Related Links

  • Monster.co.uk
  • Elsevier Ltd is not responsible for the content of external websites.

Related Stories

  • Someone’s got to pay
    Consumers are increasingly trading the high street for the home computer, and in both cases getting more than they bargained for. Rob Stringer investigates the fraud and fuzzy legislation of retail security
  • Face-off in Oxford
    Britain’s oldest university has become a flashpoint for students’ use of social networking and privacy, while companies debate whether to block or encourage Facebook and its rivals. SA Mathieson reports
  • Search for security
    With more than 30 000 web pages being infected every day, search engine results could increasingly lead to malware infection. Kari Larsen asks what the search engines are doing to mitigate security threats, and how users can protect themselves.
  • Loyalty cards: The security risks and the rewards
    Loyalty cards – with their numerous security risks and few rewards – have really taken off. Can we trust that the commercial organisations that store our data will take good care of it? Cath Everett investigates and finds there’s no such thing as a free lunch...
  • Social networking - a risk to information security?
    As the popularity of social networking sites continues to mount, it becomes increasingly important to consider the information security risks posed in the context of a wider data loss prevention and reputation management strategy. Cath Everett reports

News

Monster slain by hackers

26 January 2009

Careers website Monster.com and USAjobs.gov, the careers site for the US federal government, have been targeted by hackers, who have harvested user information including IDs, passwords and addresses.

The Monster website contains a statement from Patrick Manzo, senior vice president and global chief privacy officer for Monster Worldwide, who assures users that:
“Immediately upon learning about this, Monster initiated an investigation and took corrective steps. It is important to know the company continually monitors for any illicit use of information in our database, and so far, we have not detected the misuse of this information.”
The statement continues to advise users to change their passwords and be wary of any phishing emails that may be received as a result of the attack.
According to Manzo, CVs were not taken.
Monster act as the technology provider for the USAjobs.gov website, where the above statement is echoed by programme director Mary Volz-Peacock.
Both sites suffered a similar attack 18 months ago when cybercriminals took jobseekers’ details via recruiter accounts using a trojan, resulting in a widespread phishing campaign. Monster allegedly reported the discovery to users five days after the breach was discovered, by which time the data for 1.3 million jobseekers had been uploaded to servers in the Ukraine.
Graham Cluley, senior technology consultant at security firm, Sophos remarked that "There will be a few raised eyebrows about how Monster is choosing to inform its members of this serious security breach. As the company's database was hacked in what appears to have been a similar attack in 2007, customer confidence in the company may be damaged following this latest incident".
A statement issued by Sophos also advised users to use different passwords for each online account they have, noting that research indicates that 41 percent of people use the same password for every website they access.

 

This article is featured in:
Data Loss Encryption Internet and Network Security Public Sector

 

Comment on this article

You must be registered and logged in to leave a comment about this article.