Incidents

The benefit of a rapid incident response

June 29, 2016 | Incidents

On August 27, 2012, an intruder connected to the South Carolina Department of Revenue using a legitimate access account via the remote access service (Citrix). Initially, the intruder was able to gain access to user accounts on six (6) internal servers. In no more than three days, these accounts granted the intruder access to all user credentials (username/password) for all […]

Good hardening, good monitoring, a better R.I.

June 29, 2016 | Incidents

The insider was a contract employee working as a software developer and tester for a telecommunications organization. His contract had been terminated due to poor performance, but he subsequently obtained employment with a subsidiary of that organization. Over a period of nearly one month, the insider gained access to sixteen (16) of his former employer's systems, all of which […]

Anomalies, Errors, and Discrepancies: Inputs for discovering incidents in progress

June 29, 2016 | Incidents

For 18 months, the IT manager of a lottery company altered computer records to fraudulently win lottery prizes using real tickets. To carry out his fraud, he purchased tickets in the usual way and then modified the lottery agency's database record to make himself the winner. He bought winning tickets […]

An old story that a SOC shouldn't overlook (or dismiss as a "false positive")

June 29, 2016 | Incidents

Every night he suspected that strange, ragged little man, stopped him, and asked, “Let me see what you have in your shopping cart,” but he never found anything. Several years later, he found him in a bar and, after buying him a drink, confessed: “You see, I’m not a security guard anymore, but when I was, I always suspected you were stealing something from us. Can you tell me what it was?” […]

For attending a seminar on how to handle emergencies

June 29, 2016 | Incidents

In an act of corporate cooperation, AT&T reached an agreement with ConEd, the New York City energy company. The contract stipulated that when energy demand exceeded the electrical grid, AT&T would reduce its energy demand from the provider by pulling its switch, disconnecting some of its facilities, and drawing power from its internal generators at its substation.

Disability fraud case (excessive system privileges)

June 29, 2016 | Incidents

A supervisor in a disability claims department used her account for nearly two years to modify claims and send monthly disability payments to her fiancé. Her employer failed to update her access privileges after she changed jobs, allowing her to modify and approve data. Both positions used the same application, but […]

Beware: The flat network (do you know of one?) that left a bank without service for 36 hours

June 29, 2016 | Incidents

It was a major financial institution that did not survive the 2008-2009 economic recession, employing over 45,000 people. One Sunday evening, when the bank was closed, junior staff at the NOC (Network Operations Center) noticed unusual network activity. Confused and unsure of what they were seeing, and without instructions on how to proceed, they decided to observe the […]

When Privacy Protected Shared Music (Verizon, 2003)

June 29, 2016 | Incidents

In January 2003, a U.S. District Court in the District of Columbia ordered Verizon (an Internet service provider, or ISP) to comply with the subpoena issued by the Recording Industry Association of America (RIAA), an organization representing the interests of the recording industry. The RIAA, in an effort to stop the unauthorized sharing of music online, […]

Single command, monitoring collusion, no phone logging, remote access, 5-year fraud

June 29, 2016 | Incidents

At a financial institution, a foreign exchange trader was responsible for collecting and trading assets for the organization to generate profits. His annual bonus was based on how much profit his trades generated for the organization. However, he began losing money on his trades. Fearing the consequences for his job, he devised a complex fraud scheme that […]s

MLK Day! Is there any "lie" that doesn't have a silver lining?

June 29, 2016 | Incidents

One of the many conclusions Bruce Sterling draws in his book "The Hacker Crackdown" is that corporate security officers, as well as law enforcement officials, wasted no time in seizing upon the dark incident suffered by AT&T on January 15, 1990 (Martin Luther King Jr. Day) to launch the largest publicity campaign about the "risk of hackers." […]

Home Solutions About us Customers Blog