numbers from chains including TJX Cos. obtained access through unsecured wireless networks, not through subcontractors' systems.

Still, Verizon's report advises companies to keep a tighter rein on contractors, including by limiting partners' access to only the data they need.

ITworld reboot

Behind the changes!

We just completed a re-architecture of ITworld with loads of new social functionality! We're still tweaking, but please check it out, share your feedback and let us know if you have any problems.

Email us

ITworld LIVE

Anonymous's picture

Object

The best way to take full advantage of server virtualization's powerful capabilities is with network-based storage. Dell EqualLogic FS7500 offers a flexible solution for VMware virtual workloads by consolidating both NAS and SAN storage in a unified, scale-out architecture.

Posted by Anonymous

Anonymous's picture

Object

As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.

Posted by Anonymous

stojanos's picture

Object

Posted by stojanos

Anonymous's picture

Object

In most companies, the needs of the business are outpacing what IT can deliver. Technology is the foundation and enabler of business innovation, but developing and implementing new solutions is resource-intensive. Integrating and optimizing islands of IT is complex, time-consuming and costly.However, implementing a private cloud can be complex and daunting. HP's solution, CloudSystem Matrix, helps you build a turnkey private cloud environment to deliver the benefits of the cloud to your business users. Read now to find out how the HP CloudSystem Matrix can enable you to move quickly to a private cloud model.

Posted by Anonymous

Ferniez's picture

Object

Posted by Ferniez

Anonymous's picture

Object

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Posted by Anonymous

dlgmex@gmail.com's picture

Object

Posted by dlgmex@gmail.com

Anonymous's picture

Object

A comprehensive backup and recovery solution is one supporting a tiered-recovery model. This IDC Vendor Spotlight examines the forces driving the advancements in data protection technologies. Discover the benefits of a solution that works across physical, virtual and cloud environments. Read it today.

Posted by Anonymous

wengweng's picture

Object

Posted by wengweng

johnyosborn@hotmail.com's picture

Object

Posted by johnyosborn@hot...

Anonymous's picture

Object

Learn how IT teams can protect against spear phishing tactics. Harry Sverdlove, chief technology officer of Bit9 offers a frank discussion about spear phishing - the most common technique used in today's advanced attacks. Learn how spear phishing works and three recommendations for IT to protect against modern threats.

Posted by Anonymous

Anonymous's picture

Object

Enterprises have successfully controlled their IT budgets and server sprawl issues with the help of virtualization technologies, but what's next? Increasingly, organizations are turning to storage consolidation for virtualized server environments in order to reduce data center costs and inefficiencies.

Posted by Anonymous

Anonymous's picture

Object

This report defines "tier-1" storage in the modern IT world and in the data centers and services that support it. What was a simple environment just a few years ago with mainframes or a few large servers to be supported has evolved into a complex web of virtual machines, clouds, and expanding user expectations -- factors which demand and create flexibility, but do so in a way that pushes a lack of predictability upon the storage infrastructure. Learn what your criteria should be for tier-1 storage.

Posted by Anonymous

Anonymous's picture

Object

The new HP ProLiant Gen8 server features capabilities that speed and simplify three critical phases of the server lifecycle: configuration and provisioning, daily operational health monitoring and ongoing updates and maintenance. Download this short paper to learn more.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Posted by Anonymous

Anonymous's picture

Object

Cascade Demo: With Cascade, you get visibility into network optimization and analysis, application performance management, IT consolidation, and security. Watch as Jack, the manager of the network team, deals with user complaints about application performance. See how he uses Riverbed Cascade to solve them.

Posted by Anonymous

Anonymous's picture

Object

In this white paper, IDC analyzes the ROI that customers can expect from Riverbed Cascade, based on interviews with Cascade customers. Additionally, IDC lays out the business case for proactively managing network and application performance. Get the visibility you need to achieve your IT objectives. Download this whitepaper today.

Posted by Anonymous

Anonymous's picture

Object

NSS Labs, a global leader of independent security product testing and certification, just released the results of an in-depth assessment involving seven Next-Generation Firewall products. Solutions from SonicWALL®, Check Point®, Palo Alto Networks®, Juniper Networks®, Fortinet®, Stonesoft® and Barracuda Networks® were rigorously tested. The result? SonicWALL's SuperMassive™ E10800 is the Highest Overall Protection Next-Gen Firewall to Earn NSS Labs "Recommend" Rating.

Posted by Anonymous

Anonymous's picture

Object

In this white paper, IDC analyzes the ROI that customers can expect from Riverbed Cascade, based on interviews with Cascade customers. Additionally, IDC lays out the business case for proactively managing network and application performance. Get the visibility you need to achieve your IT objectives. Download this whitepaper today.

Posted by Anonymous

Anonymous's picture

Object

The new HP ProLiant Gen8 server features capabilities that speed and simplify three critical phases of the server lifecycle: configuration and provisioning, daily operational health monitoring and ongoing updates and maintenance. Download this short paper to learn more.

Posted by Anonymous

AN4Mobile's picture

Object

Posted by AN4Mobile

Anonymous's picture

Object

The benefits of virtualization are unassailable: increased agility, scale, and cost savings to name a few. However, so too are the monitoring challenges posed by these environments-including complexities, lack of visibility and control, and inefficiency.

Posted by Anonymous

Anonymous's picture

Object

The convenient portability and high functionality of consumer devices combined with the ability to connect to the Internet almost anywhere and at any time are resulting in a growing mobile workforce realizing important productivity benefits - right at the point of contact with customers and partners.

Posted by Anonymous

Anonymous's picture

Object

Whether your data center is large or small, it faces a similar set of roadblocks to efficiency, uptime, and ROI. This white paper reveals the six most common and intractable problems facing the data center and explains how to rectify them while improving efficiency and uptime.

Posted by Anonymous

Anonymous's picture

Object

Layered security is the way to go when it comes to protecting Active Directory. This expert e-guide explains the best method to use when planning and designing a security solution. Find out why it is important to secure Group Policy settings and discover how managed service accounts boost server security in R2.

Posted by Anonymous

Neil Fiertel's picture

Object

Posted by Neil Fiertel

Anonymous's picture

Object

Oracle Maximum Availability Architecture (MAA) is the Oracle best practices blueprint for implementing Oracle high availability technologies and is one of the key requirements for any Oracle Fusion Middleware enterprise deployment. Learn more in this whitepaper about the various components of MAA and what this exceptional product can do for you.

Posted by Anonymous

Anonymous's picture

Object

This IDC Vendor Profile analyzes Box, a company playing in the public cloud advanced storage services market and the content management and collaboration market, and reviews key success factors: market potential, technology/solution, corporate strategy, force multipliers, and customers. The company, headquartered in Palo Alto, California, has over 8 million users and is growing quickly in the file synchronization and collaboration market. Leveraging IDC's expert understanding of the competitive landscape and future outlook, this document highlights company and market information tailored to the investment professional's needs.

Posted by Anonymous

Anonymous's picture

Object

Oracle Maximum Availability Architecture (MAA) is the Oracle best practices blueprint for implementing Oracle high availability technologies and is one of the key requirements for any Oracle Fusion Middleware enterprise deployment. Learn more in this whitepaper about the various components of MAA and what this exceptional product can do for you.

Posted by Anonymous

Anonymous's picture

Object

Both business and IT need the agility enabled by the private cloud. Now you can apply technologies and processes pioneered by public cloud services to your own data center.

Posted by Anonymous

Anonymous's picture

Object

One of the key strategies that IT teams are pursuing to reduce capital costs while boosting asset utilization and employee productivity is the transition to highly virtualized data centers. However, IDC finds that expectations for further boosts in IT asset use and operational efficiency often surpass the actual results for a variety of reasons. These problems can quickly overwhelm any hoped-for benefits as the scope of virtual server deployment expands.

Posted by Anonymous

Ask a question

Ask a Question