Free Newsletters:
DatabaseDaily  
Database Journal
Search Database Journal:
 
MS SQL Oracle DB2 Access MySQL PostgreSQL Sybase PHP SQL Etc SQL Scripts & Samples Links Database Forum DBA Videos
internet.com

» Database Journal Home
» DBA Videos
» Database Articles
» Database Tutorials
MS SQL
Oracle
MS Access
MySQL
DB2
» RESOURCES
Database Tools
SQL Scripts & Samples
Links
» Database Forum
» DBA Jobs
» Sitemap

News Via RSS Feed



follow us on Twitter

Marketplace Partners
Be a Marketplace Partner

internet.commerce
Be a Commerce Partner


















Mariposa Bot Shipped With Vodafone Smartphone

IT Job Market Heating Up: Report

Bing Makes Strides But Momentum Stalls

internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers


Database Journal | DBA Support | SQLCourse | SQLCourse2







Database Administrator - SQL Server (PA)
Next Step Systems
US-PA-King of Prussia

Justtechjobs.com Post A Job | Post A Resume
December 30, 2009

Malicious attack exposes some 30,000 social security numbers at Penn State University

Quite simply some 30,000 social security numbers at Penn State University (PSU) became vulnerable after a malicious software attack. Said a spokeswoman for PSU, "We're not sure if the data was accessed" and "The Social Security numbers were in archived files that people didn't realize were on their computers,"

And because of the 2006 state Breach of Personal Information Notification Act, PSU is mandated to notify anyone whose personally identifiable information is potentially disclosed when a computer is lost or compromised. This they are doing for those affected at the Eberly College of Science and the College of Health and Human Development.

Obviously the two breaches back in 2008 and the other “protection” methods deployed in that same year did nothing to help aid in this particular breach as the school is still trying to determine whose numbers were exposed. Josh Shaul, vice president of product management for Application Security Inc., a New York-based company that specializes in database security said about this breach that "Unfortunately, a majority of organizations that are as large and as longstanding as Penn State are in the same situation” and that “Younger organizations build information technology infrastructure with today's security threats in mind”.

Additinally, Shaul states that “organizations must first protect data they know exist. Second, officials must search for data that could be in unknown places. Finally, officials must establish a system to keep data, known and unknown, within the organizations' networks.”

Interesting quotes as it seems that PSU did try and take measures in 2008 AND I’d venture to say that many new, as well as old, organizations have no idea where all their sensitive data exists within their company. Maybe it’s time we start deploying intelligent mechanisms that detect who, what, and when malicious activity occurs on our networks.

View article

Tools:
Add databasejournal.com to your favorites
Add databasejournal.com to your browser search box
IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news via our XML/RSS feed

Daily News Archives







Latest Forum Threads
Daily News Forum
Topic By Replies Updated
Boonex Dolphin PHP script is SCAM! Beware! webpass 0 March 19th, 10:07 AM
shrinking a Database tkatende 2 March 19th, 08:55 AM
Dropping database yogesphu 3 March 19th, 08:52 AM
Find each salesperson's highest sale ncumbie 1 March 19th, 07:38 AM









The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers