Related Stories

  • US standards drive Canadian information security
    An absence of legislation and the presence of the laissez-faire attitude has resulted in Canada being rather lax when it comes to information security compliance. Robin Arnfield looks at how US standards are driving the Canadian information security marketplace
  • Battle of the Internet Browsers
    Browsers are the hacker’s window into your PC – but how are they compromised, and what are vendors doing to harden them? Danny Bradbury examines the techniques vendors are employing, and looks at why user education is one of the primary solutions for increased security
  • Infosecurity - the week in brief
    Arrests A Chinese official has reportedly been arrested for taking backhanders to help one local anti-virus company disrupt the business of another. Yu Bing, director of the internet monitoring department of Beijing’s Public Security Bureau, allegedly took 4.5m Yuan ($657,000) to frame executives at antivirus company Micropoint and stop its products reaching the market. The money was said to have come from antivirus firm Rising, according to reports.
  • A Breach too Far
    How much do data breaches really damage organizations financially – and why don’t we want to hear about it? Danny Bradbury investigates
  • Security and malware threats to Mac and Apple products are on the rise
    An annual report from security software provider Intego acknowledges it was a busy year for security threats to Apple devices, including the Mac OS X and iPhones. And while the Mac OS may be a less frequent target of malware authors, security threats to Apple products are proliferating as these devices land in the hands of more and more users.

News

Monster.com hit by new breach

29 January 2009

Online recruitment website monster.com has suffered from another major data breach.

 

The company announced that its database was illegally accessed, and information including monster user IDs and passwords, email addresses, names, phone numbers, and basic demographic data was stolen.

"The information access does not include resumes," said the firm in a statement. "Monster does not generally collect - and the accessed information does not include - sensitive data such as social security numbers or personal financial data."

Monster.com chose not to email its users with news of the information, arguing that it did not want to give phishers an opportunity to capitalise on an email campaign to impersonate the company.

The breach affected Monster.com sites in north America and western Europe.

This is not the first time that monster.com has suffered from a data breach. In August 2007, the company admitted that data on the least 1.3 million users had been compromised. The breach, found by Symantec, involved the use of the PRG trojan, which gave attackers access to some recruiters' accounts, which were then used to pilfer user data, said Don Jackson, senior security researcher at Atlanta-based SecureWorks. Then, in November the same year, the company was hit by an IFRAME attack, which served up malicious code to job seekers visiting its Monster Company Boulevard web property.

When asked what it had learned from its previous breaches, a Monster.com spokesperson told Infosecurity: "We cannot comment on specific security measures, but Monster has made a significant investment in enhancing data security and we believe that our security measures are as, or more, robust than other sites in our industry." The spokesperson refused to discuss how database encryption could have prevented the latest breach, and would not divulge any security methodologies, or certifications such as ISO 27000, that the firm may or may not have attained.

 

This article is featured in:
Data Loss Identity and Access Management Internet and Network Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.