June 29, 2016
|
Incidents
On August 27, 2012, an intruder connected to the South Carolina Department of Revenue using a legitimate access account via the remote access service (Citrix). Initially, the intruder was able to gain access to user accounts on six (6) internal servers. In no more than three days, these accounts granted the intruder access to all user credentials (username/password) for all […]
June 29, 2016
|
Incidents
The insider was a contract employee working as a software developer and tester for a telecommunications organization. His contract had been terminated due to poor performance, but he subsequently obtained employment with a subsidiary of that organization. Over a period of nearly one month, the insider gained access to sixteen (16) of his former employer's systems, all of which […]
June 29, 2016
|
Incidents
For 18 months, the IT manager of a lottery company altered computer records to fraudulently win lottery prizes using real tickets. To carry out his fraud, he purchased tickets in the usual way and then modified the lottery agency's database record to make himself the winner. He bought winning tickets […]
June 29, 2016
|
Incidents
Every night he suspected that strange, ragged little man, stopped him, and asked, “Let me see what you have in your shopping cart,” but he never found anything. Several years later, he found him in a bar and, after buying him a drink, confessed: “You see, I’m not a security guard anymore, but when I was, I always suspected you were stealing something from us. Can you tell me what it was?” […]
June 29, 2016
|
Incidents
In an act of corporate cooperation, AT&T reached an agreement with ConEd, the New York City energy company. The contract stipulated that when energy demand exceeded the electrical grid, AT&T would reduce its energy demand from the provider by pulling its switch, disconnecting some of its facilities, and drawing power from its internal generators at its substation.
June 29, 2016
|
Incidents
A supervisor in a disability claims department used her account for nearly two years to modify claims and send monthly disability payments to her fiancé. Her employer failed to update her access privileges after she changed jobs, allowing her to modify and approve data. Both positions used the same application, but […]
June 29, 2016
|
Incidents
It was a major financial institution that did not survive the 2008-2009 economic recession, employing over 45,000 people. One Sunday evening, when the bank was closed, junior staff at the NOC (Network Operations Center) noticed unusual network activity. Confused and unsure of what they were seeing, and without instructions on how to proceed, they decided to observe the […]
June 29, 2016
|
Incidents
In January 2003, a U.S. District Court in the District of Columbia ordered Verizon (an Internet service provider, or ISP) to comply with the subpoena issued by the Recording Industry Association of America (RIAA), an organization representing the interests of the recording industry. The RIAA, in an effort to stop the unauthorized sharing of music online, […]
June 29, 2016
|
Incidents
At a financial institution, a foreign exchange trader was responsible for collecting and trading assets for the organization to generate profits. His annual bonus was based on how much profit his trades generated for the organization. However, he began losing money on his trades. Fearing the consequences for his job, he devised a complex fraud scheme that […]s
June 29, 2016
|
Incidents
One of the many conclusions Bruce Sterling draws in his book "The Hacker Crackdown" is that corporate security officers, as well as law enforcement officials, wasted no time in seizing upon the dark incident suffered by AT&T on January 15, 1990 (Martin Luther King Jr. Day) to launch the largest publicity campaign about the "risk of hackers." […]