topics that matter; ideas worth sharing

share a tip, submit a link, add something new

Monster shuts down rogue server after breach

August 23, 2007, 09:58 AM —  IDG News Service — 

Monster Worldwide Inc., whose job-hunting sites suffered a massive data breach caused by hackers, has shut down a rogue server that had been used to gather personal details of job seekers.

The server contained the stolen names, addresses, phone numbers and e-mail addresses of people who used Monster's service. The company was still determining the number of people affected by the breech on Wednesday. It did not disclose the location of the server.

The Monster incident is one of a growing number of prominent data breaches highlighting continuing difficulties with Internet security.

Hackers obtained the log-in credentials for companies seeking employees and used the credentials to access Monster.com's database of job seekers. An automated Trojan, dubbed Infostealer.Monstres by security vendor Symantec Corp., then transmitted the personal information to the rogue server.

Symantec said earlier in the week it had found a server containing 1.6 million records belonging to hundreds of thousands of Monster users, mostly in the U.S. It was unclear Thursday morning if the server Monster shut down is the same one that Symantec found. A Monster spokeswoman contacted in London could not provide more information.

As part of a multi-step attack, the job-seekers were then sent e-mails with links to at least two kinds of malicious software. One tries to collect login details for financial sites, and the other is designed to encrypt data on a PC, asking for a ransom to decode the data.

Monster said it will contact the people believed to have been affected by the attacks. It also posted an example of what a phishing e-mail looks like on its Web site.

"Regrettably, opportunistic criminals are increasingly using the Internet for illegitimate purposes," the company said in a statement.

IDG News Service

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Resources
White Paper

Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.

Webcast

Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.

White Paper

Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.

Free stuff
Featured Sponsor

Get a broad understanding of important regulations and how you can make sure your site is in adherence.





Learn how VeriSign SGC-enabled SSL Certificates can help improve site security and customer confidence in the free white paper, "How to Offer the Strongest SSL Encryption." In this paper you will learn the differences between weak and strong encryption and what they mean for your site's performance.

Get VeriSign's free white paper: "The Latest Advancements in SSL Technology" and learn about the benefits of strong SSL encryption, Extended Validation (EV) SSL and security trust marks and what these SSL offerings can do for your site.

Now with Extended Validation (EV) SSL available from VeriSign, you can show your customers that they can trust your site. Learn about EV SSL benefits in this free VeriSign white paper.

More Resources