Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Hackers Steal Credit Report Data Via Compromised Logins Used By Banks

Hackers Use Malware To Access Experian Credit Reports

More than 17,000 credit reports have been exposed as a result of attacks at financial institutions and other organizations over the past six years. Attackers grabbed credit reports using stolen login credentials to credit reporting bureaus.

Hackers Use Malware To Access Experian Credit Reports

More than 17,000 credit reports have been exposed as a result of attacks at financial institutions and other organizations over the past six years. Attackers grabbed credit reports using stolen login credentials to credit reporting bureaus.

There have been 86 incidents since 2006 that resulted in data belonging to the three major credit reference agencies, Experian, Equifax, and TransUnion, being exposed to snoops, according to an investigation by Bloomberg.

Attackers did not obtain people’s credit histories by attacking the credit bureaus directly, but by targeting financial institutions and other organizations that are authorized to request credit reports.

In one instance, attackers breached a Texan bank in September 2011, and got their hands on the bank’s account with credit reference agency Experian. The attackers downloaded credit reports on 847 people using that login, all of whom had never been a customer at the bank. The reports contained highly sensitive personal information, such as Social Security numbers, dates of birth, and other financial data for people all over the country.

Hacker

“It illustrates a growing problem when it comes to data breaches and security –the chain is only as strong as its weakest link,” Sen. Richard Blumenthal (R-Conn) told Bloomberg.

Experian and TransUnion told Bloomberg the breaches were the result of malware infections on customer computers. “We continue to invest in the security systems we have in place to protect our clients and consumers,” Gerry Tschopp, a spokesman for Experian, told Bloomberg.

“Of course, the first line of defense lies with end users who are obligated to manage and protect their credentials, which in all these instances were compromised through malware that infected their hardware and other illegal means,” Tschopp said.

There were 80 breaches against Experian’s database, resulting in 15,500 credit reports being downloaded. Equiax saw four attacks, which resulted in exposing more than 1,200 reports. TransUnion was targeted only twice, and exposed only 500 records to unauthorized snooping, according to the information stored on DataLossDB.org. All the incidents originated with login name and passwords being stolen.

Advertisement. Scroll to continue reading.

Criminals have access to a wealth of financial data when they steal a credit report. The reports contain enough information that would allow the perpetrators to take out new credit cards, qualify for loans and mortgages, and even get a driver’s license.

“The finely-groomed data on citizens accessible to thieves has the potential to compromise entire financial systems that use that data to validate identity, provide background data, and enable financial transactions,” Mark Bower, a vice-president at Voltage Security, told SecurityWeek.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.