Original URL: http://www.theregister.co.uk/2006/11/17/ftc_guidance_negligence_rebuke/
Guidance Software, the security company whose computer forensics software helps firms identify the source of hacking attacks, has settled with the Federal Trade Commission (FTC) over charges that it failed to protect its own customers' data from attack.
The FTC said Guidance failed to take "reasonable security measures to protect its consumers' data from tampering, in contradiction of its own security policies and federal law. As a result, hackers were able to get access to sensitive credit card information on thousands of customers' stored admin passwords in clear text on its servers, an oversight that allowed attackers to access credit card information on its network.
In agreeing the settlement, Guidance agreed to implement a comprehensive information-security programme and obtain audits by independent third-party security firms every two years for 10 years.
According to the FTC complaint (PDF (http://www.ftc.gov/os/caselist/0623057/index.htm)), Guidance failed to implement "simple, inexpensive and readily available security measures" to protect consumers' data. As well as failing to take precautions to prevent web attacks, Guidance failed to detect unauthorised access to its network, a particularly embarrassing oversight given the nature of Guidance's business".
The case is the FTC's fourteenth case challenging faulty data security practices by firms that handle sensitive consumer information. ®
FaceTime exposes prospect contact info (8 August 2007)
http://www.theregister.co.uk/2007/08/08/facetime_contact_data_breach/
Webmaster pays $3,300 to settle malware charges (1 March 2007)
http://www.theregister.co.uk/2007/03/01/ftc_spyware_settlement/
FTC spanks Sony BMG, porn operator (31 January 2007)
http://www.theregister.co.uk/2007/01/31/ftc_settlement/
Spyware firms pay token fines to FTC (22 November 2006)
http://www.theregister.co.uk/2006/11/22/ftc_spyware_settlement/
What the heck was on that stolen laptop? (19 August 2006)
http://www.theregister.co.uk/2006/08/19/laptop_loss_survey/
US veterans' data exposed after burglary (23 May 2006)
http://www.theregister.co.uk/2006/05/23/va_data_security_breach/
Adult payment firm denies customer records breach (10 March 2006)
http://www.theregister.co.uk/2006/03/10/smut_database_mystery/
FTC settles with CardSystems over data breach (27 February 2006)
http://www.theregister.co.uk/2006/02/27/ftc_settles_with_cardsystems/
ChoicePoint fined $15m over data security breach (27 January 2006)
http://www.theregister.co.uk/2006/01/27/choicepoint_ftc_settlement/
Computer forensics firm Guidance hacked (20 December 2005)
http://www.channelregister.co.uk/2005/12/20/guidance_security_breach/
Consumers punish firms over data security breaches (15 November 2005)
http://www.theregister.co.uk/2005/11/15/data_security_breach_survey/
© Copyright 2008