![]() |
Theft of personality. Against the company Sony, which made a leak of personal data, almost 100 million users of the PlayStation Network network, the first lawsuit was filed. Lawyers have no doubt that claims will follow from other victims. Sony as a result of the scandal can lose up to $ 1.5 billion, analysts say. How hackers hunt for personal data - the New Times found out
At the end of April, hackers hacked three Sony online entertainment systems - PlayStation 3, Sony Online Entertainment and Qriocity. Their customers were about 100 million people. They played computer games, watched films, listened to music and, paying for services, indicated their own names and surnames, date of birth, address, numbers and codes of their credit cards and other personal data. Now this information has fallen into the hands of crooks that can use it to receive loans and purchase goods on behalf of electronic hacking victims. The consequences will make themselves felt for many more years, predicts
Steve Ward, representative of Invincea, specializing in Internet secretary.
The Hacker attack was the first lawsuit against Sony to the California Court: it was filed by the Rotkin Law Firm law office, which specializes in collective lawsuits. While the office is the interests of the 36-year-old user of the American Christopher Jones network, but has already announced that she was looking for other victims to turn the lawsuit into group.
The amount of compensation required by the plaintiff is not indicated. But, according to the assessment
The chairman of the company Ponemon Institute Larry Premion, Sony as a result of the scandal can lose up to $ 1.5 billion. In this amount, the expert takes into account not only payments in numerous possible claims, but also a potential fall in the sales of the “toys” of the Japanese company. He guesses that lovers of game consoles will switch with PlayStation to Microsoft Xbox Live. Against the background of the scandal, the Sony shares have already begun to fall: over the past two weeks - by 8.5%.
The PlayStation Network network stopped working on the evening of April 20. The Sony administration explained that the network had to be disabled in connection with the attack of hackers, who still managed to access personal data of users. The loss of personal information can cost Sony expensive. “The main amount is not even payments for the claims of the victims (in the absence of direct damage, they can pay a couple of thousand dollars at best), and large fines from the supervisory authorities,” says he says
Searchinform analyst Roman Idov. "
Russian specifics - "drain" of the bases of personal data from state bodies
"
Hackers who attacked the game network were interested in money that can be earned on the sale of personal data of players, I am sure
Security specialist G Data Software in Russia and the CIS Roman Karas. “The cost of such information in underground forums can reach € 70 per credit card and € 25 per loan in the PlayStation Network,” the expert said. In addition, knowledge of personal data of users will allow spamers to deploy a whole series of traps for account owners to lure even more money out of them.
Analyst Huffpost Tech Larry Magid predicts a mass mailing into stolen email addresses of the so -called phishing letters - links to the official websites of computer games, where scammers ask to enter their data
* * The New Times wrote in detail about this type of computer crimes in No. 9 of March 14, 2011.
On the fly in Sony’s corporation is not the first and, unfortunately, not the last of the large companies that became a victim of hackers. Here are just a few examples of large -scale “leaks” that have happened in the United States in recent years: one of the largest databases, Choicepoint, was missing personal parameters of 145 thousand people. Another leading database, Lexisnexis, lost data for 310 thousand persons. Time Warner Corporation - 600 thousand personal files. Bank of America in the same way “made” about 1.2 million its customers in the same way, Citigroup lost personal data of 3.9 million people.
The author of these lines knows firsthand about unpleasant surprises associated with the loss of personal data. Last year, I decided to change the mobile operator. I filled out an application on the company's website and waited for parcels with new phones. And suddenly - a refusal. It turned out that in this company mobile communications on the author there is a debt of several thousand dollars, about which I - neither a dream nor spirit. He requested his dossier in the credit bureau - Credit Report. He received, as expected in such cases, for free. In the "Negative Information" section: the very mythical debt of the telephone company. The name and surname is mine, the number of social insurance is also, and the address and phone are “from the lantern”.
He filed a complaint with the credit bureau, they conducted an investigation: the author was rehabilitated, but a lot of time and nerves had to be spent. Crooks, which issued a mobile company for several thousand dollars, were never found. As they gained access to personal data, it also remained a secret. The police and the FBI have enough forces only for Krupnyak.
The national disaster in the United States, according to the federal trade commission, every fourth family one way or another encountered a leakage of personal data. Every year, scammers stole personal data about 10 million people - about 3.25% of the population. For comparison: in the UK, about 100 thousand cases of theft of personal data (0.17% of the population) occurs annually. Experts associate such a difference in numbers with the features of European and American legislation in the field of personal data protection. In particular, the legislation of Western European countries forbids companies to share personal information with other organizations - it can neither be sold or given to the deadly. In America, this is allowed. In Europe, companies are not allowed to create and sell databases with an address and telephone history of people. In the United States, such databases are often used by commercial organizations that, looking for debtors, are associated with their relatives and neighbors throughout the address of the addresses. Finally, the directives of the European Union limit the accumulation of personal information, so it is impossible to create gigantic databases such as American Choicepoint or Lexisnexis.
In Russia, hacker attacks aimed at the theft of personal data are also rarely found, soothes Roman Idov from Searchinform: electronic payments are much less common with us than in the West. However, high -profile stories related to the leakage of personal data also happen with us. At the beginning of May, the Prochrenevsky movement “ours” came to the data of more than 100 people who transferred funds using the Yandex.Money service to maintain the anti -corruption site of the lawyer Alexei Navalny Rospil. As it turned out, the FSB of Russia requested these data from Yandex, after which they migrated to the hands of “third parties”. “If you are going to fight hackers,” the famous
Blogger Anton Nosik, then keep in mind that they are sitting in state bodies. ”
“Russian specifics -“ drain ”of personal data bases from state bodies,” Roman Idov confirms. - On the black market you can buy traffic police base, telephone databases, registration and criminal records. But for this they will not even be fined, or the matter is limited to symbolic amounts of several thousand rubles. ” “The Russians also do not have to count on compensation for court claims. Most of the cases related to the leakage of personal data, even if they reached the court, ceased due to the lack of the composition of the offense, ”the expert adds.
Hope for progress, some experts believe that the problem of theft of personal data will resolve by itself as technology develops. “Plastic money” will go into the past - credit cards. It will not be necessary to leave your personal data on the Internet sites. Instead, we will, for example, wear an electronic chip on the hand with unique personal information, and a certain cunning device will, if necessary, read our data. Or smart machines will recognize us by fingerprints without any cards. This technology, by the way, already exists in the USA: in the states of Texas, Missouri, Washington, Kansas, people pay in some stores, applying fingers to a special record.
In mid -May, the international company Visa, which is the world leader in electronic payments, announced the launch of a new service - a digital wallet. It will allow its owners to have several accounts at once, and they can be opened in different banks. But the most important thing: to use this digital wallet, a plastic card is not required - a regular mobile phone is enough.
In Japan and South Korea, users of “mobile phones” can already with their help make purchases: the purchase amount is immediately deducted from the bank account. Electronic microcircuits built into the phones operating on radio frequencies are so well protected that hackers - so far - does not have a chance of intercepting information or breaking off accounts.
How to protect your personal data tips from John Sileo, the author of the bestsellers on the theft of personal data (“Stolen lives”, “Personal data as a source of profit”):
• If you are on social networks like Facebook or Twitter, install settings that do not allow you to see your profile through Google and other search engines.
• Make so that you share information only when a team enters from you, and not automatically, “by default”.
• Do not put anything superfluous on your page - there should be only that you are not afraid to betray publicity.
• No need to save passwords on the Internet for easy entering the website. Such a “saving time” may cost you a lot if your computer is in the hands of a crook.
• Do not let websites save your credit cards for the future. It is better to print 16 digits once again than then to lay out the consequences of the theft of your data.
• Before entering your personal data on some kind of commercial website, make sure that the address of this page does not begin with HTTP, but with HTTPS: this is a sign of a secure page with which it is safe to make financial transactions and send personal data.
• Do not make purchases from those Internet sorting people who do not indicate the physical address and phone number on their sites. If the coordinates of the company are only a mailbox and an email address, this should be a red traffic light for you.
• Do not rush to help “friends who are in trouble” who are asking for help: before sending money, call them on the phone.
• If someone calls you or sends E-Mail with a request to confirm your personal data-bank account number, TIN, etc., do not rush to respond. Banks, credit companies and state institutions, under which crooks are most often masked, usually do not “ask” the information that they have stored.
• Minimize the number of credit cards - do not give unnecessary chances to thieves. When buying airline tickets, books, drugs, etc. Use the same credit card. And give your email address to all businessmen the same thing - even if you have a whole dozen of them.
• Do not wear in a wallet, wallet, PIN codes, passwords, account numbers, etc. If you cannot remember the necessary data, put it into a notebook, which is always with you, but disguise this data in one way or another-do not write completely, in another language, some kind of cipher ...
• Pass all the old bank extracts through Schroeder, all unnecessary checks and receipts-do not just throw a single piece of paper on which there is at least some kind of identification information.