Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Sunday, 26 March, 2023
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

850,000 person data stash included credit card numbers in plain text

by The Gurus
November 22, 2013
in Editor's News
Share on FacebookShare on Twitter

A large stash of data was hacked recently, exposing the personal and financial information on more than 850,000 Fortune 500 CEOs, lawmakers and A-list celebrities.

Reported by Brian Krebs to have been found on the same servers as the Adobe source code, the file “CorporateCarOnline” the plain text archive apparently contained 850,000 credit card numbers, expiry dates and associated names and addresses, with more than one-quarter (241,000) including  high or no-limit American Express accounts.
Those names included basketball star LeBron James, NFL quarterback Aaron Rodgers, actor Tom Hanks and businessman Donald Trump. Krebs pointed out that such information would be extremely useful in the hands of nation-state level attackers or for would-be corporate spies or for those engaged in other types of espionage.
In terms of how it was released, points were made to a vulnerability in its implementation of ColdFusion that has become a favourite target of the attackers thought to be responsible for this and other aforementioned breaches of late.
The Missouri company in question seemed unwilling to talk about the incident. Fred Touchette, senior security analyst at AppRiver, said: “This is a major haul for the bad guys. You would really think that people have heard enough of these stories to stop thinking that this could never happen to them. Years of high-profile, high-valued data kept in plain text on a server for anyone to come and get.
“To add insult to injury, this wasn’t just names and credit card numbers either, this was a wealth of information that could allow attackers the ability to create highly customised attacks, spear phishing or direct malware deliveries with a very convincing front. Businesses can’t afford to allow security to be an afterthought any longer, it needs to be built in, because discovering that you should have had it after the fact will cost much more in the end.”
FacebookTweetLinkedIn
ShareTweetShare
Previous Post

PCI version 3.0 released with greater focus on modern attacks and authentication

Next Post

Trusted Internet Movement launches and seeks data sources

Recent News

Synopsys discover new vulnerability in Pluck Content Management System

Synopsys discover new vulnerability in Pluck Content Management System

March 24, 2023
Dole Food Company

Dole confirms employee data was breached following February ransomware attack

March 24, 2023
call centre

MyCena Improves Customer Data Access Protection in Call Centers and BPOs

March 23, 2023
Blue logo, capitalised letters. SPECOPS.

Fortune 500 Company Names Found in Compromised Password Data

March 23, 2023

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

This site uses functional cookies and external scripts to improve your experience.

Privacy settings

Privacy Settings / PENDING

This site uses functional cookies and external scripts to improve your experience. Which cookies and scripts are used and how they impact your visit is specified on the left. You may change your settings at any time. Your choices will not impact your visit.

NOTE: These settings will only apply to the browser and device you are currently using.

GDPR Compliance

Powered by Cookie Information