Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • The Canadian Copyright Lobby's Secret Pressure On the Anti-Spam Bill
  • TSA seeks hard drive, personal data for 100,000
  • Vendors take giant leap with drive encryption
  • Doubts On Yahoo's Human Rights Code of Conduct
  • Does The Children’s University hospital in Dublin keep a secret DNA file on almost every person born in Ireland since 1984 ?
  • Indefinite Detention: No Guilty Verdict Required
  • The distorting effect of grants of anonymity by journalists

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Payroll Site Hacked, Employment Numbers Swell

Submitted by MacRonin on October 16, 2009 - 2:33pm
  • Companies
  • Data Breach
  • Databases
  • Finance
  • Hmmm
  • ID
  • New Jersey
  • Privacy
  • Security

Payroll Site Hacked, Employment Numbers Swell: Via Threat Level.

A payroll processing firm that was breached by hackers last month is warning customers about a new breach, after some clients noticed phantom employees popping up on their payrolls.

New Jersey-based PayChoice sent a message to customers Thursday indicating that thieves appeared to have stolen customer login IDs and passwords by exploiting a vulnerability in the website feature for changing a password, WashingtonPost.com reports. PayChoice said it disabled the change password feature until it could fix the vulnerability.

The company discovered the problem after some of its payroll customers noticed bogus employee names being added to their payroll lists, in an attempt to get the companies to pay those “employees” through bank accounts controlled by the fraudsters.

The incident follows a breach in late September that resulted in hackers absconding with the account information of firms using its online payroll product.

In a Sept. 28 e-mail sent to customers, PayChoice indicated that the hackers had obtained e-mail addresses as well as login IDs and at least parts of passwords for account holders using the OnlineEmployer.com web site.

The hackers used the information for a phishing attack, sending targeted e-mail to the customers in an attempt to trick them into relinquishing the remainder of their passwords. The e-mails indicated that the customers needed to download a plug-in to continue using PayChoice’s OnlineEmployer web site. The plug-in, however, was actually a password-stealing Trojan.

PayChoice shuttered the site temporarily after discovering the initial attack, and forced customers to change their passwords. But it appears that implementation resulted in an additional vulnerability.

In addition to its payroll processing service, PayChoice produces an online payroll management system used by 240 other payroll processing firms,

See also:

  • Payroll Firm Breached — Online Customers Targeted

Read Original Article:(Via Threat Level.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • In Bid to Sway Sales, Cameras Track Shoppers
  • Unprecedented 25-Year Sentence Sought for TJX Hacker
  • EFF Appeals Dismissal of Warrantless Wiretapping Case
  • Viacom Makes Its Case Against Yesterday's YouTube
  • Obama supports Senators draft plan to rework U.S. immigration policy - Includes National Biometric ID card for all.
  • Domain Names Can't Defend Themselves
  • Hacker Disables More Than 100 Cars Remotely
  • Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
  • Hooking Up The Big Brother Machine... And Fighting It
  • Court: State Can Dump Non-Sex Offenders Into Registry
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.