Monster attack steals user data

by liamssoft | August 29, 2007 at 05:18 am | 256 views | 1 comment
US job website Monster.com has suffered an online attack with the personal data of hundreds of thousands of users stolen, says a security firm.

A computer program was used to access the employers' section of the website using stolen log-in credentials.

Symantec said the log-ins were used to harvest user names, e-mail addresses, home addresses and phone numbers, which were uploaded to a remote web server.

The stolen data could be used to send phishing and spam e-mails.

"This remote server held over 1.6 million entries with personal information belonging to several hundred thousands of candidates, mainly based in the US, who had posted their resumes to the Monster.com website," reported Symantec.

The program used to access Monster.com user data was a Trojan, which are commonly used to gain access to bank details, usernames and passwords.

More than 8,000 new variants of Trojans are found each month, according to internet security specialists Sophos.

Last year, a British nurse was blackmailed by hackers who had used a Trojan to access her personal e-mails.

They threatened to reveal personal details unless she paid them.

Add a comment Comments (1)

jordan

The worst part is how long it took Monster to admit the data breach: five days.

Add a comment

The content of this field is kept private and will not be shown publicly.

August 29, 2007 at 05:18 am by liamssoft, 256 views, 1 comment

closeSign in to NowPublic

is reporting from