Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

9/26/2018
03:00 PM
50%
50%

SEC Slams Firm with $1M Fine for Weak Security Policies

This is the first SEC enforcement cracking down on violation of the Identity Theft Red Flags Rule, intended to protect confidential data.

The Securities and Exchange Commission (SEC) has issued a $1 million fine against a Des Moines-based organization for failing to implement sufficient security policies related to an incident that compromised personal data belonging to thousands of customers.

Voya Financial Advisors, Inc. (VFA), a broker-dealer and investment adviser, was charged with violating the Safeguards Rule and Identity Theft Red Flags Rule, both of which are intended to protect personal data and protect customers from identity theft. This marks the first time the SEC has enforced the Identity Theft Red Flags Rule with a penalty against an offending firm.

For six months in 2016, cyberattackers impersonated VFA contractors by calling the firm's support line and requesting to reset passwords. With new passwords, the actors were able to gain access to personal data of 5,600 VFA customers. The SEC found the attackers used this information to create new online user profiles and gain unauthorized access to account documents. Its order states the VFA failed to shut down attackers' access due to weaknesses in its security procedures, and it also failed to ensure the security of contractors' systems.

VFA has agreed to pay the $1 million fine and will consult an independent expert to evaluate its policies and procedures, and ensure future compliance with both rules, the SEC reports.

Read more details here.

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
9/26/2018 | 3:40:47 PM
First of many
But fines won't fix the problem - only a change in the C-Suite attitude of risk will do that and have resources allocated AND IMPLEMENTED FOR AGGRESSIVE MALWARE HUNTING and security walls.  Fines are usually laughed off.  And watch the SEC be hacked soon too as they are a GOVERNMENT body probaby running S/370 IBM MAINFRAMES too.  
Sportialize
50%
50%
Sportialize,
User Rank: Apprentice
9/26/2018 | 5:53:58 PM
Re: First of many
Totally true !
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 9:33:21 AM
Weak Security Policies
This is good news as organizations are going to think twice when they avoid cost of security implementations.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 9:34:15 AM
Re: First of many
But fines won't fix the problem That is true but we need to start somewhere.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 9:35:33 AM
Re: First of many
only a change in the C-Suite attitude of risk will do that and have resources allocated AND IMPLEMENTED FOR AGGRESSIVE MALWARE HUNTING and security walls. That is true but to change executives mind we need to have evidence of the troubles.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 9:37:15 AM
Re: First of many
Fines are usually laughed off. I aggee better to have a fine that hurts otherwise it will be ok for most companies, they keep paying the fines instead of implementing security measures.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/28/2018 | 9:41:46 AM
Reset password
For six months in 2016, cyberattackers impersonated VFA contractors by calling the firm's support line and requesting to reset passwords. This is a common problem, social engineering. Hard to prevent from in certain situations unles a good training program.
Cloud Security Threats for 2021
Or Azarzar, CTO & Co-Founder of Lightspin,  12/3/2020
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Assessing Cybersecurity Risk in Todays Enterprises
Assessing Cybersecurity Risk in Todays Enterprises
COVID-19 has created a new IT paradigm in the enterprise and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27772
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned int`. This would most likely lead to an impact to application availability, but could po...
CVE-2020-27773
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in MagickCore/gem-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char` or division by zero. This would most likely lead to an impact to appli...
CVE-2020-28950
PUBLISHED: 2020-12-04
The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.
CVE-2020-27774
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift for 64-bit type `ssize_t`. This would most likely lead to an impact to application availability, but co...
CVE-2020-27775
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned char. This would most likely lead to an impact to application availability, but c...