ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Cybercrime software maker hacked

Joris Evers CNET News.com

Published: 20 Dec 2005 12:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Guidance Software, one of the leading sellers of software used to investigate computer crimes, has had to carry out a forensic investigation on its own systems after a hacker broke in and accessed records, including credit card data, of thousands of customers.

The attack occurred in November, but wasn't discovered until 7 December, John Colbert, chief executive officer of Guidance, said in an interview on Monday. The attack exposed data on thousands of the company's customers, including 3,800 whose names, addresses and credit card details were exposed, he said.

"A person compromised one of our servers," Colbert said. "This incident... highlights that intrusions can happen to anybody and nobody should be complacent about their security."

Guidance sent out letters last week to inform its customers about the breach. Some customers have already reported fraudulent credit card charges. "There have been a handful of cases, but we're only two weeks into this, so I don't know the total size," Colbert said.

Kessler International received notice from Guidance on Monday, three days after it got an American Express bill for about $20,000, mostly in unauthorised charges for advertising at Google, said Michael Kessler, president of the computer-forensics investigative firm.

"We got hit pretty badly," Kessler said. "Our credit card fraud goes back to 25 November. If Guidance knew about it on 7 December, they should have immediately sent out emails. Why send out letters through US mail while we could have blocked our credit cards?"

Regular mail was the quickest way to contact customers, according to Colbert. "We don't have email addresses for everybody, and we found that their physical addresses are more permanent than their email addresses," he said.

Guidance stored customer names and addresses and retained "card value verification", or CVV, numbers, Colbert said. The CVV number is a three-digit code found on the back of most credit cards that is used to prevent fraud in online and telephone sales. Visa and MasterCard prohibit sellers from retaining CVV once a transaction has been completed.

"We found that our systems were storing these numbers that were supposed to be deleted after their use," Colbert said. The company no longer stores CVV numbers, he said.

Guidance's EnCase software is used by security researchers and law enforcement agencies worldwide. The company notified all its approximately 9,500 customers about the attack and has called in the US Secret Service, which has started an investigation, Colbert said.

While Kessler isn't happy, data breaches are part of business, he said. "Obviously Guidance has to do a lot of soul searching to see if they were maintaining their data as required," he said.

The intrusion at Guidance is the latest in a string of reported data security breaches this year. Since February, more than 53 million personal records have been exposed in dozens of incidents, according to information compiled by the Privacy Rights Clearinghouse.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
73 out of 126 people found this useful


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Business Analyst - Payment systems

Candidates that have previous experience of working on credit card / chip and pin, STP and Cash management project are highly desirable. I am looking ...

Database Developer

My client is currently signing a contract with one of the UK's largest credit card companies. An Oracle 9i/10g Database Developer with Oracle PL/SQL ...

Support Manager - Financial Software - London - 50/55k

My client specialises in providing payment solutions to large blue chip clients, most notably in the banking sector, they specialise in credit ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment