Trade Association Membership Info Obtained by Fraud

The Chartered Institute for Securities and Investment, a UK-based trade association for the investment industry, suffered a breach last week which resulted in the release of personal contact information for their entire membership. This breach appears to have been the result of simple fraud, or "social engineering," where an individual contacted an Institute employee and convinced that person to provide the list. As their CEO stated on their website, "I would like to reassure you that this is not a breach of our IT system, but we fell victim to a devious confidence trick on an unsuspecting member of the support team."

It is worth noting that, even in this age of malware and highly technical theft and espionage, many of the greatest threats to an organization's data still take the form of simple fraud and confidence games of this type. It is important that every organization have clear and well-communicated policies regarding what types of information are considered sensitive, what measures must be taken to protect it, and how and to whom it may be communicated. Anchor can help you develop policies and procedures, and can also develop and deliver training to ensure staff understand and apply proper actions to avoid this type of breach.

http://www.cisi.org/bookmark/genericform.aspx?form=29848780&URL=databreachfaq

Comments

Popular posts from this blog

Weekly Infosec News Brief: 14-20 March

Weekly Infosec News Brief 20-26 July

Critical Vulnerability Discovered in IIS 6.0 Web Services