Showing posts with label hacker. Show all posts
Showing posts with label hacker. Show all posts

Tuesday, May 8, 2012

Cybersecurity Touchy Subject for US & China

Story first appeared on Politico.com.

Asserting that cyberattacks against the U.S. don't come only from China, the U.S. and Chinese defense ministers said they agreed Monday to work together on cyber issues to avoid miscalculations that could lead to future crises.

The Defense Secretary said that since China and the United States have advanced cyber capabilities, it is important to develop better cooperation.

There are other countries, actors, others involved in some of the attacks that both of the countries receive. But because the United States and China have developed technological capabilities in this arena it's extremely important that they work together to develop ways to avoid any miscalculation or misconception that could lead to crisis in this area.

China's minister of national defense offered a vigorous defense of his country, saying through an interpreter that, all of the cyber attacks targeting the United States do not come from China.

Just six months ago, however, senior U.S. intelligence officials for the first time publicly accused China of systematically stealing American high-tech data for its own national economic gain.

It was the most forceful and detailed airing of U.S. allegations against Beijing after years of private complaints, and it signaled the opening salvo of a broad diplomatic push to combat cyberattacks that originate in China.

Cybersecurity was just one of the many issues discussed by the two leaders during their meeting, but it is also one of a number of contentious topics that rattle the often rocky relationship between the two nations.

The U.S. needs to start laying the ground work for better understanding by the Chinese of what is expected from them in cyberspace. As well as putting better Security Solutions in place among their own technology.

As an example American officials want to know who to talk to when Chinese hackers breach U.S. computer networks. And if there is a cyber incident in China, the US needs the Chinese to feel confident that they can call up and ask, 'was it you?', and get a straight answer.

Chinese officials have routinely denied the cyberspying, insisting that their own country also is a victim of such attacks. And they note that the hacking is anonymous and often difficult to track.

U.S. cybersecurity experts acknowledge that attribution can be difficult, and that while they can trace an attack to China, it is often difficult to track directly to the Chinese government. Last December's report by U.S. intelligence agencies said America must openly confront China and Russia in a broad diplomatic push to combat cyberattacks that are on the rise and represent a persistent threat to U.S. economic security.

And, separately, several cybersecurity analysts have concluded that as few as 12 different Chinese groups, largely backed or directed by the government there, commit the bulk of the cyberattacks that aim to steal critical data from U.S. companies and government agencies. Officials estimate that the stealthy attacks have stolen billions of dollars in intellectual property and data.

Because people and businesses in both China and American have been victims of cyberattacks, officials have been talking more about building a better relationship so that they can work together.

Law enforcement is one area of cybersecurity where the two nations have begun to build partnerships, but so far it has been extremely limited. Lewis said that in 2011, U.S. authorities requested assistance from the Chinese 11 times, and in seven of the cases received no information. But, he said the Chinese cooperated with U.S. law enforcement in a high profile financial fraud case late last year.


For more technology and electronics related news, visit the Electronics America blog.
For national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.

Thursday, April 5, 2012

Utah Medicaid Database Hacked

Story first appeared in the Chicago Tribune.

SALT LAKE CITY (Reuters) - A data security breach at the Utah Health Department, believed to be the work of Eastern European hackers, has exposed 24,000 U.S. Medicaid files bearing names, Social Security numbers and other private information, state officials said on Wednesday.

The intrusion initially appeared to have affected claims representing at least 9 percent of the 260,000 clients of Medicaid in Utah. But because each file often contains information on more than one individual, the full extent of the breach is probably wider, officials said.

Medicaid is a federal-state program that helps pay for healthcare for the needy, the aged and disabled. The state determines eligibility and which services are covered, and the federal government reimburses a percentage of the state's expenditures.

Hudachko said the Technology Services Department notified state health officials Monday evening about the cyber attack.

Technology Services had recently moved the claims in question to a new server, allowing the hackers "to circumvent the server's multi-layered security system," according to officials.

He said the cyber attack is believed to have originated in Eastern Europe, based on a suspicious Internet Protocol, or IP, address, but investigators are still trying to pinpoint the precise source.  It is possible that an outsourced IT Security Solution could have prevented this issue.

GRAVE CONCERNS

Utah state Senator Allen Christensen, who also is a practicing dentist, said each compromised claim is going to have two parties involved - both the recipient and the provider.

The chairman for the Utah State Health and Human Services Committee, expressed grave concerns over the impact on the Medicaid population in Utah and suggested the database was left vulnerable by human error.  An outsourced IT Security Solution would have been a good option to alleviate any possible human error.

State officials said they were examining all servers and reviewing policies and procedures to ensure effective security measures are in place.

The compromised files also contain individuals' names, addresses and other private information.

State Health officials are urging all their Medicaid clients and providers to keep a wary eye on their bank accounts and other personal records. Customers whose Social Security numbers are found to have been compromised will receive free credit monitoring services, officials said.

For more technology related news, visit the Electronics America blog.