Hackers get bum rap for corporate America's digital delinquency

March 13th, 2007 Hackers get bum rap for corporate America's digital delinquency

Hacker and organizational culpability in reported incidents of compromised data 1980-2006. Credit: Phil Howard

If Phil Howard’s calculations prove true, by year’s end the 2 billionth personal record – some American’s social-security or credit-card number, academic grades or medical history – will become compromised, and it’s corporate America, not rogue hackers, who are primarily to blame. By his reckoning, electronic records in the United States are bleeding at the rate of 6 million a month in 2007, up some 200,000 a month from last year.

Howard, an assistant professor of communication at the University of Washington, bases his projections on a review of breached-record incidents as reported in major U.S. news media from 1980 to 2006. The total through last year stood at 1.9 billion – or roughly nine records per American adult.

His report delving into the flood of escaping records and some of the related dynamics, co-authored with Kris Erickson, a UW geography doctoral student, will appear in the July edition of the Journal of Computer-Mediated Communication. If anything, Howard contends the numbers they collected are conservative.

He said they were careful to avoid double counting press accounts of the same breached-record incident that led to exposed credit histories and other personal information. He believes similar incidents took place, but went un- or underreported before 2003, when California’s pioneering Notice of Security Breach law took effect. That law requires companies to disclose such lapses, and more than 20 states, including Washington, have since adopted statutes modeled on California’s, Howard said.

He and Erickson also found that:

-- Malicious intrusions by hackers make up a minority (31 percent) of 550 confirmed incidents between 1980 and 2006; 60 percent were attributable to organizational mismanagement such as missing or stolen hardware; the balance of 9 percent was due to unspecified breaches.
-- Likely as a result of California’s law and similar legislation adopted by other states, the number of reported incidents more than tripled in 2005 and 2006 (424 cases) compared to the previous 24 years (126 cases).
-- The education sector, primarily colleges and universities, amounted to less than 1 percent of all lost records, but accounted for 30 percent of all reported incidents.

A single 2003 incident involving 1.6 billion records held by Acxiom, an Arkansas-based company that stores personal, financial and corporate data, dwarfs all others. In that case, the offender controlled a company that did business with Acxiom and had permission to access some files on Acxiom’s servers. But he illegally hacked into other records and then tried to conceal the theft, prosecutors charged.

A much different picture emerges, however, when the past quarter century is viewed in terms of the number of reported incidents. Three out of five point to organizational malfeasance of some variety, including missing or stolen hardware, insider abuse or theft, administrative error, or accidentally exposing data online, Howard and Erickson found.

Thanks to the mandatory reporting process established by California, "We’ve actually been able to get a much better snapshot of the spectrum of privacy violations," Howard said. "And the surprising part is how much of those violations are organizationally prompted – they’re not about lone wolf hackers doing their thing with malicious intent."

While corporate America would prefer to let "market forces" – factors such as negative publicity and expenses generated by data loss – take care of the problem the authors aren’t convinced that would make for an effective strategy, especially with identity theft listed as the fastest-growing crime in the United States. Based on recent history, it looks as though states are more apt to fill the regulatory void than the federal government, Howard said.

Another noteworthy trend, he said, is what’s happening in the education sector, which accounted for nearly a third of reported breaches. This could be explained, Howard and Erickson said, by the fact that colleges and universities "have an organizational culture geared towards information sharing."

Source: University of Washington


print this article email this article download pdf blog this article bookmark this article     Digg this Stumble it share on Facebook share on Reddit add to delicious save to Yahoo! bookmarks
4.1/5 after 15 votes


March 13th, 2007 all stories
Technology / Computer Sciences

Comments: 0
Rank: 4.1/5 after 15 votes

  • Stumble this up

  • Digg this

  • Share it:
  • share on Facebook
  • share on MySpace
  • share on Slashdot
  • rss-newsfeed
  • share on Google
  • share on Reddit
  • add to delicious
  • save to Yahoo! bookmarks
  • share on Windows Live
  • Add to Mixx!
Rating: 4.1/5 after 15 votes

  • Related Stories

  • Procedure starts angioplasty in wrist rather than leg
    created Jun 05, 2009 | popularity not rated yet | comments 0
  • In pandemics of the past, caution for the future
    created May 24, 2009 | popularity not rated yet | comments 0
  • IBM Developing Computing System to Challenge Humans on America's Favorite Quiz Show, Jeopardy! (w/Video)
    created Apr 27, 2009 | popularity not rated yet | comments 0
  • Women less likely to have a stroke after mini-stroke
    created Feb 23, 2009 | popularity not rated yet | comments 0
  • Low maternal cholesterol tied to premature birth
    created Oct 01, 2007 | popularity not rated yet | comments 0

Tags


  • Physicists Demonstrate Quantum Memory with Matter Qubits
    Physicists Demonstrate Quantum Memory with Matter Qubits
    Physics / General Physics
    created Jul 03, 2009 | popularity 4.4 / 5 (16) | comments 1
  • 'Holey' Nanosheets for Wastewater Dye Removal
    Nanotechnology / Nanomaterials
    created Jul 01, 2009 | popularity 5 / 5 (5) | comments 1
  • Jellyfish Robot Swims Like its Biological Counterpart
    Jellyfish Robot Swims Like its Biological Counterpart
    Electronics / Robotics
    created Jun 26, 2009 | popularity 4.4 / 5 (7) | comments 1
  • Could Maxwell's Demon Exist in Nanoscale Systems?
    Could Maxwell's Demon Exist in Nanoscale Systems?
    Physics / General Physics
    created Jun 24, 2009 | popularity 4.4 / 5 (18) | comments 29
  • Living Safely with Robots, Beyond Asimov's Laws
    Living Safely with Robots, Beyond Asimov's Laws
    Electronics / Robotics
    created Jun 22, 2009 | popularity 4.6 / 5 (52) | comments 40
  • Other News

    Japan demands 119 million dlrs in tax from Amazon: report

    Technology / Business

    created 2 hours ago | popularity not rated yet | comments 0

    Japanese authorities told a sales affiliate of US retail giant Amazon.com to pay about 119 million dollars in tax for unreported income over a three-year period, a newspaper said Sunday.


    Iconic skyscrapers find new luster by going green (AP)

    Iconic skyscrapers find new luster by going green

    Technology / Energy

    created 3 hours ago | popularity not rated yet | comments 0

    (AP) -- When owners of the Empire State Building decided to blanket its towering facade this year with thousands of insulating windows, they were only partly interested in saving energy. They also needed ...


    Downturn dating: Hearts flutter as markets stutter (AP)

    Downturn dating: Hearts flutter as markets stutter

    Technology / Internet

    created 3 hours ago | popularity not rated yet | comments 0

    (AP) -- Credit the recession for "staycations" and bringing us more game-night parties at home. But also give it a shout for spurring more first dates.


    UK spy chief's family details posted on Facebook

    Technology / Internet

    created 3 hours ago | popularity not rated yet | comments 0

    (AP) -- He's the spy who came in from the beach.


    Omg! Positive tone boosts Yahoo celeb site to top

    Technology / Internet

    created 22 hours ago | popularity 2.5 / 5 (2) | comments 0

    (AP) -- Think of the most popular brands in celebrity news, and you'll probably come up with a small list that includes Entertainment Tonight, US Weekly and People.