Feeds

Bulk mailer convicted of data theft scam

Information inflation

Secure remote control for conventional and virtual desktops

A Florida man has been convicted of stealing vast amounts of personal information from Acxiom, one of the world's largest database companies, in order to inflate the value of his spamming firm.

Scott Levine, 46, of Boca Raton, Florida, was last week found guilty of 120 counts of unauthorized access to data, two access device fraud charges and a single obstruction of justice offence, AP reports. The former head of defunct bulk mail outfit Snipermail.com was cleared of 14 conspiracy charges and money laundering at the end of a trial that lasted almost a month.

Prosecutors described the case as the "largest ever invasion and theft of personal data" ever tried. In court, Levine and Snipermail.com were accused of stealing a jaw-dropping 1.6 billion customer records containing details of the name, address and email of millions of Americans from Acxiom databases during a total of 137 hack attacks. The purloined data was used to inflate the value of Snipermail, a Boca Raton-based company controlled by Levine. There is no suggestion that the accused engaged in identity theft.

Weak access control allowed Snipermail.com to illegally access swathes of information thanks to a business relationship between Acxicom and one of Snipermail's clients. Snipermail should only have been allowed limited access but instead it was allowed the run of the lan(d). The purloined data was used to inflate Snipermail's contact list and make it a more attractive target for acquisition.

Evidence of Snipermail's alleged assault was discovered by investigators probing a separate security breach at Acxiom. Daniel Baas, 25, of Cincinnati, Ohio, pleaded guilty to that attack in December 2003.

Acxiom clients include 14 of the 15 biggest credit card companies, seven of the top ten auto manufacturers and five of the top six retail banks. The company also analyses consumer databases for multinationals such as Microsoft, IBM, AT&T and General Electric.

Arkansas-based Acxiom has overhauled security since the attacks were uncovered. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
10 threats to successful enterprise endpoint backup
10 threats to a successful backup including issues with BYOD, slow backups and ineffective security.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The hidden costs of self-signed SSL certificates
Exploring the true TCO for self-signed SSL certificates, including a side-by-side comparison of a self-signed architecture versus working with a third-party SSL vendor.