trilium banner March 2012
     

By Sophie Baker

RSA executive chairman Art Coviello’s revelation that internal systems at RSA had been the victims of cybercrime, and that the resulting data breach could compromise the authentication capabilities of the SecurID authentication tokens, has rocked the security industry.

RSA, the security division of EMC, released an open letter from Coviello, addressing RSA customers. It read: “Our investigation has led us to believe that the attack is in the category of an Advanced Persistent Threat (APT). Our investigation also revealed that the attack resulted in certain information being extracted from RSA's systems. Some of that information is specifically related to RSA's SecurID two-factor authentication products. While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers, this information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack. We are very actively communicating this situation to RSA customers and providing immediate steps for them to take to strengthen their SecurID implementations.”

SecurID tokens are used by tens of millions of users to securely log into online banking and enterprise networks over the internet.

The industry has commented on the news, with IronKey speculating on the potential damage this data breach could cause.

“Criminals used an Advanced Persistent Threat (APT) attack to breach the RSA SecurID infrastructure, and can now combine that information with data-stealing malware in order to compromise high value online banking sites,” explained Dave Jevans, IronKey’s founder and chairman.

IronKey said the incident, despite being investigated, threatens the integrity of bank payment services, enterprise remote access and government systems.
RSA Security did not take up its right to reply at the time of press.

Home     More News


Other stories you may find of interest:

Cumberland runs rings around fraudsters
Cumberland Building Society is incorporating ValidSoft’s Valid authentication solution into a new secure transaction service for its online banking customers. The technology provides two or three factor authentication via phones or text messages to improve security

bankers accuity may 2012


six_group

tdwi


FStech Whitepapers
Are We There Yet? Zero-Wait BI for Everyone
This CITO Research white paper, examines the business benefits of enabling users to perform their own data analysis, without making continual demands on IT.
Mobility Is Exploding: Are You Ready?
Mobile business intelligence replaces static information with real-time information, empowering data-driven decisions on the spot. This paper describes use cases to for bringing not just BI, but business discovery, to the front lines of your business.
Single Customer View in Financial Service
This white paper outlines what a single customer view is and what the UK requirements are, why this represents best practice and how it can be advantageous to the business, and the techniques and technologies that will be most effective in establishing and maintaining such an approach.
TATA Consultancy Services - Cloud Computing
Cloud computing is the convergence of virtualization, distributed applications, grid, maturity of enterprise software applications and enterprise IT management.
Genesys. Sustained Management: Changing the Game with Genesys iWD
The article explains how Genesys intelligent Workload Distribution (iWD) has the power to change the game in the contact center space based on new visibility into tracking, reporting, and performance management
Research Study: The Revolution in Self-Service Channels in the Financial Services Sector
This report analyses the growth of consumer self-service channels in key areas of the Financial Services Market
Genesys. Staffing and Workload Management:
Fleshes out the importance of properly managing contact center and back office work, especially through the alignment of employee skill sets.
Genesys. The Importance of Proper Hiring, Training, Career Path Development, Skilling, and Routing
Which explains why it is imperative to implement these factors correctly in the contact center and back office to ensure competent customer interactions.
Dataflux Video

This website is a part of Perspective Publishing Limited, registered in England No 2876166.