Mobile Version
Subscribe
Contact Us
About Us
Advertising
Editorial
SC UK
SC Aus/NZ
Home
News
Features
Opinions
Newsletters
Products
Sectors
Company Moves
News Bytes
Products
Group Tests
First Looks
Products
About Reviews
Blogs
The News Team Blog
The Data Breach Blog
The SC Magazine Awards Blog
Buyers Guide
Whitepapers
Jobs
Events
SC Magazine Awards
SC World Congress
SCWC 24/7
Editorial Webcasts
Vendor Webcasts
Podcasts
Subscribe
Newsletters
Subscribe to SC
Archive
SC World Congress
Archive
Topic Center:
Financial Services
Health Care
Retail
Government
Compliance
20th Anniversary
SC Awards
RSA Conference
RSS
|
Login
|
Register
Home
>
News
> LendingTree sued over data breach
LendingTree sued over data breach
Sue Marquette Poremba
May 21, 2008
Print
Email
Reprint
Permissions
Font Size:
A
|
A
|
A
Related Articles
LendingTree insider attack exposes personal data
Data breaches rose dramatically during 2008
Related Links
Lending Tree
More In News
Assets frozen for accused pump-and-dumpers
Security firm finds bug in Microsoft virtual program
Gartner: Virtualization security will take time
Ransomware not considered threat for Mac OS X
Microsoft adds workaround for Internet Explorer bug
RELATED TOPICS
Finance
Lawbreakers & Cybercrime
At least two lawsuits have been filed against LendingTree in response to
a data breach that occurred
between October 2006 and early 2008.
The breach reportedly was caused by former employees who shared passwords with mortgage lenders, providing access to loan and personal information of customers.
A lawsuit filed in U.S. District Court in New York last Friday alleges that LendingTree, a mortgage loan provider, failed to adequately protect customers and their confidential records, which included names, Social Security numbers and dates of birth. The suit stated, in part, that customers had their privacy rights violated and were exposed to risks of fraud.
A similar lawsuit was filed last week in Charlotte, N.C., where LendingTree is based.
Data breaches are the most common type of criminal activities committed by employees or former employees, said Avishai Wool, co-founder and chief technology officer of AlgoSec, provider of firewall operations and security risk management solutions.
“The problem of stealing information from within a company is as old as money,” Wool told SCMagazineUS.com on Wednesday. “With emerging technologies, the theft takes new shapes.”
For that reason, he added, it is vital for companies to closely monitor any employee who has access to confidential information.
Because the Lending Tree breach was caused by sharing passwords, Wool recommended that companies review their password policies.
“Companies should reset passwords frequently,” he said.
Also, when an employee leaves a company, the password to that account should be changed immediately, especially if the account is otherwise left open for any reason, Wool said.
Most importantly, companies should not rely solely on passwords to protect data, he said. Security-conscious companies also use additional measures, such as token with code numbers that change every few minutes.
LendingTree representatives did not respond to a request for comment.
|
Share
Most Popular
Most Emailed
Most Recent
Pennsylvania CISO out of a job following RSA Conference appearance
LifeLock settles with FTC over ID theft product claims
Apple issues Safari 4.0.5 to fix 16 vulnerabilities
India, Mexico, Brazil have most Mariposa bots
Twitter to vet links with goal of curbing phishing attacks
Troyak shutdown signals short-lived win against Zeus
Let's get back to reality
Web fraud losses more than double in 2009, says report
Ransomware not considered threat for Mac OS X
Gartner: Virtualization security will take time
LifeLock settles with FTC over ID theft product claims
Military ban against USB drives partially lifted
Pennsylvania CISO out of a job following RSA Conference appearance
Newly discovered Zeus spinoff botnet has wide impact
Microsoft offers two fixes, but reveals a zero-day bug
FTC notifies 100 organizations about P2P leaks
CSO of the Year
The enterprise information protection paradigm
Rootkit to blame for Windows fix resulting in blue screen
RSA Conference: White House declassifies U.S. cybersecurity initiative details
Security firm finds bug in Microsoft virtual program
Gartner: Virtualization security will take time
Ransomware not considered threat for Mac OS X
Web fraud losses more than double in 2009, says report
Naked endpoints on your net, and what to do about them
Apple issues Safari 4.0.5 to fix 16 vulnerabilities
LifeLock settles with FTC over ID theft product claims
Troyak shutdown signals short-lived win against Zeus
Pennsylvania CISO out of a job following RSA Conference appearance
Twitter to vet links with goal of curbing phishing attacks
Popular Topics
Analyst Reports & Industry Surveys
Apple Threats
Botnets
Breach Remediation
Breaches & Exposures
Browser Flaws
Cybercrime
Data Breaches
Data Leakage Prevention
Database Security
Endpoint Protection
Government
Hackers
Hacking
Identity Theft
Lawbreakers & Cybercrime
Malware
Patch Management
Patch Tuesday
Phishing
Retail
RSA Conference 2010
Virtualization
Vulnerabilities & Flaws
Vulnerability Management
Sponsored Links