COMPUTERS
August 30, 2007 2:00 PM PDT

Monster defends delay in notifying users of data breach

Posted by Robert Vamosi
  • Font size
  • Print

Patrick Manzo, Monster Worldwide's vice president of compliance and fraud prevention, today said going forward, the company is notifying all users in its active job-seeker database that their information may be compromised.

This announcement comes one day after Monster's CEO Sal Iannuzzi admitted the theft of contact information for job seekers in Monster's database may have been much greater than the 1.3 million individuals reported earlier this month.

Monster said it learned of the proverbial break-in when it was notified by security vendor Symantec. And Monster said it wanted to launch its own investigation to verify the security breach before notifying those job seekers who had been affected, Manzo said. He added it would have been "irresponsible" for Monster to contact its job seekers without first verifying the information Symantec had provided.

In mid-August the Inforstealer.monstres Trojan horse was used in e-mails to Monster.com subscribers; the e-mail pretended to be from a potential employer. According to Symantec, subject lines included "(a person's real name), Monster.com suggests You the new job for you" and "(realname), Monster.com have the new job for you." Offers included $500 as sign-on bonus, the ability to work from home, and the recruiter also promised a very small amount of work hours.

The e-mail contained a link or attached file which, when executed, installed the Prg Trojan on the victim's computer. Thereafter any personal information typed into the compromised computer was then relayed to servers in Asia. As part of the job application, potential employees were asked to provide Social Security numbers and bank account information.

Prg uses a back-door proxy server listening for connections on port 6081. Port 6081 is not currently assigned for legitimate services, so if port 6081 is open on your computer, and there is traffic on that port, you may be infected. SecureWorks notes that some victims who used commercial antivirus protection to remove the Trojan, would later revisit the infected job sites and were therefore at risk of being infected with another variant of the same Trojan.

In mid-August, Don Jackson and Joe Stewart, two security researchers at SecureWorks, identified a server in Asia containing one of the largest caches of stolen data attributed to the Prg Trojan. The data on the server included bank and credit card information, Social Security numbers, online payment account user names and passwords.

Monster's Manzo stressed the information in the Monster Worldwide database is similar to that found on a business card--name, phone numbers, e-mail addresses--but no financial information or Social Security numbers.

Monster is beefing up its ability to monitor traffic on its Web site, tighten access controls and policies, as well as improve its privacy steps for job-seeker information, Manzo said. One such task it has undertaken is asking employers who use its site to rely on more complex passwords.

News.com's Dawn Kawamoto contributed to this blog.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from News Blog
Was InfoWorld's CTO of the Year award a year late?
VMWare VI4 renamed to vSphere
Red Hat's new support product demonstrates subscription value
Teen listens to iPod during brain tumor removal
NASA, Google Maps track Southern California wildfires
Sprint first to offer HTC Touch Pro
Flipping out: RIM BlackBerry Pearl Flip 8220 debuts
Sprint HTC Touch Diamond outed early
Add a Comment (Log in or register) 2 comments
There is NO excuse.
by UITD August 31, 2007 4:42 AM PDT
The CEO should be fired/resign AND be fined $1 per record lost or stolen. These companies and their CEO's, CIO's need to get smacked upside their heads in order to understand the severity of their errors.

Its about time people start holding problem people accountable. And dont blame the workers. The buck stops at the lazy, CHEAP CEO's desk.
Reply to this comment
Data Breach-is their more to story?
by upsonj August 31, 2007 1:15 PM PDT
I received my letter yesterday, and was very upset. I usually get nothing but "make big money @ home" that isn't worth my time to reply. But about a month ago I did reply to one, and now I'm worried. What else can they do with this software known as Infostealer.Monsters? This is who my letter states that got into data-base. If it's that easy to do that, then it would be just as easy for anyone to gain access to you PC and all its info, is this the case here? Some-one tell me, what should I do.
Reply to this comment
advertisement

In the news now

Apple: DRM-free tunes, unibody MacBook Pro

roundup At Macworld, Phil Schiller touts 10 million songs sans DRM, plus 69-cent songs, a unibody 17-inch notebook, iLife updates, and more.


Countdown to CES

special coverage The tech community descends on Las Vegas as the Consumer Electronics Show gets ready to kick off in all its gadgety glory.


About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

News Blog topics

advertisement

Inside CNET News

Scroll Left Scroll Right