Attacks/Breaches
12/1/2008
04:35 PM
50%
50%

Canadian IT Exec Accused Of Stealing Customer Database

Data on more than 3.2 million prospects could be worth more than $10 million

An IT manager of a Canadian direct marketing firm has been accused of absconding with a copy of the company's customer database.

According to a report in last week's Vancouver Sun, an affidavit filed with the British Columbia Supreme Court accuses Nick Belmonte, vice president of IT at C-W Group, of stealing a computer backup tape containing names and information about 3.2 million customers -- potentially worth more than $10 million. The tape also contained credit card and bank account information of more than 800,000 customers.

"The customer library could also potentially be marketed as a discrete asset with a value in the tens of millions of dollars," the affidavit said.

In her affidavit, C-W chief executive Gloria Evans recalled she became extremely concerned that Belmonte had recently ordered another employee to bring three backup tapes to his office, where he made copies. Only two tapes were found on Belmonte's desk. "The tape containing the customer library data was missing," the statement says.

Evans and another top executive, Brian Page, phoned Belmonte, who denied knowing anything about a third tape, according to the court documents. The CEO then changed the locks on the computer room and terminated off-site access to the company's computer system.

Although the information on the backup tape was encrypted, the tape contained information and programs that would allow a knowledgeable user to decrypt the data, the report states.

Page's statement in the court records suggests that Belmonte was a "problem employee" whose office attendance was irregular, who charged lunches with his friends to the company, and who had informed employees he would be leaving soon.

The court records include an e-mail sent by Belmonte at 1:05 a.m. on Nov. 5, saying he was on stress leave because he had been wrongly accused of theft.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, January 2015
To find and fix exploits aimed directly at your business, stop waiting for alerts and become a proactive hunter.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7402
Published: 2014-12-17
Multiple unspecified vulnerabilities in request.c in c-icap 0.2.x allow remote attackers to cause a denial of service (crash) via a crafted ICAP request.

CVE-2014-5437
Published: 2014-12-17
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote management via a request to remote_management.php,...

CVE-2014-5438
Published: 2014-12-17
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name parameter to connected_devices_computers_edit.php.

CVE-2014-7170
Published: 2014-12-17
Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.

CVE-2014-7285
Published: 2014-12-17
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.