Outsourcing aids many data thefts: Verizon

The reliance of restaurant chains and retail stores on outside companies to handle credit-card processing is partly to blame for a rash of consumer data breaches, according to Verizon Communications Inc.

NEW YORK: The reliance of restaurant chains and retail stores on outside companies to handle credit-card processing and other information-technology functions is partly to blame for a rash of consumer data breaches over the last few years, according to data sleuths at Verizon Communications Inc.

Even a chain with thousands of restaurants might have only 100 employees in information technology, so it uses outside vendors for many IT functions, said Bryan Sartin, director of the investigative response team at Verizon Business.

``What happens is there's a lack of accountability on the third party,'' Sartin said.

Verizon's unit investigates a quarter to a third of the big, publicly announced data breaches that occur each year, and hundreds of smaller cases.

In recent years, restaurant and retail businesses have accounted for more than half of Verizon's 230 to 250 cases per year, according to a report Verizon was set to issue Thursday. It often finds that insiders at service vendors are part of the heists.

Organized data-stealing gangs ``go to the call centers, the Web development companies, the content development companies, the business partners, the people who pick up the backup tapes,'' Sartin said.
ADVERTISEMENT

``They say ... if you hate your boss and you're in financial straits, we're your solution. Give us access to your customers. Better yet, give us your data.''

In a typical case Sartin was involved in, the team was approached by a large oil company in Canada, with thousands of gas stations. Customers were finding spurious charges on their credit cards after using them at the stations.

The team soon figured out that someone at a technology vendor was responsible, but couldn't pin it down. So the investigators set a trap in the system, to see who accessed customer data.

``The trap went off on Saturday morning,'' Sartin said. ``Hackers always think nobody's looking on Saturday mornings.''
ADVERTISEMENT

A police car headed to the vendor's office, and the culprit turned out to be a 21-year-old who supported the software
that operated the gas pumps. He had sold lists of customer data to organized crime.

ADVERTISEMENT
Many breaches don't happen through outsourcing. In one of the largest cases in recent years, the gang that stole 41 mn credit and debit card numbers from chains including TJX Cos. obtained access through unsecured wireless networks, not through subcontractors' systems.

Still, Verizon's report advises companies to keep a tighter rein on contractors, including by limiting partners' access to only the data they need.
Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
Download
The Economic Times News App
for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.
READ MORE
ADVERTISEMENT

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › News › International › Outsourcing aids many data thefts: Verizon
Text Size:AAA
Success
This article has been saved

*

+