Feeds

Spammer charged in huge Acxiom personal data theft

Hack to spam indictment

  • alert
  • submit to reddit

SANS - Survey on application security programs

A Florida man has been charged with stealing a vast quantity of personal information from Acxiom, one of the world's largest database companies. Scott Levine, 45, of Boca Raton, Florida, was this week indicted for 144 offences in connection with the alleged attack including "conspiracy, unauthorized access of a protected computer, access device fraud, money laundering and obstruction of justice".

The US Department of Justice said the case involves what might be the "largest illegal invasion and theft of personal data to date". Federal investigators charge that Levine and staff at Snipermail stole 8.2 gigabytes of data from Acxiom's FTP servers between April 2002 to August 2003 during the course of 137 separate intrusions. The purloined data was allegedly used in email spamming campaigns by Snipermail, a Boca Raton-based company allegedly controlled by Levine.

Although investigators allege the intrusion and theft of personal information at Acxiom resulted in losses of more than $7m there is no suggestion this data was used in the more serious offence of identity fraud. The DoJ said six other people associated with Snipermail are cooperating in its investigation.

Double jeopardy

Evidence of Snipermail's alleged assault was discovered by investigators probing a separate security breach at Acxiom. Daniel Baas, 25, of Cincinnati, Ohio, pleaded guilty to that attack last December.

Acxiom clients include 14 of the 15 biggest credit card companies, seven of the top ten auto manufacturers and five of the top six retail banks. The company also analyses consumer databases for multinationals such as Microsoft, IBM, AT&T and General Electric.

Arkansas-based Acxiom has overhauled security since the attacks were uncovered. ®

Related stories

Man charged in Acxiom cracking case
Chats led to Acxiom hacker bust
Online fraud, ID theft soars

Combat fraud and increase customer satisfaction

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.