Online hitch allows thieves to register fraudulently on payroll vendor portal.
Some customers of payroll processing provider ADP had unauthorized accounts created on ADP's portal in their names by thieves using stolen data, and their W-2 data compromised, reports KrebsOnSecurity. This leaves them exposed to the risk of tax returns being filed fraudulently in their names.
The breach was discovered last month by ADP client US Bank, which said that "a small population" of its 64,000 employees had its tax and salary data stolen from the payroll vendor portal.
To register on ADP, clients provide employees the company-specific link from ADP, and a company code. KrebsOnSecurity says unregistered employee accounts have been used by thieves to sign in with personal details of the employee, and siphon W-2 information.
This process is flawed because the code is posted by ADP customers on an unsecured online page; ADP has now disabled access to the registration portal for those clients found to be publishing the sign-up link and code online.
Read full story at KrebsOnSecurity.
About the Author(s)
You May Also Like
Securing Code in the Age of AI
April 24, 2024Beyond Spam Filters and Firewalls: Preventing Business Email Compromises in the Modern Enterprise
April 30, 2024Key Findings from the State of AppSec Report 2024
May 7, 2024Is AI Identifying Threats to Your Network?
May 14, 2024Where and Why Threat Intelligence Makes Sense for Your Enterprise Security Strategy
May 15, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024