Attacks/Breaches
12/1/2008
04:35 PM
50%
50%

Canadian IT Exec Accused Of Stealing Customer Database

Data on more than 3.2 million prospects could be worth more than $10 million

An IT manager of a Canadian direct marketing firm has been accused of absconding with a copy of the company's customer database.

According to a report in last week's Vancouver Sun, an affidavit filed with the British Columbia Supreme Court accuses Nick Belmonte, vice president of IT at C-W Group, of stealing a computer backup tape containing names and information about 3.2 million customers -- potentially worth more than $10 million. The tape also contained credit card and bank account information of more than 800,000 customers.

"The customer library could also potentially be marketed as a discrete asset with a value in the tens of millions of dollars," the affidavit said.

In her affidavit, C-W chief executive Gloria Evans recalled she became extremely concerned that Belmonte had recently ordered another employee to bring three backup tapes to his office, where he made copies. Only two tapes were found on Belmonte's desk. "The tape containing the customer library data was missing," the statement says.

Evans and another top executive, Brian Page, phoned Belmonte, who denied knowing anything about a third tape, according to the court documents. The CEO then changed the locks on the computer room and terminated off-site access to the company's computer system.

Although the information on the backup tape was encrypted, the tape contained information and programs that would allow a knowledgeable user to decrypt the data, the report states.

Page's statement in the court records suggests that Belmonte was a "problem employee" whose office attendance was irregular, who charged lunches with his friends to the company, and who had informed employees he would be leaving soon.

The court records include an e-mail sent by Belmonte at 1:05 a.m. on Nov. 5, saying he was on stress leave because he had been wrongly accused of theft.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8802
Published: 2015-01-23
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

CVE-2014-9623
Published: 2015-01-23
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quote and cause a denial of service (disk consumption) by deleting an image in the saving state.

CVE-2014-9638
Published: 2015-01-23
oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.

CVE-2014-9639
Published: 2015-01-23
Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

CVE-2014-9640
Published: 2015-01-23
oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.