Data Breaches Continue to Soar

執筆者
Roy Mark
Roy Mark
Published: Apr 15, 2009
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Organized crime successfully cranked up its data breaching efforts in 2008, and it paid off: More electronic records were breached last year than the previous four years combined, according to a new report from Verizon Business Security. The primary target of the thieves was the financial services industry, accounting for 93 percent of all such records compromised last year.
The second annual report from Verizon Business was based on data analyzed from the company’s investigative response team, which found 285 million compromised records from 90 confirmed breaches. More than 90 percent of the thefts involved groups identified by law enforcement as engaged in organized crime.
Even more troubling was Verizon Business’ finding that almost nine out of 10 breaches were avoidable if security basics had been followed. The report concluded that the attacks could have been stopped without expensive or difficult preventative controls.
“The compromise of sensitive information increased dramatically in 2008, and it’s past time to be vigilant about enterprise security,” Dr. Peter Tippett, vice president of research and intelligence for Verizon Business Security Solutions, said in a statement. “This report should serve as another wakeup call that good security and a proactive approach are paramount to running a business in this day and age-particularly since the economic crisis is likely to trigger a further increase in criminal activity.”
Bryan Sartin, director of investigative response for Verizon Business Security, told eWEEK that after the black market rate for stolen bits of personally identifiable information fell from approximately $14 to $15 a record to 15 to 20 cents a record, data thieves in 2008 turned their efforts to stealing PIN information associated with debit and credit cards. PIN fraud usually leads directly to cash being withdrawn from a person’s account.
The higher value PIN information has prompted thieves to re-engineer their processes and develop new tools such as memory-scraping malware and unique packet sniffers. Thieves are approaching PIN snatching in two ways: installing malware to decrypt the PIN when consumers type the information into ATMs or software that deceives the bank’s security systems into providing the PIN decryption key.
“Just seven or eight months ago, these were thought to be an academic exercise: the ability to steal small bits of data while temporarily in memory,” Sartin said. “It takes less than a tenth of a second.”
Despite the sharp rise in attacks in financial services, retail establishments remain the most frequent target of data breaches. Food and beverage businesses, second on the attack list in 2007, fell to third in 2008.
“Our task is not getting any easier; the sum total of information in the world grows continually and permeates everything we do and everywhere we go,” Tippett said. “While the majority of the attacks remain rather mundane, the criminals are adapting to our current protection strategies and inventing news ways to attain the data they value.”

Roy Mark

Roy Mark

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。