Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts

Citigroup hackers made $2.7 million

IDG News Service - Citigroup suffered about $2.7 million in losses after hackers found a way to steal credit card numbers from its website and post fraudulent charges.

Citi acknowledged the breach earlier this month, saying hackers had accessed more than 360,000 Citi credit card accounts of U.S. customers. The hackers didn't get into Citi's main credit card processing system, but were reportedly able to obtain the numbers, along with the customers' names and contact information, by logging into the Citi Account Online website and guessing account numbers.

Until now, it wasn't clear how much -- if any -- fraud had occurred as a result of the theft. But Citi confirmed Friday that there were losses of $2.7 million from about 3,400 accounts.

The bank has said its customers will not be liable for the losses.

Citi learned about the hack on May 10 and began notifying customers on June 3. The bank said other sensitive data, such as Social Security numbers, birthdates and the cards' CVV (Card Verification Value) security codes used for online transactions, were not taken.

In addition to the fraud losses, Citigroup will have to pay the cost of notifying customers and reissuing credit card numbers for the 360,000 affected clients. The Ponemon Institute has estimated the average cost of a data breach at $214 per compromised record. By that yardstick, the breach would cost the bank $77 million.

Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com

Reprinted with permission from IDG.net. Story copyright 2010 International Data Group. All rights reserved.

Citigroup says 218,000 affected by hackers

HONG KONG (AP) — Hackers stole information for 360,000 Citigroup Inc. U.S. credit card accounts in a recent data breach, although the actual number of customers affected was not much higher than originally reported, the bank said Wednesday.

Citi said last week that about 1 percent of its credit card customers had account information hacked online but did not say exactly how many. The actual number of customers affected was thought to be about 210,000, based on Citi's 2010 annual report, which said the company had roughly 21 million North American credit card customers.

The exact number of customers affected was not far off the mark. In a statement posted late Wednesday on its website, the company said 217,657 people were sent new cards along with notification letters starting June 3.

Hackers gained access to a total of 360,083 accounts but because many of the accounts were duplicates or already closed, they weren't affected and did not need to be sent replacement cards, Citi said.

The bank said it discovered on May 10 that hackers used its Account Online system to access the data for North America Citi-branded credit cards issued in the U.S.

The bank said last week that hackers accessed customer names, account numbers and contact information, including e-mail addresses.

But they weren't able to get their hands on social security numbers, dates of birth, card expiration dates or card security codes, information that can be useful in identity theft.

Internal fraud alerts and enhanced monitoring were placed on all accounts deemed at risk as soon as the breach was discovered, Citi said.

Citi said it has notified police and government officials.

"For the security of our customers, and because of the ongoing law enforcement investigation, we cannot disclose further details regarding how the data breach occurred," it said.

Citi reassured customers that they weren't liable for any unauthorized use of their cards and urged them to review account statements to report any suspicious transactions.

It's the latest in a series of high-profile data attacks against big companies and institutions. The International Monetary Fund said Sunday that it was investigating an attack on its computer system.

Google Inc. said earlier this month that Gmail accounts of several hundred people had been breached. In April, Sony Corp.'s Playstation Network was the victim of a massive security breach that affected more than 100 million online accounts.

Hackers claim to hit NATO server

IDG News Service - A group of hackers going by the name of the "Inj3ct0r Team" are claiming they've compromised a server belonging to NATO.

The files were posted on the MediaFire file hosting site under the name "NATO Tomcat 5.5 Servlet Backup." A member of the Inj3ct0r Team contacted via e-mail by IDG News Service wrote that the files were a "server backup, confidential data."

Contained inside the files was a notepad document dated July 3 that said: "NATO lamers! I've been watching you day and night since then! W00t! Your Machines rooted! Servers restored to default! what else! [Expletive deleted] you and your crimes! and soon enough all your stupid ideas will be published on WikiLeaks!"

NATO's press office, contacted in Belgium on Tuesday, did not respond to a query by Wednesday afternoon.

The Inj3ct0r Team runs a website, http://1337day.com/team, that contains an archive of exploits that could be used to hack into a computer. It is not a unique list, as many security companies and organization compile similar information for researchers.

The Inj3ct0r Team, founded in 2003 according to its website, describes itself as a group of "hacktivists," a combination of the words "hacking" and "activists" that is generally used to describe hackers who break into computers for political reasons or other causes.

High-profile attacks on websites from those describing themselves as hacktivists have become increasingly common from groups such as Anonymous, which has kept up a strong hacking campaign against government websites and organizations.

Another group, called Lulz Security, recently disbanded after nearly seven weeks of attacks against websites of the U.S. Central Intelligence Agency, the U.S. Senate, the U.K.'s Serious Organised Crime Agency, the Brazilian government and the energy giant Petrobras, among others.

Send news tips and comments to jeremy_kirk@idg.com

Reprinted with permission from IDG.net. Story copyright 2010 International Data Group. All rights reserved.