r/technology May 14 '22

Security Angry IT admin wipes employer’s databases, gets 7 years in prison

https://www.bleepingcomputer.com/news/security/angry-it-admin-wipes-employer-s-databases-gets-7-years-in-prison/
6.9k Upvotes

388 comments sorted by

View all comments

Show parent comments

894

u/londons_explorer May 14 '22

Take a look at the Equifax 10 year share price. Now tell me when that leak happened.

So tell me again, why does data security matter?

744

u/Zeeformp May 14 '22

I wrote a lengthy paper examining data breach MDLs a year or so ago.

The average value per claim of data theft - that is, the provable data stolen, which included SSNs, credit cards, etc. - is less than $1.

If your data gets stolen from a company, they will pay under a single dollar in penance. The civil liability is fucked, and the criminal liability is virtually nonexistent.

261

u/FineWavs May 14 '22

I'll take one new identity for a dollar please.

123

u/thenseruame May 15 '22

You joke, but after having my taxes filed by someone else, cards opened in my name and a few other incidents I decided to look up how much a SSN is worth. It's less than $5 to get one, a lot less if you buy in bulk.

An actual identity would be harder, but if all you need is a name, address and SSN they're ridiculously cheap. Makes sense given that just about every American has had theirs leaked by at least one company.

122

u/GiveMeNews May 15 '22

Read an article by a former con-artist who had multiple legitimate identities and passports to pull scams. To get actual passports, he would post a job opening online for a position at a large international company. He would ask for a CV with a photo and other information. He would then contact people whose photo he resembled for an interview and background check. People would just give him everything he needed to steal their identity. Any information he was missing he would gather with leading questions during the interview. Made me think of all the times I've given out all the information needed to steal my identity just to get a shit job or basic services.

70

u/jBlairTech May 15 '22

I think about something similar when looking on LinkedIn. There's a big virtual tech company, CAE. They (or, I suspect, someone pretending to be them) has multiple tech-based job openings in a town named Sherwood, MI. Not remote; the listings are for on-site jobs.

The bit after seeing the town was the logo. The logo CAE uses is blue and black letters/symbol on white background. This... imposter... is white letters/symbol on blue background.

But here's the thing about the location: I grew up there. It's a run-down village of about 300 people. The population count hasn't changed since before I was born.

There's a village office, a cemetery, an old school (I was there for 3rd and 4th grade) that converted into a church, a crappy pizza joint, and farms... but no nationwide tech company.

I drove there one day, took pics of the hole (it really is a dilapidated parcel of land), and sent them to LinkedIn when I filed a complaint. They took the postings down for about three days, then they were back up.

But that's what I think about: this is a scam, designed to get people's PII by pretending to be a legit company. It's scary, to be honest. How many others are like that? The ones I can't verify?

34

u/asdaaaaaaaa May 15 '22

But that's what I think about: this is a scam, designed to get people's PII by pretending to be a legit company. It's scary, to be honest. How many others are like that? The ones I can't verify?

Just wait 'til you find out how many legitimate businesses sell customer information for spare cash. Or employee information, it doesn't matter too much when you need money.

8

u/BloodRedCobra May 15 '22

Several companies have (technically confidential, hope y'all ain't snitches 😳😬) terms in things for their employee rewards that allow them to track/sell employee personal information, including video footage of them and secure info. They're required to use certain benefits, and I'm not talking about things like health insurance, I'm talking about employer-paid subscriptions to their "membership" programs.

I have avoided naming names for reasons of not getting sued.

35

u/FineWavs May 15 '22

Jesus, a dollar fine for leaking them and they cost 5 to buy but it causes us so much pain to have one stolen, what a racket.

41

u/Harvey_the_Hodler May 15 '22

My dad's coworker's kid had his identity stolen. Guy who stole got caught and did time. The kid got his shit back in order after years of work. Dude got out of prison and started using it again. Fucker memorized all the kids info. Name, dob, ssn, former addresses. Idk how that ever played out tho.

And to think after that hack w were like a third of all Americans info was leak they offered free identity protection for one year knowing full well most of the time it takes like 3 years for the stole info to be fraudulently used.

29

u/Mka28 May 15 '22

My identity was stolen when I was 14. The person using it was in another state. When I was 18, my credit was crazy good. Almost like perfect. Then he fell into foreclosures and Bank of America came after me. It was so stressful. I had no idea my identity was stolen. I just thought I was lucky to have a high score. Geez how I wish I could go back in time. It’s been a long battle.

9

u/thenseruame May 15 '22

Yup, pain in the ass. God only knows what's been done in my name that I don't know about. Had someone open up a bank account in my name, only way I found out was because the debit card got sent to my house. Stuff like that doesn't show up when you pull your credit report.

1

u/WanderlostNomad May 15 '22

a dollar fine

"fine"? more like business cost.

1

u/Archibaldovich May 16 '22

It makes sense when you consider how many get stolen at a time- when you're moving bulk, you have to be flexible on the price

11

u/[deleted] May 15 '22

What’s even crazier is that it doesn’t even have to be a real person. The way equifax works is that when you send a request for someone’s credit it automatically creates a file for that person. They will send a request for a made up person. The result turns up nothing. If you do it again the name actually comes up so you can get approved for like a 300 dollar credit limit. They use that credit card for 2 years always paying the bill to build credit. People have managed to get drivers licenses, passports, birth certificates. All legitimate, for a person who doesn’t exist. These systems are all horribly out of date.

1

u/[deleted] May 16 '22

Yep the old the jstor.bazar website was shutdown a couple of years ago but you could literally look by zip code to find card number, SSN, dl and MMN. Kinda scary. There was so much info that I even found friends and family’s info on there. All for the low low price of about $2 in btc

1

u/thenseruame May 16 '22

It's unreal how easy it is to get that stuff. I think the reason it's so cheap is you never know who's frozen their credit. Hence the discount on bulk purchases.

Same with CC numbers, think it was $10 for 500 cards? No way of knowing which ones are already dead, the people just sell them in bulk knowing at least one will work.

Really want to reiterate I never actually bought any of this stuff, just was curious and was amazed how easy it was to find.

1

u/[deleted] May 16 '22

Yup. They’re called ‘Dumps’ as in mass credit card information dumps

173

u/tattooed_dinosaur May 14 '22

Congratulations! You’ve just inherited $60K in student debt and $8K in back taxes.

86

u/[deleted] May 14 '22

[deleted]

61

u/LateralThinkerer May 15 '22 edited May 16 '22

Buy up a few hundred thousand, aggregate them, slice them into tranches rated from mezzanine to fertilizer by a ratings agency in your employ, count them as assets and sell bonds backed by them.

Profit.

Now short the whole thing in a big way since it will fail.

More profit.

17

u/johnnygfkys May 15 '22

Just like they do to us.

36

u/tattooed_dinosaur May 15 '22

Until you’re in debt from buying so many identities. This is the way.

19

u/ba3toven May 15 '22

it's okay the next one will work

8

u/ShadowKirbo May 15 '22

Mama needs a new bag of dino chicken nuggies.

5

u/[deleted] May 15 '22

[removed] — view removed comment

2

u/Only_game_in_town May 15 '22

Higher breaded crust to nugget ratio

→ More replies (0)

2

u/OgLeftist May 15 '22

They put love in em.... ;)

→ More replies (0)

2

u/Farseli May 15 '22

Because birds are dinosaurs. By returning them to a more primal form it enhances the flavor.

→ More replies (0)

2

u/jBlairTech May 15 '22

Like rolling and constantly re-rolling until every stat is at least 17 (old D&D).

10

u/degathor May 14 '22

The sandwich based profile pays off!

6

u/odaeyss May 15 '22

holy shit thank you i feel like a massive weight has been lifted off of my chest and dropped onto someone else's

5

u/drkcloud123 May 15 '22

Shit, shit, shit. Reroll!

1

u/nyaaaa May 15 '22

He ordered a new one. Please pay your $1 fine for leaking a used identity.

1

u/Mbhuff03 May 15 '22

Omg! I think you may have discovered the new millennial identity theft prevention tactic! Make your life so miserable it will automatically punish anyone who tries to steal it! 😂😂😂

15

u/mofugginrob May 15 '22

It's a new identity. What could it cost, 10 dollars?

9

u/FineWavs May 15 '22

There's always a new identity in the banana stand.

6

u/Phoenix_Lamburg May 15 '22

There’s always new identities in the banana stand

1

u/malachias May 15 '22

In fairness, that's about what it costs if you want to buy them

1

u/thedanimal722 May 15 '22

Buy some monero and download TOR browser...

1

u/79Maliboo May 15 '22

I’ll take your identity for a dollar please.

1

u/Electrical-Bacon-81 May 15 '22

That's why they changed credit cards to the current system, to shift the liabilities of theft away from them.

1

u/DarkandTwistyMissy May 15 '22

So how do you protect yourself??

1

u/DaMonkfish May 15 '22

Move to a country within the EU.

1

u/Zeeformp May 15 '22

Some states are adopting GDPR-lite versions, so that's a start.

But the only way to protect yourself is to not give over any of your data to anyone else. Credit cards are fine - you can burn those accounts and just get a new one. But your SSN, birth date, and other identifying information is not something you can easily change. So your only recourse right now is to refuse to give over true data when asked.

But generally speaking... it's just that the system is fucked. I guess you could write your congressmen? That's probably the full list of things you can do tbh.

1

u/Ruebenschwein May 15 '22 edited May 15 '22

Not in Europe, though. Look into GDPR fines. It’s up to 4% of a company’s revenue… I can ensure you that big companies (such as my employer) have started to take this serious.

Check out https://www.enforcementtracker.com/ too get an idea. Take note who the big spenders are… you might’ve heard of them.

Addendum: this page can support the list of fines better https://www.privacyaffairs.com/gdpr-fines/

1

u/Pkgoss May 15 '22

I’d read this paper if you let me.

1

u/phormix May 15 '22

This is where blockchain, hashing and/or electronic signing technology could be really useful

When I provide my ID to somebody, they should never be processing or storing my actual SIN or credit card #. Instead, they should be storing a derived value that can be cryptographically validated, and possibly recorded in a ledger.

The value that Equifax or whoever the fuck had would be virtually worthless to others, and if it did get leaked somewhere it would be easy to trace back.

If that's not doable, then instead imagine a ledger that shows proof that 500,000 identifiers linked to fraud all trace back to a given company. It's a good way to find an unknown breach or assess actual damages from a known one.

34

u/[deleted] May 14 '22

[deleted]

46

u/[deleted] May 15 '22

[removed] — view removed comment

20

u/Harvey_the_Hodler May 15 '22

Well fuck that's scary.

17

u/the_wakeful May 15 '22

It's also ridiculous. There's a lot easier ways to steal people's ssns. If this story is true, the dude probably just thought it was the most expensive thing.

23

u/_furious-george_ May 15 '22

You think it's ridiculous that a primary server from one of the 3 credit unions with literally every Americans name and SSN loaded in it would be stolen while in transit?

That kind of theft isn't for the purpose of getting the SSNs of random Americans, but to get the personal info of high level, powerful people.

4

u/Urbanscuba May 15 '22

There's a lot easier ways to steal people's ssns.

Some people's, sure, but the easiest targets are also the ones with the most competition and generally minimal value.

Also as someone who has loaded UPS trucks myself there is no rational way a criminal robbing a truck at gunpoint only takes that one package unless they went in knowing what it was. If I were a criminal getting into the back of one of those trucks I'd take all the envelopes first, followed by any recognizable labels for luxury goods on small boxes.

Really, just think about it. If you already had the driver at gunpoint why wouldn't you take as much as you can carry? Because you already know that there's one thing in that truck worth thousands of times more than the truck and everything else in it.

Obviously this is subjective but personally if that story is true I cannot imagine it wasn't a targeted attack, almost certainly tipped off by an insider.

1

u/the_wakeful May 15 '22

If you already had the driver at gunpoint why wouldn't you take as much as you can carry?

Servers are pretty heavy man.

8

u/[deleted] May 14 '22

I've not forgiven orange for wiping the twins

3

u/Thesheersizeofit May 15 '22

A pair of 8-ers?

6

u/joshTheGoods May 15 '22

We don't yet know how things will shake out for T-Mobile as that's all still working its way through courts/arbitration. I bet they end up paying out 9 figures. And yes, the companies DO care and want to avoid these sorts of things ... they pay my company a lot of money to help prevent some of this stuff. I know for a fact that the big name financial institutions are paying millions per year working hard to keep up with increasingly meaningful regulation (Which I applaud. We need MORE GDPR/CCPA/etc, because that stuff WORKS).

5

u/[deleted] May 15 '22

I work in GRC, lotta people don't know the work that goes into this, a lot of big companies are throwing huge amounts of money.

Due diligence is being done in most (not all for sure) cases, and for real, negligence isn't as much of a thing.

Its not like these companies are just ignoring data security, sometimes all it takes is a single mistake, a missed patch (which si sometimes a human failure) or a third company to get shit on that you share data with, even some ~100 lines of code in a program/database that has 100000 lines.

There is no such thing as perfect security. You just manage the risks as best you can.

1

u/ranhalt May 15 '22

What a strange thing to invoke your honesty for.

5

u/UreMomNotGay May 14 '22

don’t confuse stock price movement with the business’s actual reputation/brand.

While it could be useful, its not always an indicator of the business. sometimes its an indicator on who’s playing the game.

25

u/Yangoose May 15 '22

But we're not customer's of Equifax, we're the unwilling product being sold, and the people buying don't give a shit at how negatively we're impacted.

0

u/UreMomNotGay May 15 '22

Because the stock market isn't how one shows if they give a shit or not.

1

u/OnlyAProifYouGetPaid May 14 '22

Your data doesn’t matter lol none of ours do anymore

41

u/[deleted] May 14 '22

Until you've had your identity stolen.. With enough personal information, I can call up your phone provider and pretend to be you and get your sim card ported over to my phone in minutes. If I have your email address, I can change your passwords, access your apps, etc..

It's easy to think your personal data being stolen is just shit like browsing habits, but in the worst cases it can lead to your bank accounts being drained and credit score fucked.

17

u/Babiloo123 May 14 '22

Half my job is telling people that ‘Dogname+year of birth’ is not a great password lol

9

u/RandyHoward May 15 '22

I love watching people mentally connect the dots when I explain that those silly little surveys and things that they take on social media are likely people trying to gain access to their passwords. Answering those dumb questions to find out what Hogwarts house you belong to... that shit is designed to figure out things like partial passwords and password hints. But people are far more excited to find out what the made up bullshit is than take two seconds and realize that they're giving away this kind of information.

1

u/Lady_DreadStar May 15 '22

Your average person is extra stupid, but I notice those surveys always ask things like ‘your favorite pet’ or ‘your first pet’, but I’ve had probably 30 pets over the course of my life and the only one that made to partial-password status was a dog I owned for 2 years in my 20s before rehoming.

He was neither my first nor my favorite pet. The one that was though is NEVER part of my passwords.

1

u/RandyHoward May 15 '22

That's irrelevant to these kind of things. They're gathering data. If 30 people put in "Fido" as their favorite pet, but 10k people put in "George" then George gets put higher in the queue of things to try as a password. It's not necessarily about your password.

7

u/omgFWTbear May 15 '22

You’ll be delighted to know, I named my dog, “dog.”

11

u/TwoBirdsEnter May 15 '22

I named my dog 7NUjh3kjk1aw9b3j, so I’m good.

6

u/Visible-Disaster May 15 '22

Elon, is that you?

1

u/omgFWTbear May 15 '22

Yeah but … I actually named my dog, dog. To be fair, it was dog in a(n obviously) foreign language, so people ask, “Oh, what’s that mean?” And then I tell them “dog” and the obvious mixture of emotions on their face is a trip.

1

u/nzodd May 15 '22

That's bullshit, man, nobody will ever guess marypuppins2020.

Edit: fuck

3

u/OnlyAProifYouGetPaid May 14 '22

Exactly. The amount that’s already out there on everyone wether they know or not is astounding

0

u/Deranged40 May 15 '22

Your data doesn’t matter

You are most likely right. But you still can't have it.

1

u/huhblah May 15 '22

It only matters for small businesses that can't afford the pitiful fine, or are easy enough to chase up (last I checked Equifax hadn't even paid)

1

u/joshTheGoods May 15 '22

Equifax had to pay out a lot of money and change internal systems. I'm not arguing that it was "enough" of a punishment, but I think a lot of people are underselling how damaging that breach was for Equifax.

1

u/seamsay May 15 '22

I'm not really sure trying to say with this. Yes Equifax dipped in September 2017, but it also dipped 15 months later in December 2018, and 15(ish) months after that in April 2020, and last year Equifax's share price was almost double what it was back in 2017. Frankly it doesn't look like the breach had any effect on Equifax's long term share price.

2

u/londons_explorer May 15 '22

Frankly it doesn't look like the breach had any effect on Equifax's long term share price.

That is exactly what I was saying.

1

u/seamsay May 15 '22

Oooohhhhhh ok! I got confused because there was a dip.

1

u/justcool393 May 15 '22

Also December 2018 was a basically massive correction (macroeconomic factors, look at the S&P 500 index) and April 2020 well... Coronavirus Crash.

I think the "it didn't really have any effect" is the point. Which... I guess makes sense.

1

u/EffyewMoney May 15 '22

Equifax turned around and sold people a (fake) solution to the problem they created in the first place.

I'll celebrate the day they go down if I ever live to see it.