Monster.com job database comes under attack by phishers
MASSACHUSETTS - Monster.com, one of the world's largest internet recruitment agencies, has been targeted by cybercriminals in a large-scale phishing scam. Using personal information from the Monster.com client database, the hackers posed as potential employers or Monster.com employees to contact clients in a bid to extract their bank account details and passwords.
Details of the breach were discovered only after computer security firm Symantec reported on its website that it had found a new kind of trojan, called Infostealer.Monstres, which had gathered a hoard of 1.6 million personal records stolen from Monster.com and had uploaded them to a remote server on a computer in Ukraine. The trojan only attacked the "Monster for Employers" site, the section used by recruiters and human resources personnel to search for potential candidates, which was probably accessed using the stolen credentials of a Monster.com employee.
On discovery of the attack, Symantec informed Monster.com, which disabled the affected accounts and posted a warning on its online security centre that clients were being sent fraudulent job offers in an attempt to gain access to their financial information. Monster.com has not reported the crime to police and no arrests have been made.
The threat is not yet over for Monster.com as the personal data stored in the database - from potentially several hundred thousand, mainly US-based, people - could also be used to steal personal identities and perpetrate financial fraud. The personal details and the Monster.com name made the phishing scam appeared more genuine than those most online consumers have become used to. The victims were also expecting to be contacted by strangers with job offers as a result of signing up with the recruitment site.
In a statement, the data vaulting and security specialist Cyber-Ark said the data leakage could have been avoided if the site had maintained its database in a secure and encrypted format. Calum Macleod, European director for Cyber-Ark, said: "Modern encryption and digital vaulting techniques mean personal information uploaded to a website like Monster.com need only be decrypted when the database is interrogated. Using this approach means the data can be held securely on the web server and, even if hackers succeeded in downloading the files, the fact that they were encrypted would render the data unreadable - and therefore unusable."
コンテンツを印刷またはコピーできるのは、有料の購読契約を結んでいるユーザー、または法人購読契約の一員であるユーザーのみです。
これらのオプションやその他の購読特典を利用するには、info@risk.net にお問い合わせいただくか、こちらの購読オプションをご覧ください: http://subscriptions.risk.net/subscribe
現在、このコンテンツを印刷することはできません。詳しくはinfo@risk.netまでお問い合わせください。
現在、このコンテンツをコピーすることはできません。詳しくはinfo@risk.netまでお問い合わせください。
Copyright インフォプロ・デジタル・リミテッド.無断複写・転載を禁じます。
当社の利用規約、https://www.infopro-digital.com/terms-and-conditions/subscriptions/(ポイント2.4)に記載されているように、印刷は1部のみです。
追加の権利を購入したい場合は、info@risk.netまで電子メールでご連絡ください。
Copyright インフォプロ・デジタル・リミテッド.無断複写・転載を禁じます。
このコンテンツは、当社の記事ツールを使用して共有することができます。当社の利用規約、https://www.infopro-digital.com/terms-and-conditions/subscriptions/(第2.4項)に概説されているように、認定ユーザーは、個人的な使用のために資料のコピーを1部のみ作成することができます。また、2.5項の制限にも従わなければなりません。
追加権利の購入をご希望の場合は、info@risk.netまで電子メールでご連絡ください。
詳細はこちら 規制
SRBのトップは、「規制者たちは次なるクレディ・スイスのような事態によりよく備えている」と述べる
FSBは国際間協力に関する指針を強化していますが、EUにはさらなる相互支援が必要です
柱から柱……そしてポストへ:欧州のオペリスクの行方は?
専門家たちは、DORAの知見を踏まえた、強化された第2の柱の要件の方が、画一的な第1の柱よりも有用であると考えている
PRAは、FRBのFRTBモデリングに関する動きに追随するのに苦戦している
市場リスクの専門家によると、米国の規制における些細な違いが積み重なり、IMAの導入を後押しする要因となっているとのことです。
単一報告の状況にとっての一筋の光は、欧州の希望を維持する
ESMAが取引報告の委任に関する提案を行ったにもかかわらず、業界の要望が叶う可能性はまだあります
EUの競争力強化計画は、大きな立法上のハードルに直面している
大規模かつ物議を醸している一連の法案は、その内容が曖昧すぎるため、迅速な成果を上げられない可能性があります
FDICは、SVBの教訓を再認識し、破綻処理の仕組みを見直している
要件の縮小には賛同する声もある一方で、懸念も残っています
ステーブルコイン・コンソーシアムは、銀行による単独発行に向けた「過渡的な」段階である可能性がある
シティグループの元決済部門責任者であり、Ubyxの創業者である同氏は、すべてのG-Sibsが独自のコインを発行するようになると述べています。
単一報告:ESMAの10億ユーロ規模の改革は、全体像を正確に把握できるのか
批判派は、3つの報告制度を統合する計画は、ほとんど成果が上がらず、一方的な報告とは相容れないだろうと指摘しています。