Reply
Respected Contributor
Posts: 3,358
Registered: ‎02-21-2014

•••Scottrade Had No Idea of Data Breach•••

 

 


http://www.pcworld.com/article/2988993/security/scottrade-had-no-idea-about-data-breach-until-the-fe...


10/3/15

"Scottrade had no idea about data breach until the feds showed up"

 

 

"When an organization gets hacked, ideally they'll realize it promptly and warn their users right away. Take crowdfunding site Patreon, which was hacked on Monday and has already informed the world about the problem. Scottrade, an investment brokerage company, is different, and not in a good way.

 

 

The company announced Friday that it suffered a security breach over a period of several months from late 2013 to early 2014, affecting approximately 4.6 million customers. But in a statement, Scottrade said it had no idea that the breach had occurred until law enforcement officials told them about it.

 

 

Remember: This is a company that is charged with storing real money and managing investments.

 

Let that sink in for a second.

 

 

The FBI notified Scottrade of the breach in August but asked that the company hold off on disclosing the attack until it had wrapped up another part of its investigation. The company was cleared to disclose the breach at the end of last week and began informing customers Friday.

 

 

To its credit, Scottrade said that it believes attackers obtained only clients' names and street addresses -- not the social security numbers, email addresses and other sensitive data stored in the compromised system. According to the company, the attackers didn't compromise Scottrade's trading platforms, and clients' funds were untouched.

 

 

People who had a Scottrade account prior to February 2014 may have been affected by the breach. Those people who Scottrade knows were affected will be notified of that by email. The company isn't suggesting that users change their passwords, since it believes that they remained encrypted during the attack.

 

 

As is expected in these sorts of cases, Scottrade is offering affected customers a free year of identity theft protection. It's not clear how much good that will do, since the data was taken more than a year ago, but offering that sort of service is something consumers expect from a breach response at this point.

 

 

Looking forward, the company said that it has secured the intrusion point the attackers used to get into its systems, and conducted an internal investigation with the help of an unnamed computer security firm. The company also said that it has further secured its network.

 

These aren't the only data breaches revealed this week.

T-Mobile and Experian said yesterday that 15 million

people may have been affected by a mammoth breach

that could include data like names, birthdates and

Social Security numbers.

 

 

Incidentally, October is National Cyber Security Awareness Month in the U.S.

 

And now at least 20 million people have had their awareness raised."

 

 

 

 


••• Please adopt don't shop ••• Save a life adopt a pet •••
Honored Contributor
Posts: 16,242
Registered: ‎03-09-2010

Re: •••Scottrade Had No Idea of Data Breach•••

Computers and computer files do wonderful things for our lives, but they also create incredible opportunities for thieves.  Scary times we live in.

 

I truly do not know how a company knows it's been hacked -  how do they find out?

Esteemed Contributor
Posts: 6,506
Registered: ‎03-10-2010

Re: •••Scottrade Had No Idea of Data Breach•••

A really good system would have a breach notification, and there are web managers that monitor the systems.

Esteemed Contributor
Posts: 7,136
Registered: ‎06-29-2010

Re: •••Scottrade Had No Idea of Data Breach•••

Russians?????  Chinese?????

Never Forget the Native American Indian Holocaust
Honored Contributor
Posts: 11,126
Registered: ‎06-20-2010

Re: •••Scottrade Had No Idea of Data Breach•••

I'm going to assume every company at some point has been or will be hacked.

 

 

How did they not know?

Respected Contributor
Posts: 3,358
Registered: ‎02-21-2014

Re: •••Scottrade Had No Idea of Data Breach•••


@riley1 wrote:

A really good system would have a breach notification, and there are web managers that monitor the systems.


 

 

Thanks @riley1 I wondered about that.


••• Please adopt don't shop ••• Save a life adopt a pet •••
Respected Contributor
Posts: 4,026
Registered: ‎03-12-2010

Re: •••Scottrade Had No Idea of Data Breach•••

I don't believe them when they say they didn't know. 

_____ ,,,^ ._. ^,,,_____
Trusted Contributor
Posts: 1,173
Registered: ‎03-19-2010

Re: •••Scottrade Had No Idea of Data Breach•••

 

Do you really think they didn't know? Didn't Target delay the news that they were breached?

Respected Contributor
Posts: 2,278
Registered: ‎03-15-2010

Re: •••Scottrade Had No Idea of Data Breach•••

Geez.  Data breaches are getting to be a weekly thing.  Goes to reassure us that nothing on the computer is safe.

Honored Contributor
Posts: 21,417
Registered: ‎11-03-2013

Re: •••Scottrade Had No Idea of Data Breach•••


@Smaug wrote:

I don't believe them when they say they didn't know. 


I hate to say it but I do believe they didn't know they were hacked.  What I don't believe is that they only breached clients names and addresses and no sensitive data was touched.

 

What frightens me is that these are probably for the most part people's retirement funds.  If the hackers got the necessary data, they could possibly follow them to another brokerage firm and gain access to their data and remove their money.  Does anyone know if these online brokerages come with any guarantees if you get hacked and your money is gone?

 

Shameful.