Share

Related Stories

  • A Rotting Security Apple?
    Vendors, analysts, and commentators alike have long predicted a surge in malware affecting Apple’s products. Yet, until recently, these prognostications have failed to materialize. Drew Amorosi examines recent malware threats to Apple’s OS X operating system to find out if this is an anomaly, or a sign of things to come
  • US standards drive Canadian information security
    An absence of legislation and the presence of the laissez-faire attitude has resulted in Canada being rather lax when it comes to information security compliance. Robin Arnfield looks at how US standards are driving the Canadian information security marketplace
  • US standards drive Canadian information security
    An absence of legislation and the presence of the laissez-faire attitude has resulted in Canada being rather lax when it comes to information security compliance. Robin Arnfield looks at how US standards are driving the Canadian information security marketplace
  • The Gods of Phishing
    Some phishing attempts are truly ethereal – near flawless representations of official communications. Others, however, are mere mortals. And then there’s the absolutely absurd. Esther Shein visits the pantheon of scammer emails
  • Data Breach Spring
    Infosecurity’s Drew Amorosi examines three data breach incidents from the past few months that, by their nature, keep security vendors in business, regulators busy, and CISOs up at night. Find out why industry observers think this rash of massive breaches could lead to a ‘PCI for consumer privacy’

Top 5 Stories

News

Monster.com hit by new breach

29 January 2009

Online recruitment website monster.com has suffered from another major data breach.

 

The company announced that its database was illegally accessed, and information including monster user IDs and passwords, email addresses, names, phone numbers, and basic demographic data was stolen.

"The information access does not include resumes," said the firm in a statement. "Monster does not generally collect - and the accessed information does not include - sensitive data such as social security numbers or personal financial data."

Monster.com chose not to email its users with news of the information, arguing that it did not want to give phishers an opportunity to capitalise on an email campaign to impersonate the company.

The breach affected Monster.com sites in north America and western Europe.

This is not the first time that monster.com has suffered from a data breach. In August 2007, the company admitted that data on the least 1.3 million users had been compromised. The breach, found by Symantec, involved the use of the PRG trojan, which gave attackers access to some recruiters' accounts, which were then used to pilfer user data, said Don Jackson, senior security researcher at Atlanta-based SecureWorks. Then, in November the same year, the company was hit by an IFRAME attack, which served up malicious code to job seekers visiting its Monster Company Boulevard web property.

When asked what it had learned from its previous breaches, a Monster.com spokesperson told Infosecurity: "We cannot comment on specific security measures, but Monster has made a significant investment in enhancing data security and we believe that our security measures are as, or more, robust than other sites in our industry." The spokesperson refused to discuss how database encryption could have prevented the latest breach, and would not divulge any security methodologies, or certifications such as ISO 27000, that the firm may or may not have attained.

This article is featured in:
Data Loss  • Identity and Access Management  • Internet and Network Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.