Massive data theft leads investigators to India hackers, New York businessman
June 4, 2010 By Dan BrowningA massive data theft from the e-commerce company Digital River has led investigators to hackers in India and a 20-year-old in New York who allegedly tried to sell the information to a Colorado marketing firm for half a million dollars.
The Eden Prairie, Minn., company obtained a secret court order last month to block Eric Porat of Brooklyn from selling, destroying, altering or distributing purloined data on nearly 200,000 individuals. Digital River suspects the information was stolen by hackers in New Delhi, possibly with inside help.
Porat has said he got the information from India, but won't say how or from whom.
"I fully suspect that Mr. Porat hacked the hacker," said Christopher Madel, an attorney with Robins, Kaplan, Miller and Ciresi who is overseeing Digital River's investigation.
The matter came to light Thursday afternoon when U.S. District Judge Donovan Frank convened a public status conference in the case. The hearing was posted on the court docket without listing any of the parties involved.
A reporter attended the hearing, and Frank ordered all previously filed documents to be unsealed without objection. Frank, who co-chairs a committee on public access to the federal courts in Minnesota, said he temporarily allowed the civil case to be filed under seal -- and without notice to the defense -- so that Digital River could issue subpoenas and safeguard evidence that might otherwise be destroyed or disappear.
Digital River Marketing Solutions Inc. filed the lawsuit under seal on May 13 listing Porat and his company Affiliads LLC, as defendants and demanding to know how they obtained the firm's data and what they've done with it.
The data was originally gathered by companies that offer "affiliated marketing" programs, a practice in which businesses pay a commission to affiliates who post links on the Internet that drive customers to participating companies. The affiliates get paid when consumers buy something, make an inquiry or provide a sales lead.
Direct Response Technologies, a Digital River subsidiary based in Pittsburgh, Penn., sells a leading software program called DirectTrack to help companies create and manage affiliated marketing programs. Data gathered by the program gets stored on Digital River's servers, and access to it is tightly restricted with passwords and other security measures, the company says.
Since the lawsuit was filed, Porat has tried to be as forthcoming as possible without waiving his constitutional rights, said his attorney, Joseph Nierman, of Passaic, N.J. He noted that Porat participated in a deposition with the plaintiffs that lasted nearly six hours.
Madel said that while Porat has cooperated, he also invoked his Fifth Amendment right against self-incrimination "about 26 times," refusing to explain how he got the data, or from whom. "I am very reluctant to say that Mr. Porat has been forthcoming" with everything he knows, Madel said.
Porat said Thursday evening that he was too busy to talk to a reporter.
Regardless of how he got the data, the suit alleges that Porat tried to sell it for $500,000 to Media Breakaway, a Westminster, Colo.-based marketing firm, as well as to some of its competitors. Court records say that Porat had been an affiliate of Media Breakaway, collecting commissions totaling $1,600 for driving consumer traffic to the firm.
According to Media Breakaway records, they initially spurned Porat's offer. When he persisted, the company notified Digital River and helped the FBI to investigate the matter.
Madel disclosed Thursday that a federal grand jury is investigating the alleged data theft under the direction of Assistant U.S. Attorney Timothy Rank, one of the prosecutors in the trial of convicted Ponzi schemer Tom Petters.
Porat, who lives at home with his parents, claimed in e-mails and instant messages with Media Breakaway that he had consumer-tracking information from a dozen different companies, including names, e-mail addresses, websites, company names and unique user-identification numbers for 198,398 individuals. These data are valuable to companies seeking targeted marketing lists of potential customers.
Scott Richter, CEO of Media Breakaway, said in a court filing that Porat claimed to be offering the DirectTrack data to the highest bidder. He said Porat told him he got the data from a former consultant for Digital River, who captured it during an enhancement of the DirectTrack data system when security systems were taken down temporarily.
Gary Olden, vice president of product management at Digital River Marketing, said in a court filing that an internal investigation found that the stolen data was accessed Jan. 27 from four different computers linked to a DirectTrack customer in New Delhi named VCommission, or Vaxat iTech Pvt. Ltd. He said the data was downloaded using a "highly unusual" search command.
Olden said he could find only one other instance where that type of command was used to access DirectTrack data. It took place six hours after the command was issued in India, and it came from another customer, Clickbooth/IntegraClick, a marketing firm in Sarasota, Fla. In that case, though, the user only accessed Clickbooth/IntegraClick's own data, he said.
Olden said his customers and clients view data security as an important component of DirectTrack, as they have "a significant interest in ensuring that their customer lists are not made available to their competitors (let alone sold to the highest bidder)."
(c) 2010, Star Tribune (Minneapolis)
Distributed by McClatchy-Tribune Information Services.
-
TD Ameritrade data theft settlement gets court OK
May 11, 2009 |
not rated yet |
0
-
Verizon sues to block data theft
Jan 24, 2006 |
not rated yet |
0
-
Trust Digital Offers Smart-Phone Security Management Tool
Mar 19, 2007 |
not rated yet |
0
-
AT&T claims ownership of customer data
Jun 22, 2006 |
not rated yet |
0
-
T-Mobile: No security breach in alleged hacking
Jun 10, 2009 |
not rated yet |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (31) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Calling function with no input argument
8 hours ago
-
Force free body diagram problem on gym equipment
8 hours ago
-
Empirical data regarding shower heads and water
16 hours ago
-
feed hold button on CNC lathe
Feb 09, 2012
-
RFAC in Fortran
Feb 09, 2012
-
dynamics 2/32
Feb 08, 2012
- More from Physics Forums - General Engineering
More news stories
Google users warned of threat to smartphone wallets
Users of Google smartphone wallets were being warned on Friday that there is a way to crack pass codes intended to thwart thieves from going on illicit shopping sprees.
1 hour ago |
5 / 5 (1) |
0
Anonymous knocks CIA website offline (Update)
The website of the Central Intelligence Agency was inaccessible on Friday after the hacker group Anonymous claimed to have knocked it offline.
2 hours ago |
5 / 5 (4) |
8
New error-correcting codes guarantee the fastest possible rate of data transmission
Error-correcting codes are one of the triumphs of the digital age. Theyre a way of encoding information so that it can be transmitted across a communication channel such as an optical fiber o ...
Technology / Computer Sciences
11 hours ago |
5 / 5 (4) |
5
|
New power source discovered
(PhysOrg.com) -- Researchers at the Massachusetts Institute of Technology (MIT) and RMIT University have made a breakthrough in energy storage and power generation.
Technology / Energy & Green Tech
10 hours ago |
4.8 / 5 (16) |
5
|
Small modular reactor design could be a 'SUPERSTAR'
(PhysOrg.com) -- Though most of today's nuclear reactors are cooled by water, we've long known that there are alternatives; in fact, the world's first nuclear-powered electricity in 1951 came from a reactor ...
Technology / Energy & Green Tech
10 hours ago |
4.2 / 5 (10) |
19
|
Complex wiring of the nervous system may rely on a just a handful of genes and proteins
Researchers at the Salk Institute have discovered a startling feature of early brain development that helps to explain how complex neuron wiring patterns are programmed using just a handful of critical genes. ...
NASA sees wide-eyed cyclone Jasmine
Cyclone Jasmine's eye has opened wider on NASA satellite imagery, as it moves through the Southern Pacific Ocean.
NASA sees Giovanna reach cyclone strength, threaten Madagascar
Tropical Storm 12S built up steam and became a cyclone on February 10, 2012 as NASA's Terra satellite passed overhead. Residents of east-central Madagascar should prepare for this cyclone to make landfall ...
Putting the squeeze on planets outside our solar system
(PhysOrg.com) -- Using high-powered lasers, scientists at Lawrence Livermore National Laboratory and collaborators discovered that molten magnesium silicate undergoes a phase change in the liquid state, abruptly ...
The power of estrogen -- male snakes attract other males
A new study has shown that boosting the estrogen levels of male garter snakes causes them to secrete the same pheromones that females use to attract suitors, and turned the males into just about the sexiest ...
Grass to gas: Researchers' genome map speeds biofuel development
Researchers at the University of Georgia have taken a major step in the ongoing effort to find sources of cleaner, renewable energy by mapping the genomes of two originator cells of Miscanthus x giganteus, a large perenn ...
Jun 04, 2010
Rank: not rated yet
Jun 04, 2010
Rank: not rated yet
Jun 05, 2010
Rank: not rated yet