<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:www.readwriteweb.com,2011:/1/tag:www.readwriteweb.com,2009://1.13519-</id>
  <updated>2011-08-16T17:51:52Z</updated>
  <title>Comments for Monster.com Loses User Data Again</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.35-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=13519" title="Monster.com Loses User Data Again" />
    <published>2009-01-25T06:53:32Z</published>
    <updated>2009-01-25T21:00:18Z</updated>
    <title>Monster.com Loses User Data Again</title>
    <summary>UPDATE: Nikki Richardson, VP Corporate Communications at Monster Worldwide has replied to our e-mail saying that the company is in the process of contacting users but can not disclose specific details of the breach right now. If you&apos;re interested in reading the entire communication, please scroll down to the end of the post. Popular online...</summary>
    <author>
      <name>Lidija Davis</name>
      
    </author>
    
    <category term="NYT" />
    
    <category term="News" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img alt="monster_jan_09.jpg" src="http://www.readwriteweb.com/monster_jan_09.jpg" width="117" height="43" /><em>UPDATE: Nikki Richardson, VP Corporate Communications at Monster Worldwide has replied to our e-mail saying that the company is in the process of contacting users but can not disclose specific details of the breach right now.  If you're interested in reading the entire communication, please scroll down to the end of the post.</em></p>

<p>Popular online job site <a href="http://monster.com/">Monster.com</a> acknowledged a security breach of its user database Friday and is <a href="http://help.monster.com/besafe/jobseeker/index.asp">recommending</a> users immediately change passwords and be on the lookout for phishing e-mails.  The compromise is the second in two years for Monster.com and involved the loss of user log-in details, passwords, email addresses, names, and telephone numbers.  </p>

<p>This breach also affected Monster.com's client, <a href="http://www.usajobs.com/">USAJOBS</a>, the official job site of the US government.</p>]]>
      <![CDATA[<h2>Drive by Downloads and Trojans at Monster.com in 2007</h2>

<p>In August 2007, virus writers set their sights on Monster.com using a Trojan in advertisements on the site as a means of installing malicious software on visitors' machines.  While some ads required a visitor to click on the ads, others merely needed a visitor to land on the page hosting the ad.</p>

<p><a href="http://www.symantec.com/index.jsp">Symantec</a>, who had been monitoring and analyzing the attack said that the Trojan stole sensitive data and relayed the information to a remote server controlled by the attackers.  When Symantec accessed the remote server, it found over 1.6 million entries containing personal information belonging to several hundred thousand people.  </p>

<p>Interesting to note was that the data was accessed from specific domains set aside for recruiters and HR personnel - the "Monster for employers" site. "Upon further investigation, the Trojan appears to be using the (probably stolen) credentials of a number of recruiters to login to the Web site and perform searches for resumes of candidates located in certain countries or working in certain fields," Symantec <a href="https://forums.symantec.com/t5/Vulnerabilities-Exploits/A-Monster-Trojan/ba-p/305529;jsessionid=28CDB424157C6F868DE301369EE93764#A112">wrote in their forums</a>.</p>

<h2>Information Security at Monster.com</h2>

<p>Monster.com has provided little information about this latest breach, not disclosing number of accounts compromised or information as to whether it was an internal or external security breach, but this could be standard procedure given the company is still in the process of investigating and determining the extent of the damage.</p>

<p>However, what is interesting to note that the company has decided not to e-mail users according to a report in <a href="http://www.theregister.co.uk/2009/01/24/latest_monster_security_breach/">The Register</a>, meaning users will only learn about it by visiting the Monster.com site and clicking on the 'important security information' link, or reading about it on other sites.</p>

<p>Additionally, the issue of storing user information particularly passwords in unencrypted format is disturbing, especially for a company that has had first hand experience with information security breaches and has had two years to firm up its security policies. </p>

<p>Between large corporations leaving data exposed with insufficient security measures, and un-savvy tech users using same password/user accounts across the board, theft of personal information has become a money maker for the bad guys who can use it for all sorts of nasty things; at worst, identity theft, at best, the horror spam attacks.</p>

<p>We have contacted Monster.com for a comment, but officials could not be reached. We will update this post in the event we hear back from them.</p>

<h2>Update: Monster Worldwide replies to our questions</h2>

<p><strong>RWW: How many user accounts have been compromised?</strong></p>

<p>MW: To be prudent, we are notifying all of our job seekers and customers.</p>

<p><strong>RWW: Will Monster be contacting users?</strong></p>

<p>MW: Monster elected not to send e-mail notifications to avoid the risk that those e-mails would be used as a template for phishing e-mails targeting our job seekers and customers. Monster believes that the combination of on-site notification and password changes is the most effective way to address the situation.</p>

<p><strong>RWW: Is it an internal or external breach?</strong></p>

<p>MW: While Monster is sharing the information necessary to assist and protect our job seekers and customers, we cannot disclose specific details of the situation because we need to protect the integrity of our security systems and our ongoing inquiry into the situation.</p>

<p><strong>RWW: Why are passwords not encrypted, or if they are, how are they compromised?</strong></p>

<p>MW: We don't comment on specific security measures.</p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519-comment:124783</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13519" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php#c124783" />
    <title>Comment from KTG on 2009-01-28</title>
    <author>
        <name>KTG</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I think Mr. Levin has it dead on.  As a consumer interacting in the "wild wild west" that is many parts of the net has to put a little work in.  Checking their online accounts, perhaps getting some ID protection if they aren't up to the task themselves, and checking a <a href="http://www.justaskgemalto.com/" rel="nofollow">digital security site</a> regularly to keep up their knowledge is crucial.</p>]]>
    </content>
    <published>2009-01-29T05:53:58Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519-comment:124628</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13519" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php#c124628" />
    <title>Comment from ADAM K. LEVIN on 2009-01-27</title>
    <author>
        <name>ADAM K. LEVIN</name>
        <uri>http://identitytheft911.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://identitytheft911.com">
        <![CDATA[<p>The monster.com breach is but another confirmation that the level of hacker sophistication continues to evolve and that we must never underestimate their ingenuity or capacity for stealth. Unfortunately, I anticipate that this type of criminal activity will become even more prevalent during this period of economic turmoil. Therefore, it is imperative that business, the Obama Administration and the new Congress keep privacy, security and identity theft issues on the front burner.</p>

<p>Just as many public companies time the release of negative earnings reports to coincide with the end of the trading day on Friday, I am not surprised that disclosure of this particular breach was made on a Friday. </p>

<p>This breach is yet another reminder of why consumers must spend a few minutes every day reviewing online the activity in their bank and credit card accounts and feeling completely comfortable that every transaction they see is correct.</p>

<p>All the best,</p>

<p>Adam K. Levin<br />
Chairman and Co-Founder<br />
Identity Theft 911</p>]]>
    </content>
    <published>2009-01-27T23:08:21Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519-comment:124450</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13519" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php#c124450" />
    <title>Comment from Diamonds on 2009-01-26</title>
    <author>
        <name>Diamonds</name>
        <uri>http://www.diamondonnet.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.diamondonnet.com/">
        <![CDATA[<p>Get rid of the infected machines and start anew.</p>]]>
    </content>
    <published>2009-01-26T18:30:24Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519-comment:124389</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13519" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php#c124389" />
    <title>Comment from Darren Tan on 2009-01-26</title>
    <author>
        <name>Darren Tan</name>
        <uri>http://www.indiesurf.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.indiesurf.com">
        <![CDATA[<p>With more ppl have access to the Internet, it would be no surprise if they have a breach again. Hope the best, prepare for the worst!</p>]]>
    </content>
    <published>2009-01-26T08:26:58Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519-comment:124363</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13519" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php#c124363" />
    <title>Comment from John Franks on 2009-01-25</title>
    <author>
        <name>John Franks</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Another day, another breach... Price Waterhouse Cooper and Carnegie-Mellon’s CyLab have recent surveys that show the senior executive class to be, basically, clueless regarding IT risk and its tie to overall enterprise (business) risk.  I like to pass along things that work, in hopes that good ideas make their way back to me.  Data breaches and thefts are due to a lagging business culture – and people aren’t getting the training they need.   As CIO, I look for ways to help my business and IT teams further their education.   Check your local library:  A book that is required reading is "I.T. WARS:  Managing the Business-Technology Weave in the New Millennium."  It also helps outside agencies understand your values and practices.<br />
The author, David Scott, has an interview that is a great exposure:  <a href="http://businessforum.com/DScott_02.html" rel="nofollow">http://businessforum.com/DScott_02.html</a> -  <br />
The book came to us as a tip from an intern who attended a course at University of Wisconsin, where the book is an MBA text.  It has helped us to understand that, while various systems of security are important, no system can overcome laxity, ignorance, or deliberate intent to harm. Necessary is a sustained culture and awareness; an efficient prism through which every activity is viewed from a security perspective prior to action.  <br />
In the realm of risk, unmanaged possibilities become probabilities – read the book BEFORE you suffer a bad outcome.<br />
</p>]]>
    </content>
    <published>2009-01-25T20:00:49Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519-comment:124349</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13519" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php#c124349" />
    <title>Comment from rachel on 2009-01-25</title>
    <author>
        <name>rachel</name>
        <uri>http://www.workfromhome-business-opportunity.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.workfromhome-business-opportunity.com/">
        <![CDATA[<p>even an animal do not make the same mistake twice<br />
</p>]]>
    </content>
    <published>2009-01-25T15:28:01Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519-comment:124342</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13519" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php#c124342" />
    <title>Comment from Andrew Peters - APLINK on 2009-01-25</title>
    <author>
        <name>Andrew Peters - APLINK</name>
        <uri>http://htt://apink.wordpress.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://htt://apink.wordpress.com">
        <![CDATA[<p>oops I mean i use <a href="http://recruit.net" rel="nofollow">http://recruit.net</a> - fingers all over sorry..</p>]]>
    </content>
    <published>2009-01-25T12:21:43Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519-comment:124341</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13519" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php#c124341" />
    <title>Comment from Andrew Peters - APLINK on 2009-01-25</title>
    <author>
        <name>Andrew Peters - APLINK</name>
        <uri>http://htt://apink.wordpress.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://htt://apink.wordpress.com">
        <![CDATA[<p>I us recruit.net no problems there....</p>]]>
    </content>
    <published>2009-01-25T12:20:18Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519-comment:124340</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13519" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php#c124340" />
    <title>Comment from Balaram on 2009-01-25</title>
    <author>
        <name>Balaram</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>They've to learn from their mistakes... </p>]]>
    </content>
    <published>2009-01-25T11:53:06Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519-comment:124339</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13519" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php#c124339" />
    <title>Comment from venkat on 2009-01-25</title>
    <author>
        <name>venkat</name>
        <uri>http://computersservicing.blogspot.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://computersservicing.blogspot.com/">
        <![CDATA[<p>How these things happen again and despite security levels maintained by companies and using high level security stratergies ,one thing is sure our data and computers are never safe from these viruses and hacking programmers,though we use strong security programs.</p>]]>
    </content>
    <published>2009-01-25T11:25:44Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519-comment:124337</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13519" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php#c124337" />
    <title>Comment from tony on 2009-01-25</title>
    <author>
        <name>tony</name>
        <uri>http://friendfeed.com/tonyknuckles</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/tonyknuckles">
        <![CDATA[<p>Think maybe the Monster and recent credit card scam might be a coincidence?</p>]]>
    </content>
    <published>2009-01-25T09:02:27Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519-comment:124336</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13519" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php#c124336" />
    <title>Comment from Akiva Moskovitz on 2009-01-25</title>
    <author>
        <name>Akiva Moskovitz</name>
        <uri>http://friendfeed.com/akiva</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/akiva">
        <![CDATA[<p>Thankfully, I haven't used Monster to search for a job in over five years.</p>]]>
    </content>
    <published>2009-01-25T08:59:15Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.13519-comment:124335</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.13519" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/monstercom_loses_user_data_aga.php#c124335" />
    <title>Comment from Robert Miller on 2009-01-25</title>
    <author>
        <name>Robert Miller</name>
        <uri>http://friendfeed.com/robertmiller</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/robertmiller">
        <![CDATA[<p>...And they did not learn from the first time...</p>]]>
    </content>
    <published>2009-01-25T08:50:26Z</published>
  </entry>

</feed>
