Limo Company Hack Exposes Juicy Targets, 850k Credit Card Numbers 43
tsu doh nimh writes "A compromise at a U.S. company that brokers reservations for limousine and Town Car services nationwide has exposed the personal and financial information on more than 850,000 well-heeled customers, including Fortune 500 CEOs, lawmakers, and A-list celebrities. Krebsonsecurity.com writes about the break-in, which involved the theft of information on celebrities like Tom Hanks and LeBron James, as well as lawmakers such as the chairman of the U.S. House Judiciary Committee. The story also examines the potential value of this database for spies, drawing a connection between recent personalized malware attacks against Kevin Mandia, the CEO of incident response firm Mandiant. In an interview last month with Foreign Policy magazine, Mandia described receiving spear phishing attacks that spoofed receipts for recent limo rides; according to Krebs, the info for Mandia and two other Mandiant employees was in the stolen limo company database."
A-List Spear Phishing (Score:2)
Re: (Score:1)
Too bad Brian Krebs is always raining on our parade.
and use adobe PDF reader (Score:2)
that just auto hacks your system when some opens an PDF loaded with hacker tools in it.
Good (Score:2, Funny)
Exposing the personal information of 30 million people wouldn't bother those in power. But those in power having their information hacked? Finally, we may see some protection of data--at least for those in power.
Hold Them Responsible (Score:4, Interesting)
If things like credit card information are stored in cleartext, the corporation doing it should be fined and the people responsible prosecuted if there is a leak. It's just gross irresponsibility, for which nobody has seemed to get punished.
That needs to change.
Re: (Score:1)
When are corporations going to be held responsible for the security of their customers' information?
Probably now since this actually targets someone in charge.
The problem is that the "fix" will be to only hold corporations responsible if someone "important" is hurt.
Re: (Score:3, Interesting)
Re: (Score:2)
Every credit card related info leak is in breach of PCI compliance.
Even if they got audited just a week previously and passed with flying colours.....
We are a limo company not an IT one the outsourcer (Score:2)
The outsource is the one who messed up.
Re: (Score:2)
When are corporations going to be held responsible for the security of their customers' information?
Just as soon as we stop referring to "corporations" as if they were people?
Re:Hold Them Responsible (Score:5, Funny)
I'll believe they're people when Texas executes one.
Re: (Score:1)
I'll believe they're people when Texas executes one.
I guess Texas [idownloadblog.com] did [techdirt.com]
Re: (Score:2)
"Just as soon as we stop referring to "corporations" as if they were people?"
Corporations can be held legally responsible for their actions. Hell, that's one of the reasons corporations were invented.
Re: (Score:3)
When are residents going to be held responsible for the security of their valuables?
If things like cash and jewelery are stored behind unlocked doors, the households storing them should be fined and the people responsible for the storage prosecuted if there is a theft. It's just gross irresponsibility, for which nobody has seemed to get punished.
That needs to change.
I'm exaggerating a little, but this is really how the law works now. The criminal responsibility falls to the guy who thought "I'm going to vio
Re: (Score:2)
Re:Hold Them Responsible (Score:5, Insightful)
Having YOUR stuff stolen kind of is the fine. Your anology doesn't work because in this case, it's not the company's information that was stolen. It was their customers. A bank is a closer analogy but even that doesn't work. I'm pretty sure the bank will compensate you if the contents of your security box is stolen due to their poor security practices.
With this company and the recent Adobe breach, there's no compensation for their customers who had their data stolen. The company gets to just go "Well shucks, I'm sorry guys." Meanwhile, their customers have been exposed to possible identity theft or fraud and they're the ones who have to deal with the consequences.
A couple of years ago, my social security number was stolen from a local university that I took a summer class at. My parents then subscribed to one of those identity theft protection services. Were we ever compensated for the service fees needed to protect my identity? Nope. Would I have been compensated if someone stole my identity and destroyed my credit for life? Nope.
That's the problem.
Re: (Score:2)
Oh yeah for years the community college I went to would use SSN for student IDs. They'd pass around an "anonymized" roll sheet where everyone would sign next to their SSN. At the end of the semester your grades would be posted next to your SSN instead of your name.
Idiots.
Re: (Score:2)
I'm not saying it makes sense for a company to be unaccountable, but only that that's the way the law is set up now. There's a pretty strong fear of blaming the victim in legislature, so I doubt we'll see any such laws crop up soon. Legally, it's the same as a gym's locker room that says "not responsible for lost or stolen items". The law just doesn't make them responsible.
You do bring up an interesting point... why does a university need your federal retirement savings account number?
Re: (Score:2)
My point is that they're not really the victim. Their customers are. The businesses are the conduit. They are the means by which the attacker is able to cause you damage. Framed that way, it becomes clearer that they deserve consequences for their failure.
Re: (Score:2)
When are corporations going to be held responsible for the security of their customers' information?
It used to be that companies really feared being out of compliance with PCI standards [pcisecuritystandards.org] but things must have changed. I don't know for certain but if I had to venture a guess, companies probably find it more appealing to take chances being non-compliant rather than invest in appropriate infrastructure (including competent staff) to support full PCI compliance .
It's *extremely* difficult to sell proper security to management based on potentials. They want numbers to plug into their spreadsheets to measure cost
850K (Score:2, Interesting)
Also known as a list of 850,000 people making a hell of a lot more than I do.
St Louis in the House!!!! (Score:4, Funny)
Hey, I have to take every chance I get to promote my hometown, and that's where this company is based.
A coworker for mine knows someone that used to work for the company, it sounds like they used a custom (homebrew) encryption scheme for the passwords. This could be incorrect, the guy hasn't worked there in a couple of years.
Anyway, we didn't win the World Series, but apparently we can give you Tom Hanks credit card info...
Re: (Score:2)
East St Louis is the best St Louis.
That's a slight exaggeration. But St Louis really is a shithole.
Re: (Score:2)
I'm assuming you were trying to be offensive, but no offense taken. STL is a good "live in" city, better than So Cal (where your 2nd job is sitting in traffic and the state/federal officials seem to be... out of touch with reality - watch out for cancer!!!). Better than Phoenix as well (summer sucks and I prefer "character" rather than a 15 square mile suburb). Same for Vegas on the suburb. All are nice for visiting, but not for living, unless you have millions to spend/waste. Washington state is proba
not THAT rich (Score:2)
Pffft... if they were really rich, they'd have their own fulltime bonded limo drivers on staff. Before you laugh, remember that the suckily rich own huge yachts which have a permanent crew whose only job is to make sure the yacht shows up at whatever port the owner wants his next party to be at.
Re: (Score:3)
"...at whatever port the owner wants.." is kind of a small list of boats.
Just moving even a smallish yacht (75 feet or so) ocean distances is really expensive and/or really slow. Sport yachts capable of 20+ knots cruising speeds can eat double-digit quantities of fuel per hour. Moving from Miami to NYC could take days and tens of thousands of dollars in fuel and most don't have the fuel capacity for major blue ocean transits. Trawler styles use less fuel, but have cruising speeds in the single digits.
I th
Re: (Score:2)
The rich use their yachts primarily as vacation homes. And they rent them out to defray the costs. Or lend them out to impress their buddies.
Re: (Score:3)
Or, just fly your cars (multiple needed for backup and for security details) in your second 747. Poor folks may have to cram the cars into the cargo hold on their primary (and only) 747 -- but that's pretty low class and only trailer trash would consider it.
Re: (Score:1)
Uncle Leo? (Score:1)
Prostitution / Mistress Detection (Score:3)
850,000 Limo Riders? (Score:3)
Cricket (Score:1)