Bank customers at risk after details are hacked
Tuesday 05 April 2011
Related articles
Customers of many of the world's biggest banks and numerous other companies are being warned to expect fake emails trying to lure them to part with their log-in details, after what could be one of the biggest data breaches of the internet era.
The company at the centre of the incident, a Dallas-based email marketing firm called Epsilon, revealed last Friday that it had been the victim of a computer hacker, but the scale of the breach has only become clear as, one by one, some of the world's largest companies have alerted their customers.
The banks and other firms involved have all said that no customer account details were stolen, only email addresses.
The list of banks affected includes Citigroup, JP Morgan Chase, Capital One Financial and US Bancorp and Barclays' US credit card arm. American retailers involved include Walgreens, Best Buy and Kroger. Customers of Disney's travel business and TiVo, which sells digital video recorders, are also victims.
"Epsilon has assured us that the only information obtained was your name and email address," Barclays Bank of Delaware said in an email to its US credit card customers. "It is possible you may receive spam email messages as a result which could potentially ask you for additional information about your account. Please note, Barclays will never ask you in an email to verify sensitive information such as your full account number, username, password or social security number. Therefore, any email which does so should be treated as suspicious, even if it looks like it comes from Barclays."
The not-for-profit College Board, which administers the SAT admissions tests and has the email addresses of 7 million US students, asked students and parents to be cautious about receiving "links or attachments from unknown third parties". Millions of similar emails have been sent out by the firms affected in the days since Epsilon reported the security breach.
Internet scam artists routinely send emails to people, purporting to be from a large bank and asking them to log in at a site that looks like the bank's own website. Instead, the fraudulent site captures their log-in information and uses it to access the real account. The Epsilon data breach could make these so-called "phishing" attacks more efficient, by allowing the fraudsters to target people who they know really have an account with the bank.
Epsilon, a subsidiary of Nasdaq-listed Alliance Data Systems, is a digital marketing and data management firm that helps companies manage their email correspondence with customers. The company says it works on behalf of 2,500 clients and sends more than 40 billion emails each year, often email ads and offers, to people who register for a company's website or who give their email addresses while shopping.
Late last Friday, Epsilon disclosed that it had been the victim of a hacker. In a statement, it said: "On 30 March, an incident was detected where a subset of Epsilon clients' customer data were exposed by an unauthorised entry into Epsilon's email system. The information that was obtained was limited to email addresses and/or customer names only. A rigorous assessment determined that no other personal identifiable information associated with those names was at risk. A full investigation is under way."
The company has refused to comment but confirmed it is cooperating with law enforcement authorities who are investigating the breach.
-
In pictures: Saturn images from Cassini probe as it prepares to turn lens towards Earth
-
Serena Williams apologises after comment that rape victim 'shouldn't have put herself in that position'
-
FBI finds possible human remains at former home of late gangster James Burke - the man who inspired Goodfellas
-
'Theres something quite unpleasant going on': Nigel Farage confronted for second time on visit to Scotland
-
World news in pictures
- 1 Bankers could face jail after report urges the Government to introduce new criminal offence for reckless management
- 2 Breaking the Silence: In the reality of occupation, there are no Palestinian civilians – only potential terrorists
- 3 Richard Nieuwenhuizen death: Six teenagers and 50-year-old father convicted of manslaughter in shocking case of referee killed over a game of football
- 4 Exclusive: Newcastle's star talent-spotter on brink as Joe Kinnear sparks walkout
- 5 Vast methane 'plumes' seen in Arctic ocean as sea ice retreats
How will you make today delicious?
Tell us how you plan to make today delicious and you could win a £50 M&S gift card.
Win a Nook® Simple Touch eReader
Find out how Nook® is supporting the Evening Standard's Get Reading campaign - and your chance to win one.
Free reading festival for families
Follow The Standard's campaign to get London's children reading - and experience this unique event at Trafalgar Square on 13 July.
Enter the latest Independent competitions
Win anything from gadgets to five-star holidays on our competitions and offers page.
Business videos from commercial thought leaders
Watch the best in the business world give their insights into the world of business.
iJobs Money & Business
FX Options Front Office Java / C# Developer
£500 - £600 per day: Orgtel: FX Options Front Office Java / C# Developer - Ba...
Project Manager - Front Office - Regulatory IT
£600 - £700 per day: Orgtel: Project Manager - Front Office - Regulatory IT C...
FATCA Project Manager
£600 - £750 per day: Orgtel: FATCA Project Manager - Banking - London - £600-...
Fidessa Analyst / PM - Banking - London - £600pd
£550 - £600 per day: Orgtel: Fidessa Analyst / PM - Banking - London - Up to £...
Day In a Page
Babies behind bars
Sonic youth: The high-pitched sound alarm
The art of living in small spaces
'Teaching bright children isn't rocket science'
Can technology lure us back to the high street?



Comments