|
April, 13, 2010
The Financial Industry Regulatory Authority (Finra) handed DA Davidson the fine for failing to protect the information - including customer account numbers, social security numbers, names, addresses, dates of birth - of 192,000 people.The firm's database was breached on the 25 and 26 of December, 2007, when an unidentified assailant carried out a simple SQL injection attack to download customer details.
The attacks were visible on Web server logs but DA Davidson failed to review them, says Finra. In fact, the firm only became aware of the breach on 16 January, when the hacker sent an e-mail in a blackmail attempt.The company then reported the attack to authorities and helped the Secret Service identify four members of an international group suspected of the hack. Of these, three have been extradited from Eastern Europe, arrested and are facing charges in federal court in Montana.
.
.
|
|