Site icon Liquidmatrix Security Digest

Monster Waited Five Days To Disclose Data Theft

Maybe they thought no one would notice? An interesting use of the “LALA gambit”. Allow me to demonstrate.

“LALALA I can’t hear you LALALA”

From ZDNet:

Monster.com waited five days to tell its users about a security breach that resulted in the theft of confidential information from some 1.3 million job seekers, a company executive told Reuters on Thursday.

Hackers broke into the US online recruitment site’s password-protected CV library using credentials that Monster Worldwide said were stolen from its clients, in one of the biggest internet security breaches in recent memory.

They launched the attack using two servers at a web-hosting company in Ukraine and a group of personal computers that the hackers controlled after infecting them with a malicious software program known as Infostealer.Monstres, said Patrick Manzo, vice president of compliance and fraud prevention for Monster, in a phone interview.

The company first learned of the problem on 17 August, when investigators with internet security company Symantec told Monster it was under attack, Manzo said.

“In terms of figuring out what the issue was, that was a relatively quick process,” he said. “The other issue is you want to make sure exactly what you are dealing with.”

All kidding aside, I would imagine that they were trying to figure things out rather than running screaming into a press room. Facts are always nice to have. Now, if they had taken several months…that would be another matter.

Article Link

[tags]Monster.com, Monster Hacked, Data Theft, Privacy[/tags]

Exit mobile version