News: 1707802094

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Infosys subsidiary named as source of Bank of America data leak

(2024/02/13)


Indian tech services giant Infosys has been named as the source of a data leak suffered by the Bank of America.

Infosys disclosed the breach in a [1]November 3, 2023, filing [PDF] that revealed its US subsidiary Infosys McCamish Systems LLC (IMS) "has become aware of a cyber security incident resulting in non-availability of certain applications and systems in IMS."

A data breach [2]notification filed in the US state of Maine this week describes the incident as "External system breach (hacking)" and reveals the improperly accessed data includes "Name or other personal identifier in combination with: Social Security Number."

[3]

The notification was submitted by an outside attorney working on behalf of the Bank of America, names IMS as the source, and revealed that information on 57,028 people was leaked.

[4]

[5]

A sample of the [6]letter [PDF] sent to those impacted by the incident reveals that on November 24, "IMS told Bank of America that data concerning deferred compensation plans serviced by Bank of America may have been compromised. Bank of America's systems were not compromised."

[7]India's big four services giants soar on demand for AI

[8]Infosys co-founder doubles down on call for 70-hour work weeks

[9]Working from home never looked better: Leopard stalks around Infosys and TCS campuses

[10]Wipro: Get back to the office for three days a week or else

Things then get a bit scary: "It is unlikely that we will be able to determine with certainty what personal information was accessed as a result of this incident at IMS. According to our records, deferred compensation plan information may have included your first and last name, address, business email address, date of birth, Social Security number, and other account information."

In other words, almost everything a fraudster needs to attempt identity fraud – a likely outcome of this event as the term "deferred compensation plan" describes private pensions, retirement savings plans, and awards of stock options.

The term can also describe payouts under life insurance policies, which The Register mentions as IMS [11]bills itself as "the center of excellence for Infosys's Life Insurance software solutions and services offerings in the US."

[12]

The Register has asked Infosys to explain the incident. We've not received a response at the time of publication.

But we note that on November 4, 2023, an [13]allegation emerged that the notorious LockBit ransomware-as-a-service gang was behind the incident at IMS.

Ransomware certainly fits the description of the incident.

[14]

Victims have been offered the usual advice – change passwords, watch your accounts for stuff you didn't do – and the customary two years of free identity theft protection services from Experian. ®

Get our [15]Tech Resources



[1] https://www.sec.gov/Archives/edgar/data/1067491/000106749123000059/exv99w01.htm

[2] https://apps.web.maine.gov/online/aeviewer/ME/40/c2da936e-14f0-421a-833e-a24cbdd79cfa.shtml

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZctL2Rh0vpRzNWX4mDRi@gAAAUM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZctL2Rh0vpRzNWX4mDRi@gAAAUM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZctL2Rh0vpRzNWX4mDRi@gAAAUM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://apps.web.maine.gov/online/aeviewer/ME/40/c2da936e-14f0-421a-833e-a24cbdd79cfa/58970c93-7322-4f85-ac74-e2715d066d79/document.html

[7] https://www.theregister.com/2024/01/18/hcl_infosys_tcs_wipro_results/

[8] https://www.theregister.com/2024/01/15/narayana_murthy_long_work_comments/

[9] https://www.theregister.com/2024/01/17/leopard_infosys_tcs_india/

[10] https://www.theregister.com/2023/11/08/wipro_office_return/

[11] https://www.infosysbpm.com/mccamish/about.html

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZctL2Rh0vpRzNWX4mDRi@gAAAUM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://twitter.com/DarkWebInformer/status/1720868655037120602

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZctL2Rh0vpRzNWX4mDRi@gAAAUM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://whitepapers.theregister.com/



System approach is necessary

Anonymous Coward

Private details should be centralized in a few highly guarded places, split by content type if necessary, and accessed on demand with logs and immediate notifications to data owners for any access. Users could allow or block access requests through their smartphones, as the devices have already become keys to everything.

Otherwise only the regulatory and legal bureaucracy bubbles are blown. Also spreading security workforce into managing distributed risks is less productive than concentrating it in a few highly specialized places.

Re: System approach is necessary

Binraider

In a former life at a bank, there were considerable safeguards and logs on any account data access. An employee searching for notable clients without reason would rightly be pulled.

Dependency

elsergiovolador

It's so great to know that Infosys doesn't work on any critical infrastructure in the UK. Oh wait...

"Oops," Says MPAA President

Recently, the United States filed a legal brief in support of the MPAA's
argument that linking to the DeCSS source code is not protected by the
First Amendment.

At the time, the MPAA was ecstatic. But not any longer. The tables have
turned: the Federal government has filed a lawsuit against the movie
industry, arguing that many Hollywood-produced movies 'link' to illegal
content. The MPAA is now desperately wrapping itself up in the Bill of
Rights.

"Murder is illegal. Showing a murder in a movie -- or, rather, 'linking'
to it -- is also illegal," explained a spokesperson for the Coalition Of
Angry Soccer Moms In Support Of Brow-Beating Movie Industry Executives, an
interest group that has backed the government's lawsuit.