Epsilon breach used four-month-old attack

 

ReturnPath had warned partners of breach in November.

A data breach exposing the customer details of the likes of Citigroup, Hilton Hotels and Dell Australia was part of a series of socially-engineered attacks first reported by an Epsilon technology partner some four months ago, iTnews can reveal.

The world’s largest email service provider, Epsilon, disclosed on April 1, 2011 that the data it manages on behalf of a subset of its 2500 global clients had been accessed by hackers the day prior.

Today iTnews can reveal that Epsilon has been aware of the vulnerability behind this attack for some months.

In late November, Epsilon partner ReturnPath – which provides monitoring and authentication services to email service providers - warned customers about a series of coordinated phishing and hacking attacks levelled at the mailing list industry.

Neil Schwartzman, senior director of security strategy at Return Path’s ‘Email Intelligence Group’ warned its partners of “an organized, deliberate, and destructive attack clearly intent on gaining access to industry-grade email deployment systems”.

He said that the phishing attacks were targeted specifically at employees at email service providers that had specific access to email operations.

Schwartzman offered an example to illustrate:

“Hey Neil, it’s Michelle here, it has been a long time huh ? how’re you doing ? how’s your work with Return Path ? Is everything ok there ? Hey, can you believe it! I got married to Brian ! Yes I did. I tried to call but you did not answer. You have changed your number, haven’t you? Just give meyour current telephone number if you read this mail. It’s really a pity that we did not see you in our wedding. I wanted to invite you so much. Well, here I’m sending you a few pics taken in our wedding:

http://www.weddingphotos4u.net/Photos/Michelle/

Let’s keep in touch then.

Love,

Michelle & Brian”

The link in the body of the email took the user to a page that downloaded three malware programs – one that disables anti-virus software, another (iStealer) that is a Trojan keylogger to steal passwords, and a third (CyberGate) which offers hackers remote administration of the infected machine.

“The potential consequences should ESP [email service provider] client mailing lists be compromised at this time of the year is unimaginable,” Schwartzman told customers.

Schwartzman’s nightmare came true within days.

By December 10, drugstore giant Walgreens – today an Epsilon customer - revealed that it had been the victim of a phishing attack levelled at its customers.

On December 13, fellow email service provider Silverpop Services revealed that it too had “recently detected suspicious activity in a small percentage of customer accounts”, and responded by changing all passwords and engaging the FBI’s cybercrime division.

In the days that followed, it was revealed that McDonalds and Play.com customers had been hit with phishing attacks as a result of this breach.

In an update on December 15, Silverpop chief executive Bill Nussey revealed that the company was “working with industry peers to share what we have learned” from the attack.

Epsilon – the world’s largest email service provider and a ReturnPath partner – subsequently installed systems designed to alert administrators to unusual patterns in the downloading of data.

It was this system that kicked in on March 30, 2011 and the company subsequently informed its clients of a data breach affecting two percent of its large customer base.

“Epsilon is working with Federal authorities, as well as other outside forensics experts, to both investigate this matter and to ensure that any additional security safeguards needed will be promptly implemented,” the company said in a statement overnight.

The challenge for Epsilon will be to now convince its clients that it had done enough to protect their data, considering the number of months it had known of the vulnerability.

Copyright © iTnews.com.au . All rights reserved.


Epsilon breach used four-month-old attack
"Unfortunately, coordinated attacks on ESPs, ISPs, and company databases are occurring every day, much like attempted terrorist attacks around the world. Companies like FreshAddress (www.freshaddres..."
By BillKaplan
 
 
 
Comments: 1
BillKaplan
Apr 8, 2011 12:09 AM
Unfortunately, coordinated attacks on ESPs, ISPs, and company databases are occurring every day, much like attempted terrorist attacks around the world. Companies like FreshAddress (www.freshaddress.com), Return Path, and thousands of other email industry service providers spend a significant portion of their resources protecting their systems and their clients against unwanted intrusions.

This article implies that Epsilon knew about a potential vulnerability months in advance of the breach but there are no facts provided here that support this. Warnings of coordinated attacks are issued every day by thousands of companies so referencing a specific warning from four months ago is certainly no evidence of a smoking gun.

The learning, however, is that companies need to keep a watchful eye on the security measures taken to protect their most prized possession, their customer database. Equally as important, they need to carefully vet the partners and service providers they do business with as saving a few dollars on a project pales in comparison to the costs of having your customer database hijacked by a less than ethical database service provider.
Comments have been disabled for this article.
 
 
Top Stories
Review: Microsoft Surface Pro
A year is a long time in the computer hardware business.
 
 
NBN Co could miss revised June fibre targets
Analysis: Cutting it fine in the race to the line.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

iTnews Academy: Microsoft Windows Server 2012 - Hyper-V
iTnews Academy: Microsoft Windows Server 2012 - Hyper-V
Interview: Australia's 'cloud-last' policy is dangerous.
Interview: Australia's 'cloud-last' policy is dangerous.
Interview: Vivek Kundra on Australia's 'cloud last' policy
Bankwest builds continuous delivery capability
Bankwest builds continuous delivery capability
To automatically deploy test/dev sandboxes by mid-year.
Veterans' Affairs sets sights on modernisation
Veterans' Affairs sets sights on modernisation
Data safe with Human Services, CIO says.
Citi Australia drops platform customisations
Citi Australia drops platform customisations
Technology chief shifts focus from building to leveraging systems.
VicRoads restructures IT team
VicRoads restructures IT team
Department moves to align with industry benchmarks.
Zurich Australia extends IT team offshore
Zurich Australia extends IT team offshore
Malaysian staff served from Australian data centres.
Leigh Berrell - Utilities CIO of the Year
Leigh Berrell - Utilities CIO of the Year
Yarra Valley Water CIO Leigh Berrell accepts his Benchmark Award for Utilities CIO of the Year.
Wayne McMahon - Retail CIO of the Year
Wayne McMahon - Retail CIO of the Year
Domino's Pizza CIO Wayne McMahon accepts his Benchmark Award for Retail CIO of the Year.
Inside Perpetual's ongoing IT transformation
Inside Perpetual's ongoing IT transformation
CIO Jenny Levy discusses how outsourcing will help the firm "simplify, refocus and grow".
Managing Complexity - Defence's Daniel McCabe
Managing Complexity - Defence's Daniel McCabe
Daniel McCabe, Assistant Secretary of Australia's Department of Defence, provides the audience at the iTnews Data Centre Strategy Summit with a deep dive into the organisation's data centre consolidation program.
How Facebook designed the data centre from scratch - Marco Magarelli
How Facebook designed the data centre from scratch - Marco Magarelli
The full keynote by Facebook data centre architect Marco Magarelli at the Australian Data Centre Strategy Summit. Magarelli details the design considerations behind the social network's Prineville, Oregon; North Carolina and Luleå, Sweden data centres.
Modernising Legacy Data Centres - Telstra's Jon Curry
Modernising Legacy Data Centres - Telstra's Jon Curry
Telstra general manager of managed data centres Jon Curry guides the audience at the iTnews Australian Data Centre Summit through the build of the telco's Clayton, Victoria data centre.
NSW Government launches NABERS data centre rating tools
NSW Government launches NABERS data centre rating tools
Matthew Clark from the NSW Department of Environment guides facilties managers through the details of the new NABERS data centre energy rating tool at the Australian Data Centre Strategy Summit.
NABERS launch panel: Australian Data Centre Strategy Summit
NABERS launch panel: Australian Data Centre Strategy Summit
Matthew Clark (NSW Dept of Environment), Greg Boorer (Canberra Data Centres), Glenn Allan (National Australia Bank), Mike Andrea (Strategic Directions) and Bob Sharon (Green Global Consulting) discuss the impact of the NABERS data centre rating.
Judges notes: Fortescue Metals [The Benchmark Awards]
Judges notes: Fortescue Metals [The Benchmark Awards]
iTnews' panel of judges discuss Fortescue Metals 'New World of Work" project, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Retail [The Benchmark Awards]
Judges notes: Retail [The Benchmark Awards]
iTnews' panel of judges discuss the shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: Pacific Aluminium [The Benchmark Awards]
Judges notes: Pacific Aluminium [The Benchmark Awards]
iTnews' panel of judges discuss Pacific Aluminium's lightning fast service desk refresh, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Domino's Pizza [The Benchmark Awards]
Judges notes: Domino's Pizza [The Benchmark Awards]
iTnews' panel of judges discuss Domino's Pizza's shift to hosted services, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: McDonald's Australia [The Benchmark Awards]
Judges notes: McDonald's Australia [The Benchmark Awards]
iTnews' panel of judges discuss McDonald's Australia's new self-service portal for employees, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Latest Comments
Polls
Will you quit any cloud services in light of PRISM?

   |   View results
Yes
  59%
 
No
  41%
TOTAL VOTES: 86

Vote