Share

Hackers are closer than you think

New York - Hackers stole personal information from millions of JPMorgan Chase customers this summer, in one of the biggest breaches of a financial company.

The bank says only non-financial data was taken — names, addresses, telephone numbers and email. But that's still a lot of personal detail, and experts warn that customers need to be vigilant about identity theft in the next several months.

The theft — involving 76 million households and seven million small businesses — raises questions about the safety of personal information, especially at banks. What risks do people face? Will this keep happening? And can bank customers reduce the threat of identity or financial theft?

AP conducted a Q&A with leading online security experts:

How concerned should I be if the hackers didn't get social security numbers, bank account or credit card information?

We may not yet know the full scope of what the hackers were able to steal, said Eric Chiu, president of HyTrust, a cloud security company based in Mountain View, California. "They can sit on your network for months, siphoning off data before being detected," said Chiu.

He says that customers' addresses and phone numbers could be used or sold to others who might combine that information with other stolen data. It could then be used to access accounts or even to open new accounts in the unwitting customers' names.

Even if the information isn't used for phishing schemes or direct fraud, it could be sold on the gray market to people who might want to send spam or sales pitches to bank customers. "There's a good market for that kind of data," said Adam Kujawa, head of malware intelligence at Malwarebytes, a San Jose, California company that makes security software.

How close did the hackers get to stealing customers' money or more sensitive financial data?

We don't really know. The hackers may not have been looking to siphon funds, said Chiu, because "data is what's gold now." Other security experts say the bank's public statements suggest that its defenses were partly successful, because hackers weren't able to get other information.

So is this a partial win for the bank?

It might be, said Mike Lloyd, chief technology officer at Sunnyvale, California-based RedSeal Networks. But the bank shouldn't declare victory — cybersecurity is "a never-ending war" against new and evolving threats.

What else could happen?

One concern is that this breach was a reconnaissance mission in preparation for a bigger hack, said Craig Carpenter, chief strategist at AccessData, a cybersecurity firm. "They don't have to crack the entire system tomorrow," he said. "They could have simply been mining for data, or looking to leave something behind that would allow them to get into (JPMorgan's servers) easier next time."

What else should banks do to protect customer data?

The financial industry is already doing more than other industries, said Dwayne Melancon, chief technology officer for the cybersecurity firm Tripwire, in Portland, Oregon.

Chase in particular is known for using advanced security technology, said Avivah Litan, an analyst with Gartner, a technology research firm based in Stamford, Connecticut. But she also says that most companies have trouble keeping up with constant threats, and one big vulnerability lies with employees.

While businesses tend to spend more on defending against outside attacks, many hacks begin with a compromised employee account. Litan says companies must do more to screen workers and also train them in security precautions.

Should I close my account at JPMorgan?

At this point, there's no indication that's necessary. Steve Weisman, a Boston attorney and author of several books and articles about identity theft, said "it won't do any good" because other banks may be equally vulnerable to hacking. "There's no place to run and hide. You should monitor your account regularly and don't trust any communications you receive."

After big attacks against retail chains and now Chase, should we expect more breaches?

The size and scope of the breaches are going to get worse, not better. Target, Home Depot and JPMorgan Chase are just the beginning, said Darren Hayes, a professor and expert in cybersecurity at Pace University in New York.

It's safe to presume that hackers have been sitting inside these banks and business networks for months, even years, sometimes not doing anything. "Hackers these days are patient ... and are extremely effective at just gathering a lot of data over time."

Is there any way to protect myself if they're this sophisticated?

Change your passwords regularly, don't click on links in suspicious emails (they could be phishing attempts by scammers), and regularly check online statements for any charges you don't recognize. Be wary of calls requesting personal information.

How bad is the fallout so far?

The New York-based bank said there's no evidence of financial fraud associated with the breach.

- Fin24.

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.01
+1.1%
Rand - Pound
23.79
+0.7%
Rand - Euro
20.40
+0.8%
Rand - Aus dollar
12.40
+0.7%
Rand - Yen
0.12
+1.2%
Platinum
925.50
+1.5%
Palladium
989.50
-1.5%
Gold
2,331.85
+0.7%
Silver
27.41
+0.9%
Brent Crude
88.02
-0.5%
Top 40
68,437
-0.2%
All Share
74,329
-0.3%
Resource 10
62,119
+2.7%
Industrial 25
102,531
-1.5%
Financial 15
15,802
-0.2%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders