Attacks/Breaches
6/9/2011
12:20 PM
50%
50%

Citigroup Confirms Hackers Stole Customer Data

Names, account numbers, email addresses, and contact details for more than 200,000 customers stolen in newest attack.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
Citigroup on Thursday confirmed that attackers recently breached its systems, resulting in the exposure of customers' personal details.

"During routine monitoring, we recently discovered unauthorized access to Citi's Account Online," said a Citi spokesperson via email. "A limited number--roughly 1%--of Citi North America bankcard customers' account information ... was viewed." According to the company's most recent annual report, it has 21 million North American customers, meaning that approximately 210,000 customers had their details stolen during the attack.

The exposed account information included names, account numbers, email addresses, and contact details. But according to Citi, "the customer's social security number, date of birth, card expiration date, and card security code (CVV) were not compromised."

Even so, "customers affected by this incident should be on high alert for scams, phishing, and phone calls purporting to be from Citibank and their subsidiaries," said Chester Wisniewski, a senior security advisor at Sophos Canada, in a blog post.

Citi said that it's contacting affected customers, and that it's already "implemented enhanced procedures to prevent a recurrence of this type of event," although for security purposes, it declined to detail those enhancements.

Citi apparently discovered the Citi Account Online breach in May, during routine systems maintenance. But the breach didn't come to light until Citi responded to questioning by the Financial Times on Wednesday.

Citigroup is the country's third-largest bank, after Bank of America and J.P. Morgan Chase. The Citi breach follows recent attacks against Sony, which in the past two months has seen its websites breached 17 times, PBS, Honda Canada, as well as EMC's RSA division. EMC this week confirmed that attackers used stolen SecurID two-factor authentication system information to attempt to hack into the website of defense contractor Lockheed Martin, which said that it successfully repelled the attack. Other defense contractors have also reportedly been targeted by similar attacks.

How widespread are data braches? No one knows for sure. Currently, there's no national data breach law, although about 15 states do require companies to inform residents when their information may have been compromised. The resulting breach notification letters are a primary source of information for identifying when businesses have suffered data breaches.

But the House and Senate have been taking a closer look at data breach notifications, and especially the speed with which companies notify affected consumers. Last week, the House Energy & Commerce Committee Subcommittee on Commerce, Manufacturing, and Trade, asked representatives from Sony, as well as Epsilon (which was breached in March), for detailed timelines about how quickly they responded to the breach and notified affected customers.

Meanwhile, last month, a group of senators called on the Securities and Exchange Commission to begin requiring public companies to disclose all privacy or security exposures--in other words, breaches.

Now, government agencies are also getting involved. On Wednesday, the Department of Commerce's Internet Policy Task Force issued a report that called for the department to create new incentives for companies to improve their information security practices.

According to a blog post from Bret Cohen, an attorney at Hogan Lovells, such incentives "would include continuing to advocate for the adoption of a national breach notification law, facilitating the sharing of information about security breaches as they occur, and evaluating other public policy tools that can be used to promote cybersecurity best practices--such as liability protection and reducing 'cyberinsurance' premiums for companies that adopt best practices and openly share details about cyberattacks."

In this new Tech Center report, we profile five database breaches--and extract the lessons to be learned from each. Plus: A rundown of six technologies to reduce your risk. Download it here (registration required).

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Why else would HR ask me if I have a handicap?"
Current Issue
The Changing Face of Identity Management
Mobility and cloud services are altering the concept of user identity. Here are some ways to keep up.
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio

The cybersecurity profession struggles to retain women (figures range from 10 to 20 percent). It's particularly worrisome for an industry with a rapidly growing number of vacant positions.

So why does the shortage of women continue to be worse in security than in other IT sectors? How can men in infosec be better allies for women; and how can women be better allies for one another? What is the industry doing to fix the problem -- what's working, and what isn't?

Is this really a problem at all? Are the low numbers simply an indication that women do not want to be in cybersecurity, and is it possible that more women will never want to be in cybersecurity? How many women would we need to see in the industry to declare success?

Join Dark Reading senior editor Sara Peters and guests Angela Knox of Cloudmark, Barrett Sellers of Arbor Networks, Regina Wallace-Jones of Facebook, Steve Christey Coley of MITRE, and Chris Roosenraad of M3AAWG on Wednesday, July 13 at 1 p.m. Eastern Time to discuss all this and more.