Blogs

RSS FeedBlogs
RSS FeedSubscribe to this blog
About Author
Jericho Forum

The Jericho Forum is an international group of organisations working together to define and promote the solutions surrounding the issue of de-perimeterisation. Members include top IT security officers from multi-national Fortune 500s & entrepreneurial user companies, major security vendors, government, & academics. Working together, members drive approaches and standards for a secure, collaborative online business world.

Contact

Email

There goes another 25 million Sony customer records

Once is bad enough. Twice suggests a deeper problem

Article comments
Following on from last week’s Sony PlayStation Network revelations, the company has now admitted losing the details of another 25 million users, this time from the Sony Online Entertainment (SOE) network.

While the data here is said to be outdated (from a 2007 copy of the database), a great deal of the information will still be relevant. People don’t move around all the time and they won’t change their date of birth. Furthermore, the chances are that the direct debit detail will also still be valid. ‘Old’ data doesn’t mean ‘out-of-date’.

Advanced Persistent Threats (APTs), which both of these attacks appear to be examples of, are designed to be long lasting and difficult to discover. The cyber-criminal in an APT attack bides his or her time and siphons off information more slowly, leaving few traces, making it harder to counteract.

In other cases, when a breach has been discovered, the leak still goes back weeks or months. This raises the interesting question for companies - are you currently subject to an APT but just don’t know it yet? Time to revisit audit and security controls, just in case.

Guy Bunker, Jericho Forum board member

Share:

Comments

Send to a friend

Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

ComputerworldUK Knowledge Vault

ComputerworldUK
Share
x
Open