BATON ROUGE, La. — Whether deploying high-tech data theft methods or something as low-tech as dressing up as a fire marshal, one company says it was able to penetrate more than nine in 10 of the CUs and banks it targeted.
TraceSecurity, a provider of IT risk assessment and security compliance solutions, has released an analysis stemming from five years of social engineering and penetration testing that is says found 95% of U.S. financial institutions' sensitive data, including bank account records and Social Security Numbers, could have been robbed on average in 30 minutes or less.
Between 2003 and 2008, TraceSecurity's said its engineering team compromised the security of more than 1,000 financial institution branches. As an independent auditor for regulated industries including the financial services sector, TraceSecurity said it estimates that tens of millions of consumers' personal identity could have been stolen if the attempts had been legitimate.
The company said those statistics were based on a core group of its more than 800 clients, with assets ranging up to $2.7 billion in 48 states and represented an average of four or more branch locations. "Personally, I've been able to bypass security policies, procedures and technology of any bank or credit union where I've performed social engineering engagements 100% of the time," said Jim Stickley, co-founder and CTO of TraceSecurity.
The tests from which statistics were drawn focused on three types of TraceSecurity solutions: penetration testing, remote social engineering and onsite social engineering.
Penetration testing employs hacking attempts on the company's network through the Internet, whereas Social Engineering tests include phishing, pharming, pre-text calling and onsite impersonation of a trusted third-party.
TraceSecurity said its engineers often disguised themselves as a fire marshal or pest inspector as part of their onsite social engineering engagements. They were able to gain entry 95% of the time into areas that often contain sensitive data, which can be easily compromised.
The company reported that backup tapes storing sensitive data were cited as the easiest target to steal. Other items stolen in the test heists included loan applications, miscellaneous hardware such as laptops, cell phones and PDAs, keyboard data and more containing common information such as Social Security numbers, banking/account numbers, addresses/contact information, mother's maiden names, driver license numbers and credit card numbers.










