Risk

10/2/2015
05:15 PM
50%
50%

Scottrade Breach Hit 4.6 Million Customers, Began 2 Years Ago

Social Security numbers might have been exposed, but the main target appears to have been contact information.

Today, Scottrade Inc. announced a breach of 4.6 million customer contact information records (and possibly Social Security numbers), resulting from an attack that occurred between late 2013 and early 2014. 

Scottrade told customers in an email that it had "not seen any fraudulent activity as a result of this incident." However, the company also stated that it learned about the breach from the FBI, which was investigating a rash of breaches involving financial services firms. The company says it has no reason to believe its trading platforms or client funds were compromised, and that the focus appears to have been contact data, possibly to facilitate stock scams.

"A concerning lack of detective capabilities must not have been in place to have missed data exfiltration to the tune of 4.6 million records," says Stewart Draper, director of insider threat at Securonix. "The timeline specified was a particularly sensitive time in this sector with hacktivist and criminal groups regularly targeting financial companies. Federal authorities should not be the avenue with which companies are discovering they may have been breached.  In 2014 Scottrade was fined for failure to provide complete trade logs, blamed on an internal IT error from a migration. Accountability for these mistakes need to be taken at the highest levels of the organization to help drive awareness and improvement in security defense."

"The FBI is unlikely to explain in detail why notification of this breach took so long, but it's not uncommon for an ongoing investigation to delay notification so that criminals aren't tipped off," Tim Erlin, director of IT security and risk strategy at Tripwire.

A Scottrade representative told Wired that the FBI informed them of the breach in August but did ask them to withhold the information from customers until last Friday while they completed a part of the investigtion.

"Cyber criminals behave more like an infestation than the usual metaphor of a burglar," says Erlin. "Once they're inside, it takes more than a rolled-up newspaper to get rid of them."

"Scottrade customers are in the dark about exactly what was taken (the names and addresses were provided by Federal law enforcement), and don’t yet know where the data was taken from," says Trey Ford, global security strategist at Rapid7. "What we do know is that the data appears to have been taken 18-24 months ago. Few, if any, organizations store log data reaching that far back and it’s no wonder Scottrade cannot definitively state what data was taken for this reason."

See more at Scottrade's notice, at KrebsOnSecurity and Wired.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
prospecttoreza
0%
100%
prospecttoreza,
User Rank: Strategist
10/5/2015 | 9:54:38 AM
Scottrade breach
With all these breaches, it seems that there are more accounts stolen than people in US.

One could argue that by this time, there is almost nothing new to be stolen aside from info on kids just entering their credit lives.

So, what is the point of all these breaches? And do they even matter, if everyone is ultimately affected?
Blog Voyage
50%
50%
Blog Voyage,
User Rank: Strategist
10/3/2015 | 9:16:38 AM
Nice
What a drop ! Hoping the best for them
5 Reasons the Cybersecurity Labor Shortfall Won't End Soon
Steve Morgan, Founder & CEO, Cybersecurity Ventures,  12/11/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Gee, these virtual reality goggles work great!!! 
Current Issue
The Year in Security: 2017
A look at the biggest news stories (so far) of 2017 that shaped the cybersecurity landscape -- from Russian hacking, ransomware's coming-out party, and voting machine vulnerabilities to the massive data breach of credit-monitoring firm Equifax.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.