• Most Popular
  • Most Shared
Vincent Padois, head tutor at the Pierre and Marie Curie University who teaches robotics and is babysitting the Paris ICub, makes a demonstration with ICub robot, a ?hybrid embodied cognitive system for a humanoid robot" about 1 metre (3.2 feet) high, at the Pierre and Marie Curie University in Paris September 4, 2009. Six versions of ICub exist in laboratories across Europe, where scientists are painstakingly tweaking its electronic brain to make it capable of learning, just like a human child and hoping it will learn how to adapt its behaviour to changing circumstances, offering new insights into the development of human consciousness.   REUTERS/Philippe Wojazer

Pictures of the year: Technology

A look at the year's best science and technology photos.   Slideshow 

    Monster.com took 5 days to disclose data theft

    BOSTON
    Fri Aug 24, 2007 9:35am EDT
    A screen grab of Monster.com. The names and contact information of some 1.3 million job seekers were stolen from Monster Worldwide Inc, the U.S. online employment Web site said on Thursday. REUTERS/www.monster.com

    BOSTON (Reuters) - Monster.com waited five days to tell its users about a security breach that resulted in the theft of confidential information from some 1.3 million job seekers, a company executive told Reuters on Thursday.

    U.S.  |  Technology

    Hackers broke into the U.S. online recruitment site's password-protected resume library using credentials that Monster Worldwide Inc said were stolen from its clients, in one of the biggest Internet security breaches in recent memory.

    They launched the attack using two servers at a Web-hosting company in Ukraine and a group of personal computers that the hackers controlled after infecting them with a malicious software program known as Infostealer.Monstres, said Patrick Manzo, vice president of compliance and fraud prevention for Monster, in a phone interview.

    The company first learned of the problem on August 17, when investigators with Internet security company Symantec Corp told Monster it was under attack, Manzo said.

    "In terms of figuring out what the issue was, that was a relatively quick process," he said. "The other issue is you want to make sure exactly what you are dealing with."

    His security team spent the weekend investigating, located the rogue servers, and got the Web-hosting company to shut them down some time either late in the evening on August 20, or early in the morning of August 21, he said.

    Manzo said that based on Monster's review, the information stolen was limited to names, addresses, phone numbers and email addresses, and no other details including bank account numbers were uploaded.

    On August 21, Symantec published a report on its Web site that said it had found copies of scam e-mails that the engineers of the attack were using, with the aim of getting information that was more valuable than just the names and contact details of Monster.com users.

    Pretending to be sent through Monster.com from job recruiters, the e-mails asked recipients to provide personal financial data, including bank account numbers. They also asked users to click on links that could infect their PCs with malicious software.

    Their ultimate goal in taking the data from Monster.com was to gain enough personal information to lower the guards of target victims when they read the e-mails, said Patrick Martin, a senior product manager with Symantec's response team in Austin, Texas, which first identified the attack.

    "It gives these spam e-mails just a little bit of credibility," Martin said. "These guys were trying to get financial information from people."

    It wasn't until Wednesday, a day after Symantec issued the August 21 report, that Monster put a notice on its Web site, www.monster.com, warning users they might be the target of e-mail scams.

    Monster then announced on Thursday that the details of some 1.3 million job seekers had been stolen. Fewer than 5,000 of those affected are based outside the United States, it said in a statement.

    A company spokesman said Monster also posted letters to the 1.3 million affected users on Thursday in case the users were wary of opening e-mail from the company after the breach. He said Monster's database has about 73 million resumes.

    The security breach comes at a rough time for the company, which in July reported lower-than-expected quarterly earnings.

    Chief Executive Sal Iannuzzi, who took the company's helm in April, said on July 30 that he plans to cut 800 jobs, or 15 percent of Monster's full-time staff, in a bid to improve its financial performance.



    More from Reuters

    Joint Terminal Attack Controller SSgt Clinton J. Herbison, a U.S. Airman from the 817 Expeditionary Air Support Operations Squadron (EASOS) takes a break during a night mission near Honaker Miracle camp at the Pesh valley of Kunar Province August 12, 2009. Credit: REUTERS/Carlos Barria

    Pictures of the Year

    A look at the best photos of 2009.  Slideshow 

      The Dalai Lama jokes with a nasal spray after being asked his opinion on the swine flu during a press conference after his first lecture in Lausanne, Switzerland, August 4, 2009. REUTERS/ Valentin Flauraud

      What a wacky year it's been...

      Um, what's up the Dalai Lama's nose? "Oddly Enough" editor Bob Basler rounds up the goofiest photos of the year.  Full Article 

      A caution sign is seen next to a stock board at the Australian Securities Exchange (ASX) in Sydney September 5, 2008. REUTERS/Daniel Munoz
      Political Risk in 2010:

      Don't say we didn't warn you

      With the financial crisis (mostly) in the past, U.S. investors are eying a fresh start to the coming year. Here's a look at what speedbumps lie ahead.  Full Article