Compromised again: Another monster data breach

Compromised again: Another monster data breach

By Richard Moss | Feb 3, 2009 | 18557 reads

On-line recruitment firm monster.com has revealed another major security breach compromising millions of its customers' personal data. This follows a similar breach in 2007 which compromised 1.3 million users' details.

Back in 2007 I used that monster.com breach during security seminars as empirical evidence of the change in the nature of the threat faced by organisations – the shift from hobbyist hacker to criminal. The shift was well documented but not necessarily well understood (even believed) in some quarters − but the 2007 breach at monster was demonstration that criminally motivated attacks could be made against targets where the motivation was monetary, but the theft was not intrinsically financial; rather, the aim was illegal acquisition of data that had potential commercial value, in this case, people's personal details. This shift is now complete and represents a significant threat to the modern-day fabric of society which the Internet epitomises!
 
And monster isn't the only recruitment site that has fallen foul of criminal activity. Numerous sites in the past having fallen victim to such attacks, a casualty of the trade-off between ease-of-use and security.
 
But should users be worried about the loss of data in this case? Given that the majority of data – although personal – is something that is in a CV and therefore in the public domain to some extent, there’s no need for an over-reaction. However, the consequence for users whose data has been compromised varies from an increase in personalised spam attacks (Phishing for passwords or other valuable details), to e-mail mimicking monster.com with the intent of downloading malware, to an additional vector of attack via the combination of the compromised personal details and monster.com password against other on-line applications – sadly it's not unusual for users to use the same (and often weak) user-name and password combination for multiple on-line applications such as Facebook, LinkedIn, or − worse still − financial applications such as banking.
 
Users impacted here would do well to change passwords on other applications as soon as possible, avoid using a single password for multiple applications, use a strong password that’s difficult to guess (combining letters, numerals and symbols) and should as a matter of course change passwords on a regular basis − after all, how would you know if any organisation to which you have given over the security of your personal information has been compromised in the past 24 hours, or the past week?
 
 

Add comment

Post a Comment

The content of this field is kept private and will not be shown publicly.
Verification Code
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
 

Comments

Comments

توبيكات

توبيكات نونو
توبيكات
توبيكات سعودي

توبيكات 2011

توبيكات بنات

العاب نونو

العاب

العاب بنات

games

شات لمني الصوتي

دردشة لمني الصوتية

شات صوتي لمني

شات صوتي

دردشة صوتية

دردشة

دردشه

شات سعودي

شات خليجي
سكر بنات

جات

شات صوتي سعودي خليجي

chat voice

ahj

خليجي الصوتي

سعودي الصوتي

دردشة صوتي

شات صوتي
دردشة صوتية
شات كتابي

شات كتابي خليجي

شات عسل الصوتي

دردشة كتابية

chat
سعودي كول
سعودي كول 6666

كول

سعودي

سعودي كول انحراف

سعودي كول بنات

سعودي كول 1994

chat saudi col ‏

شات سعودي كول

سعودي انحراف

سعودي انحراف2010

سعودي انحراف الصوتي

شات سعودي انحراف

دردشة سعودي انحراف

سعودي انحراف الصوتية

شبكة سعودي انحراف

سعودي انحراف الاصلي

سعودي انحراف كول

سعودي انحراف 2010

انحراف سعودي

saudideviation

دردشة صوتية سعوديه
دردشة صوتية سعودية

دردشة كتابية
دردشة كتابية خليجية
شات
دردشة
خاص للبنات

عرب ذوق

عرب ذوق الصوتي

عرب ذوق الصوتية

دردشة عرب ذوق

شات عرب ذوق

شبكة عرب ذوق

شات صوتي بنات

شات بنات الصوتي

دردشة بنات الصوتي

Girls Chat

شبكة عفناك

صوتية عفناك

شات عفناك

دردشة عفناك

عفناك الصوتي

دردشة عفناك

الخيال
الخيال كام
شبكة الخيال
الخيال الصوتي
الخيال الصوتية
دردشة الخيال
الخيال الصوتية
دردشة صوتية الخيال

شات سعودي خليجي

منتدى نونو

منتدى

منتديات

موقع

شبكة

نونو

Chat Nono

ahj w,jd

]v]am w,jdm

دليل مواقع ويب

دليل مواقع

دليل

مواقع

بنت كول
بنت كول الصوتي
شات بنت كول

دردشة بنت كول
شات بنت كول الصوتية

بنت كول الصوتيه
سعودي كول
صوتية سعودي كول
شات سعودي كول
دردشة سعودي كول
سعودي كول الصوتي
سعودي كول 6666
سعودي كول6666
سكر بنات
شات صوتي زين
شات صوتي ملوك
شات صوتي سعودي
شاتات صوتيه
مكتبة ماسنجر
شات صوتي حبي
شات صوتي كويت
YouTube - Broadcast Yourself.‏ , اليوتيوب نونو
صيف كام
شات صوتي كول
شات انحراف
وه بس
خريطة الموقع نونو
الرياض كول الصوتي
كامات 6666
شات المها
كامات6666
شات كامات 6666
كامات 666
كامات 66
سعودي انحراف
شاتكامات6666
سعودي احوه
شات سعودي احوه
سعودي احوه الصوتي
سعودي احوه كول
دردشة سعودي احوه
احوه سعودي
بنات احوه
دبي الصوتي
سعودي في اي بي الصوتي
شبكة الرياض الصوتي
روعة الليل
لايف كام
الخليج كام
شات كان زمان الصوتي
شات صوتي قصيمي
شات قلبي
ارجوان
شات صوتي قطري
بدور الخليج

منتدى روح

شبكة روح

روح ديزاين

تحميل ماسنجر بلس

توبيكات حزينه

توبيكات

ماسنجر

ماسنجر بلس

تحميل ماسنجر

توبيكات رومنسيه

منتديات روح
دردشة
شات سعودي
خليجي
شات صوتي

Formal Gowns dresses, formal

Formal Gowns dresses, formal dresses, prom shoes, 2010 designer prom gowns at dres4sale.
for cocktail dresses, dresses for prom, homecoming dresses, and evening dresses. Cheap prom dresses or couture designer evening gowns for your next formal.
prom dresses

This shift is now complete

This shift is now complete and represents a significant threat to the modern-day fabric of society which the Internet epitomises!
----
Ed Hardy UGG Boots tiffany jewellery

nfl jersey:

nfl jersey: Obama,49ers.Bears,BengalsBills,BrownsBroncos, CardinalsChargers, ChiefsColts, Cowboys,Dolphins.Eagles, Falcons,Giants,Jets.Lions.Packers.Panthers.cheap nfl jerseys.Raiders. Rams,Ravens.Redskins.Saints.Seahawks,.Steelers.Texans, .nfl jerseys.Pro bowl Super bowl, , etc.

第二の永久歯といわ

第二の永久歯といわれるインプラントですが、興味はあっても
インプラント治療に対して、 不安をお持ちの方がたくさんいらっしゃいます。

Louis Vuitton Global Store

Louis Vuitton Global Store Launch
, Monogram Vernis Melrose Avenue
, perfect accessories for the fashion conscious, at a fraction of the cost of a Louis Vuitton Damier Canvas Bags
.

You could buy a Louis Vuitton Damier Graphite Bags
for each day of the week for the price of one Louis Vuitton store
. Apart from you and Louis Vuitton outlets
, no one else will know that your louis vuitton
was manufactured in China.

Chinese, you have to admit are the superb masters of imitation. You can scrutinize your Louis Vuitton Damier Canvas
with a magnifying glass to find that our eagle-eyed craftsmen in their zeal for perfect imitations have not missed even a minor detail that could set apart Louis Vuitton Puple Weekender PM Replica M95733
from Louis Vuitton Speedy 25
.

Quality not quantity is our inspiration as is evident from the end result i.e. our perfectly imitated Louis Vuitton Wallets Porte-Monnaie Billets Viennois White
.

Pleased, satisfied customers are what we desire, happy customers mean return customers, customers who will always come to Louis Vuitton Wallets Koala Black
for all their Louis Vuitton Wallets Pochette Porte Monnaie NM White
needs!

We aim to please with our Louis Vuitton Wallets Kate Clutch
, offering a highly sought-after French chic with quality at prices that you will be happy to pay, always coming back for more! Also, don't forget to ask about our wholesale Louis Vuitton Wallets Pochette MM Black
.

louis vuitton thanks ,can

louis vuitton

thanks ,can help me

Information on Blogger

leave a comment

knowledge_central_tab

 
 
Knowledge Central
Trusted Mobility Index
The mobile ecosystem of devices, services and networks is at a critical inflection point.While the mobile revolution is unleashing massive opportunities in both emerging and mature economies, it is also increasing in complexity and confusion. The reality is the lightning-fast adoption of powerful, smart devices is outpacing society’s ability to secure them. Today, trust in mobility hangs in the balance.
The state of the Internet, Q4, 2011
Geography appears to play a role in frequency of observed attacks on specific ports. For example, Port 23 (Telnet) is a favorite target for attacks observed to be originating from South Korea and Turkey, where it accounted for more than five times the number of attacks targeting the next most popular port (445 in both countries). Other instances of geography-based port targeting include observed attacks centered on Port 1433 (Microsoft SQL Server) in China and on Port 80 (WWW/HTTP) in Indonesia.
 
 
 
HID Global deploys a centralized, web-based IP access control solution at Fuxi Power Plant
Unable to meet the needs for real-time monitoring with its traditional patrol system, China's Fuxi Power Plant has deployed HID Global's VertX V2000.
StubHub: How to spot fraud before it happens
Whenever a list of log-on credentials is dumped onto the Web, retailers get hit with waves of automated attacks. Here's how ticket marketplace StubHub fights the threat.