Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Fraud & Identity Theft

South Carolina Hit in Massive Cyberattack – 3.6 Million Tax Payers Exposed

South Carolina Data Breach Exposes 3.6 Million Tax Payers

State officials in South Carolina say a devastating cyberattack on the state’s Department of Revenue has resulted in the theft of 3.6 million social security numbers and nearly 400,000 credit and debit card numbers.

South Carolina Data Breach Exposes 3.6 Million Tax Payers

State officials in South Carolina say a devastating cyberattack on the state’s Department of Revenue has resulted in the theft of 3.6 million social security numbers and nearly 400,000 credit and debit card numbers.

According to the Department of Revenue (DOR), the vast majority of the credit card numbers are protected by strong encryption. However, approximately 16,000 are unencrypted.

South Carolina Map“On October 10, the S.C. Division of Information Technology informed the S.C. Department of Revenue of a potential cyber attack involving the personal information of taxpayers,” said Department of Revenue Director James Etter, in a statement. “We worked with them throughout that day to determine what may have happened and what steps to take to address the situation. We also immediately began consultations with state and federal law enforcement agencies and briefed the governor’s office.”

Six days later, investigators uncovered two attempts to probe the system in early September, as well as a previous attempt that was made in late August. In mid-September, two other intrusions occurred that authorities believe were the first times the intruder or intruders obtained data. No other intrusions have been uncovered at this time, and on Oct. 20, the vulnerability in the system was closed, according to the DOR.

“The number of records breached requires an unprecedented, large-scale response by the Department of Revenue, the State of South Carolina and all our citizens,” said South Carolina Governor Nikki Haley in a statement. “We are taking immediate steps to protect the taxpayers of South Carolina, including providing one year of credit monitoring and identity protection to those affected.”

In a survey by Deloitte & Touche released this week, less than a quarter of state chief information security officers said they were confident in their states’ ability to safeguard data from attacks. Just 32 percent of CISOs felt state employees had the “required cyber-security competency.”

In light of the recent attack, Gov. Haley issued an executive order instructing state IT officers to work with the Office of the State Inspector General to review and bolster security.

“From the first moment we learned of this, our top priority has been to protect the taxpayers and the citizens of South Carolina, and every action we’ve taken has been consistent with that priority,” Etter said. “We have an obligation to protect the personal information entrusted to us, and we are redoubling our efforts to meet that obligation.”

Advertisement. Scroll to continue reading.

It has been a tough year for the State. In late August, The University of South Carolina (USC) notified some 34,000 people after a system intrusion was detected on a computer used by the College of Education.

Related: State CISOs Have Little Confidence In Ability To Defend Against External Threats

RelatedHackers Targeting South Carolina DMV Underscores Security Realities

Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Fraud & Identity Theft

Famed hacker Kevin Mitnick has died after a battle with pancreatic cancer.  At the time of his death, he was Chief Hacking Officer at...

Fraud & Identity Theft

A team of researchers has demonstrated a new attack method that affects iPhone owners who use Apple Pay and Visa payment cards. The vulnerabilities...

Cybercrime

Deepfakes, left unchecked, are set to become the cybercriminals’ next big weapon

Cybercrime

A threat actor tracked as ‘Scattered Spider’ is targeting telecommunications and business process outsourcing (BPO) companies in an effort to gain access to mobile...

Application Security

Password management firm LastPass says the hackers behind an August data breach stole a massive stash of customer data, including password vault data that...

Cybercrime

While there are likely many different approaches, here are a few points that are important for enterprises to consider when evaluating bot solutions.