Infosys subsidiary named as source of Bank of America data leak
- Reference: 1707802094
- News link: https://www.theregister.co.uk/2024/02/13/infosys_bank_of_america_leak/
- Source link:
Infosys disclosed the breach in a [1]November 3, 2023, filing [PDF] that revealed its US subsidiary Infosys McCamish Systems LLC (IMS) "has become aware of a cyber security incident resulting in non-availability of certain applications and systems in IMS."
A data breach [2]notification filed in the US state of Maine this week describes the incident as "External system breach (hacking)" and reveals the improperly accessed data includes "Name or other personal identifier in combination with: Social Security Number."
[3]
The notification was submitted by an outside attorney working on behalf of the Bank of America, names IMS as the source, and revealed that information on 57,028 people was leaked.
[4]
[5]
A sample of the [6]letter [PDF] sent to those impacted by the incident reveals that on November 24, "IMS told Bank of America that data concerning deferred compensation plans serviced by Bank of America may have been compromised. Bank of America's systems were not compromised."
[7]India's big four services giants soar on demand for AI
[8]Infosys co-founder doubles down on call for 70-hour work weeks
[9]Working from home never looked better: Leopard stalks around Infosys and TCS campuses
[10]Wipro: Get back to the office for three days a week or else
Things then get a bit scary: "It is unlikely that we will be able to determine with certainty what personal information was accessed as a result of this incident at IMS. According to our records, deferred compensation plan information may have included your first and last name, address, business email address, date of birth, Social Security number, and other account information."
In other words, almost everything a fraudster needs to attempt identity fraud – a likely outcome of this event as the term "deferred compensation plan" describes private pensions, retirement savings plans, and awards of stock options.
The term can also describe payouts under life insurance policies, which The Register mentions as IMS [11]bills itself as "the center of excellence for Infosys's Life Insurance software solutions and services offerings in the US."
[12]
The Register has asked Infosys to explain the incident. We've not received a response at the time of publication.
But we note that on November 4, 2023, an [13]allegation emerged that the notorious LockBit ransomware-as-a-service gang was behind the incident at IMS.
Ransomware certainly fits the description of the incident.
[14]
Victims have been offered the usual advice – change passwords, watch your accounts for stuff you didn't do – and the customary two years of free identity theft protection services from Experian. ®
Get our [15]Tech Resources
[1] https://www.sec.gov/Archives/edgar/data/1067491/000106749123000059/exv99w01.htm
[2] https://apps.web.maine.gov/online/aeviewer/ME/40/c2da936e-14f0-421a-833e-a24cbdd79cfa.shtml
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZctL2Rh0vpRzNWX4mDRi@gAAAUM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZctL2Rh0vpRzNWX4mDRi@gAAAUM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZctL2Rh0vpRzNWX4mDRi@gAAAUM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://apps.web.maine.gov/online/aeviewer/ME/40/c2da936e-14f0-421a-833e-a24cbdd79cfa/58970c93-7322-4f85-ac74-e2715d066d79/document.html
[7] https://www.theregister.com/2024/01/18/hcl_infosys_tcs_wipro_results/
[8] https://www.theregister.com/2024/01/15/narayana_murthy_long_work_comments/
[9] https://www.theregister.com/2024/01/17/leopard_infosys_tcs_india/
[10] https://www.theregister.com/2023/11/08/wipro_office_return/
[11] https://www.infosysbpm.com/mccamish/about.html
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZctL2Rh0vpRzNWX4mDRi@gAAAUM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://twitter.com/DarkWebInformer/status/1720868655037120602
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZctL2Rh0vpRzNWX4mDRi@gAAAUM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
Re: System approach is necessary
In a former life at a bank, there were considerable safeguards and logs on any account data access. An employee searching for notable clients without reason would rightly be pulled.
Dependency
It's so great to know that Infosys doesn't work on any critical infrastructure in the UK. Oh wait...
System approach is necessary
Private details should be centralized in a few highly guarded places, split by content type if necessary, and accessed on demand with logs and immediate notifications to data owners for any access. Users could allow or block access requests through their smartphones, as the devices have already become keys to everything.
Otherwise only the regulatory and legal bureaucracy bubbles are blown. Also spreading security workforce into managing distributed risks is less productive than concentrating it in a few highly specialized places.