internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Opera
Internet Explorer 7
QuickTime for Windows
Winamp
Mozilla Firefox 3
Ad-Aware 2008 Free
Adobe Flash Player
Paint Shop Pro
Adobe Shockwave Player
AVG Anti-Virus Free
7-Zip

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

U.S. Lab Falls Victim to Phishing Attack
Sophisticated Targeted Attack Compromises 14 Years of Private Date
Andy Patrizio

One of the most common forms of malware infestation is people clicking on links in e-mails from unknown sources. Now it appears that not even a major U.S. research lab is immune.

The Oak Ridge National Laboratory yesterday disclosed it has been wrestling with a "sophisticated cyber attack that appears to be part of a coordinated attempt to gain access to computer networks at numerous laboratories and other institutions across the country."

The attacks have been ongoing since late October, it said.

In a disclosure on its site, the lab, run by the U.S. Department of Energy, said a hacker illegally gained access to its computers by sending staff e-mails that appeared to be legitimate official communications.

When employees either opened an attachment or clicked on an embedded link in the e-mail, they installed a Trojan that surreptitiously copied and retrieved information.

The lab said the attack began Oct. 29, and that it believes data was stolen from a database used for visitors to the facility. As a result, personal information belonging to personnel visiting from 1990 to 2004 may have been stolen, including the names, social security numbers, and birthdates.

No classified information appears to have been lost, the lab said.

On Monday, Lab Director Thom Mason disclosed in an e-mail to staff that after weeks of research, he believed that thieves made "approximately 1,100 attempts" to steal data. According to the letter, he said they used a sophisticated strategy that involved sending staff seven targeted phishing e-mails, all of which initially appeared legitimate.

One of the fake e-mails notified employees of a scientific conference, while another pretended to alert the employee to a complaint on behalf of the Federal Trade Commission. In both cases, the employee was instructed to open an attachment for further information.

The lab also warned anyone who visited between 1990 and 2004 to check their personal information with major credit check agencies Experian, Equifax, and TransUnion.

An Oak Ridge National Laboratory spokesman declined to comment further on the issue.

Avivah Litan, senior security researcher with Gartner, said the scary part about the breach was its "inside job"-like nature.

"It's a little frightening that the phishers got that list to send a targeted e-mail," she told InternetNews.com. "I don't think there's cause for panic because they've said nothing has been compromised. But it's very troublesome that phishers got a list of employees to target."

"It makes you wonder what other holes are out there," she said.

News courtesy of internetnews.com

December 10, 2007

View All Anti-Spam / Anti-Phishing Software

View All Anti-Malware Software

Contents:
1. Sophisticated Targeted Attack Compromises 14 Years of Private Date






JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers