South Carolina Department of Revenue Hacked, 3.6 Million SSNs Taken 112
New submitter Escape From NY writes "3.6 million Social Security numbers and 387,000 credit and debit card numbers were stolen from the SC Department of Revenue. Most of the credit and debit card numbers were encrypted — all but about 16,000. There were several different attacks, all of which originated outside the country. The first they're aware of happened on August 27, and four more happened in September. Officials first learned of the breach on October 10, and the security holes were closed on October 20. This is still a developing story, but anyone who filed a SC state tax return since 1998 my be at risk. Governor Nikki Haley today signed an executive order (PDF) to beef up the state's IT security."
Love their response (Score:2, Informative)
No worries, every single citizen of South Carolina--just call this skeevy company that offered us free credit protection and give THEM your personal info too.
And also, the phone lines are busy. And the website doesn't actually work. And the offer is just a scam to try to try to get you on the hook for their "upgraded" service, which you'll never be able to cancel.
Sorry, you didn't expect the state to actually PAY to fix this mess did you?
Also, the Governor forgot to mention that one of her first acts in off
Re: (Score:2, Funny)
That's OK. Security's fixed now; the governor signed an executive order that made it so.
Re: (Score:1)
With the GOVERNATOR, the criminal would already be dead ;)
I'll be back!
Re: (Score:2)
why bother (Score:4, Insightful)
obviously there is no repercussions to the vendors, administration and IT staff.
Re: (Score:2)
You assume they are at fault, but it is possible a zero-day vulnerability was used and there was absolutely nothing they could reasonably have done.
Disclaimer: I didn't read TFA.
So when is someone going to swing? (Score:5, Insightful)
This is yet another fine example of Government security doing its usual - leaking like a sieve, in clear violation of Statutory data security requirements. I'll make a prediction right here: some anonymous H1B or lowly DEC will catch it and be fired, notwithstanding the fact that the buck should stop not there, but at the feet of the DCM or the Executive who will continue to collect seven digit salaries.
Re:So when is someone going to swing? (Score:5, Insightful)
I'll play devil's advocate here...
The true fault lies with the lazy citizens. They demand every government agency put their stuff online so they don't have to get off their fat asses and actually do something in person. The fault lies in the citizens always screaming "no taxes to pay for the services I demand". The fault lies with the citizens screaming for "less government" yet expecting government to do everything for them. The fault lies with the citizens who demand lowest bids be accepted for contracts allowing inferior products and services.
Two things come to mind...
Be careful what you wish for. You just may get it!
and
You get what you pay for.
Re:So when is someone going to swing? (Score:5, Insightful)
The fault lies with the citizens screaming for "less government" yet expecting government to do everything for them.
Sorry, mate, but I'm one of the ones who says "less government", and I also say "stop doing things for me that I can do better myself." Trying to paint all people who call for less government with the same brush as those who feel the government should be a nanny state is a mistake, and leads to a sloppy and fatally flawed argument.
Re: (Score:2, Insightful)
So when the crime rate goes up because of your less government you will remain silent right? When your house burns down because they closed the fire department that was closest to you you won't complain right? When the hurricane hits the east coast next week you won't have a single comment on how the government handles the response right?
Right....
Re:So when is someone going to swing? (Score:5, Insightful)
So when the crime rate goes up because of your less government you will remain silent right?
Unfortunately for your rant, the things you want to claim I've been calling for less of aren't. You don't know, so please stop making a fool of yourself.
When the hurricane hits the east coast next week you won't have a single comment on how the government handles the response right?
Yes, I will. I will say "those idiots who build houses on a coast that both erodes on a regular basis and is innundated by storms should not get taxpayer support in rebuilding. They chose to live there despite the dangers, they should assume the risk.
Re: (Score:2)
Did you ever consider that they might not have had a choice? Perhaps they were born in that area, got a job there and needed to live within commuting distance. Couldn't just up-sticks and move inland.
I think most people would prefer not to have to be building engineering and geological experts and instead just have the government figure out what is safe and set some rules for building houses.
Re: (Score:2)
Did you ever consider that they might not have had a choice? Perhaps they were born in that area, got a job there and needed to live within commuting distance. Couldn't just up-sticks and move inland.
The people who build or buy $2 million homes on the beachfront were neither born there, got a job there, nor are they so poor that they cannot afford to move somewhere else. In fact, many of those million dollar homes built on stilts are VACATION properties that they are busy renting out for big bucks whenever they aren't using them. Their jobs are in DC or New York or someplace else, they aren't commuting from the Outer Banks of North Carolina.
I think most people would prefer not to have to be building engineering and geological experts and instead just have the government figure out what is safe and set some rules for building houses.
Yes, most people would rather have a nanny state where some c
Re:So when is someone going to swing? (Score:4, Insightful)
So when the crime rate goes up because of your less government you will remain silent right? When your house burns down because they closed the fire department that was closest to you you won't complain right?
Texas has no income tax yet has fire departments, police departments, schools, roads, and so on. California has the highest income tax, yet far crappier roads (seriously, the don't even light the freeways in town, and they're full of potholes), though the schools might be better (that tends to vary more between neighborhoods than between states, though).
Here's a clue: the "infrastructure" part of government only takes a very small government to do. Mostly, government takes your money to give it to supporters
When the hurricane hits the east coast next week you won't have a single comment on how the government handles the response right?
Florida has no income tax, and had great government support when 4 hurricanes hit that one year (I was living there at the time). They even had a Republican governer that stood up against insurance companies and forced the to continue offering insurance that covered hurricane damage.
You don't need a government that vacuums all possible cash form its citizens to do the good stuff government does - you only need that only to hand over vast sums of money to governments friends.
Re: (Score:3)
I couldn't let this one slide since I was in FEMA during that time...
Florida gets far, far, far more federal dollars than it contributes especially in disaster response. Hell, there are still about 2,500 federal employees still
Re: (Score:2)
And collective that's a trivial part of the federal government. The "non-military, non-mailing-checks-to-supporters" part of the federal goverment -pretty much everything all active, non-military federal employees do, is about 20% of the federal budget. Probably couldn't make that work with no income tax, but it's still cheap. The federal government is a pension plan with a military -the actual productive work it does is almost an afterthought, budget-wise.
Re: (Score:2)
Florida gets far, far, far more federal dollars than it contributes especially in disaster response.
So? You seem to think that anyone who wants smaller government must accept no federal money under any circumstances. You can have a smaller government and still have federal aid in times of disaster. Maybe not aid to people who build in known-hazard areas, but when a hurricane rips all the way across a state, not everyone is in a known-hazard area. Or when the levies break. People who build right on the shore, and build on stilts because they know floods happen on a regular basis, however, are a different
Re: (Score:1)
Re: (Score:3)
You are totally right penix1!
Instead of reducing government waste, we should actually increase it. Just think! Almost no crime, or fires if we had 10x the government we do now. And in order to pay for it, instead of them taking 18% of you paycheck, they will only have to take 180% of it! What a utopia that would be!
Re: (Score:1)
I never see anyone calling for less government expecting the government to do everything for them.
Perhaps you missed Eric Cantor asking for Federal Disaster assistance after the east coast earthquake?
Or the fact that SC receives FAR more money from the Feds than they contribute...
Or perhaps the ever hilarious Tea Party signs "Keep your government hands off my Medicare"
Re: (Score:2)
Re:So when is someone going to swing? (Score:5, Interesting)
I'll play devil's advocate here...
The true fault lies with the lazy citizens. They demand every government agency put their stuff online so they don't have to get off their fat asses and actually do something in person. The fault lies in the citizens always screaming "no taxes to pay for the services I demand". The fault lies with the citizens screaming for "less government" yet expecting government to do everything for them. The fault lies with the citizens who demand lowest bids be accepted for contracts allowing inferior products and services.
Two things come to mind...
Be careful what you wish for. You just may get it! and You get what you pay for.
Nope. SC is accepting credit cards. They are under the same requirements (PCI) as all other MERCHANTS who wish to accept credit card payments. They weren't PCI compliant (I'll go out on a limb and 'guess' that's the case), and they got hacked.
They need pay the fine to Visa. That'll be interesting to see how that happens.
I walked out of a company, where I built the IT and PCI Compliance, because exactly what the parent says will happen - does happen. I just got out before the morons in charge let us get hacked and I got fired for their idiocy. I can only imagine what happened to the IT guys at CardSystems.
Re: (Score:2)
Because their citizens demanded it.
Re: (Score:2)
This is yet another fine example of Government security doing its usual - leaking like a sieve, in clear violation of Statutory data security requirements. I
Have you SERIOUSLY not paid any attention to the massive, massive amount of data security breaches that have occurred over the last 10+ years? MOST of them are from private industry. How many times did Sony get 0wn3d in 2011.. like 10?
The problem really has nothing to do with "Government security doing its usual", it's a problem across the board. Yo
Re: (Score:2)
um...yes [independent.co.uk], actually [guardian.co.uk] I have [bbc.co.uk]. Those were just a few out of my bookmarks. OK, some of them were subcontractors to Government departments, but there are more than an insignificant number of breaches there that were quietly swept under the carpet that were entirely down to Government agents being either totally stupid or deliberately making sure that that data got out. Who knows how many breaches of remarkable severity go unreported?
Re: (Score:2)
Also the Governor of SC already cut funding and personnel to the state IT depts.
So Yea, I would agree that it's not likely to have been an honest mistake and the eventual consequence pf government action.
You can cut corners all you like but at the end of the day, security and redundancy do cost money.
The horses have run (Score:4, Funny)
breached on October 10 (Score:1)
The first they're aware of happened on August 27, and four more happened in September [...] breached on October 10, and the security holes were closed on October 20.
What's wrong with this picture?
Re: (Score:2)
Re: (Score:1)
Re: (Score:1)
Forget the credit and debit card numbers. TFA "none of the Social Security numbers were encrypted". Amusing the summary cherry picked the most useless info.
Re: (Score:3)
Can we fire the government?
Apparently early voting has already started if you want to fire the current group. Not that that will make a big differenced for this kind of activity.
Re: (Score:2)
No early voting in SC. Might cause an increase in Democratic votes.
Re: (Score:1)
Yes, you can
Re: (Score:2)
Re: (Score:1)
"Can we fire the government?"
Not in SC, which is run by crony rustic dumbfuck white trash Scary Republican Base/Christian Taliban and their sock puppet/token brown person Nicky Haley.
The alternative, exemplified by Congressman Clyburn, is even worse.
The only consolation is most people here deserve it.
Re: (Score:2)
Icing on the cake (Score:1)
In other news, Cybersecurity consultants have seen a 18% increase in their hourly rates in the South Carolina area.
Re: (Score:2)
Cybersecurity consultants
Who do think broke in in the first place . . . ? It's called market making . . .
"Only" 16,000 credit/debit numbers at risk (Score:5, Insightful)
Re: (Score:2)
oh, they have that in the US as well? Here it's covered by section 71 of the Serious Organised Crime and Police Act 2005, where blanket immunity is given for any public agency which turns evidence in *any* *other* *proceeding*.
Re: (Score:2)
addendum: what I don't get is this: they broke the Law, why should they get to hide behind it?
Re: (Score:2)
addendum: what I don't get is this: they broke the Law,
Which law? Is there a law that says government agencies must encrypt certain information when they store it? Is there one that makes the government the criminal when a real criminal breaks in and steals data?
Re: (Score:3)
In answer to your first question: Data Protection Act 1998. In answer to your second question: the same Act, under the heading "Offences by Bodies Corporate", which includes actionable negligence.
Re: (Score:2)
In answer to your first question: Data Protection Act 1998.
Nice try. Last time I checked, South Carolina wasn't in the UK, so the UK Data Protection Act of 1998 wouldn't apply. I think the odd spelling of "Offences" might have been a give-away. We'd have called it "Offenses".
Re: (Score:2)
some folks may decide to pay the tax bill on a CC and or they used it to pay for the tax prep (plus they may also have actual bank account numbers for DD of a refund).
Re: (Score:2)
some folks may decide to pay the tax bill on a CC and or they used it to pay for the tax prep (plus they may also have actual bank account numbers for DD of a refund).
Don't forget people who may have elected a direct deposit of any tax refund. They may have had their bank account details compromised as well.
Re: (Score:2)
Why do they even need credit card numbers to process tax returns? I am not American, so maybe I'm missing something in how you handle things, but seriously, why?
They don't need them, and I've never given them mine. You may, however, elect to pay your taxes with a credit card.
Re: (Score:2)
I wonder where the decryption key to the rest of the numbers where stored ...
This could explain the break-in and theft of over 200 Post-it notes.
Re: (Score:2)
Well - that's reassuring! So, "only" 16,000 people potentially have their life savings at risk,
Uhhh, what? None of the data was encrypted, according to the actual article. Why the summary says most of it was is a mystery. So all of the millions have their credit/debit info exposed.
Why you are claiming they have their "life savings" at risk, I don't know that, either. A public statement of this kind pretty much puts the credit card companies on notice that their reports of fraud are going to go up, and you don't lose your life savings just because someone steals your credit card data.
Similarly, you
Re: (Score:2)
You are wrong about the type of risk (Score:2)
South Carolina (Score:2)
Re:South Carolina (Score:4, Interesting)
Ah the wonders of the American Education System
Re: (Score:2)
Ah the wonders of the American Education System
Oh, the system we don't put money in?
Re: (Score:2)
Oh, the system we don't put money in?
No, the system we keep throwing money at as if simply throwing money at the system would fix it.
You can hire a thousand teachers so the class sizes are all less than one student per teacher, and as long as the teachers are hamstrung by federal requirements (and local requirements implemented to deal with federal and state requirements), you'll not get good results.
Re: (Score:2)
The classes with less than one student per teacher don't do well.
Re: (Score:2)
But I'll just point out that the statement was a bit of hyperbole in a reductio ad absurdum manner. If reducing class sizes is good, then reducing them even more must be gooder, and the lower limit is somewhere below one student per teacher. That's "throwing money at the system" for a result that is absurd.
Re: (Score:2)
Wait, are you serious? Last I checked, most teachers were earning well over the US median wage, with a few of them earning much more than that. Only a handful are earning anything near a below standard salary -> we've heard it in the press, how they're earning $10-30,000 more than the median wage of the people of their surrounding community.
On top of that, I don't know of a teacher alive who wouldn't testify against the corruption of the administrators / supervisors of their school districts. Not one.
You
Wrong slogan (Score:2)
North Carolina claims "first in flight", and has that phrase on the license plates, and South Carolina does not. Please don't confuse North Carolina with South Carolina.
Re: (Score:1)
Re: (Score:2)
I'm sure if you tried you could squeeze "fuck" in there a few more times.
Re: (Score:2)
Re: (Score:2)
I'm sure if you tried you could squeeze "fuck" in there a few more times.
Hell, it's not even challenging. He could have gone, "Except the fucking plane fucking flew first in fucking North fucking Carolina. Fuck yourself you fucking fuck. Fuck!"
Re: (Score:2)
Meow meow meow meow meow meow meow meow meow meow
In a sentence, no, but you didn't ask for that.
Re: (Score:2)
Dayton was at its time a mini-Silicon Valley: a hotspot for innovation, bringing us people like the Wrights, Charles Kettering and John Patterson.
North Carolina is just windy.
Re:Spy Handler (Score:2)
First to run his mouth, last in 20th century American History
Re: (Score:3)
NC was first in flight.
SC was first in fight.
Re: (Score:2)
"First in Flight" is a bit north of here. Try "Smiling Faces. Beautiful Places."
COBOL on IBM-360 emulation (Score:2)
Re: (Score:2)
Don't know about the state, but the county level agencies still run a ton of OS/400 stuff written in COBOL. Suggestions to replace the aging codebase with something newer are quickly reigned in when they hear about the cost involved.
Why are SSNs secret? (Score:2)
A social security number is just a hash code to numerically identify a person. Kind of like a full name, except a little more precise. It was my student ID for both undergrad and grad school. It has since turned int a closely guarded secret, although it is included on the paperwork of pretty much anything you sign. There's got to be a better way.
Re: (Score:2)
The SSN system is stupid, but the CC system isn't any better.
You have to give a single set of numbers to a merchant (or other) and hope that not a single one fucks up, or you have to cancel the whole card and all the stuff (e.g. recurring payments) associated with it. It's fucking braindead, especially nowadays.
Here we like to complain about our banks, but at least we have decent payment system where the payer and not the payee initiates the transaction, as it should. Not to mention free virtual CCs for whe
Re: (Score:2)
I think the Swedish experience is that its national ID number doesn't do anything all that significant (none of the purposes you noted here would be severely inconvenienced or affected if you just used another number.)
In short, stealing someone's Swedish number doesn't achieve much.
The US uses the SSN as a gateway to the person's financial history.
Get a credit freeze (Score:3)
Credit freeze [wikipedia.org]
"A credit freeze, also known as a credit report freeze, a credit report lock down, a credit lock down, a credit lock or a security freeze, allows an individual to control how a U.S. consumer reporting agency (also known as credit bureau: Equifax, Experian, TransUnion) is able to sell his or her data. The credit freeze locks the data at the consumer reporting agency until an individual gives permission for the release of the data."
You have to pay each of these companies $10 for the privilege, but it's worth it.
Of course, any time you need to do something that requires a credit check (take out a loan, apply to lease an apartment, apply for a job (sometimes)...), you'll have to temporarily lift the freeze, which is another fee.
Re: (Score:2)
Re: (Score:2)
Actually they all have web forms available:
Experian [experian.com]
Equifax [equifax.com]
TransUnion [transunion.com]
So that's where that account came from... (Score:1)
Not "stolen", they've been shared (Score:2)
They're just data, right? Copying them doesn't take them away. You can't steal numbers.
Applies to music and movies, applies to any other data.
Re: (Score:2, Funny)
Uh, for those who missed it, "SSN" is the Navy term for a nuclear submarine.
(SSN = "ship, submersible, nuclear")
So the headline saying "3.6 million SSNs taken" is a bit disconcerting, if you're reading the wrong acronyms.
Re: (Score:2)