Computer forensics firm's database hacked
The credit card numbers of 3,800 Guidance Software people were exposed
Computerworld - The customer database of computer forensics firm Guidance Software Inc., a provider of software that diagnoses computer break-ins, has been hacked.
The Pasadena, Calif. company said in a Dec. 13 letter to its customers that the breached database contained credit card numbers of 3,800 people. The database also contained the expiration dates and card verification numbers of those credit cards as well the names, addresses and telephone numbers of the customers, according to the letter from Guidance CEO John Colbert. The database did not contain any customer financial data that could put them at risk of identify theft, he said.
"Guidance is taking this matter very seriously," Colbert said in the letter. "Upon learning of the incident on December 7, we have been working quickly to investigate the unauthorized network activity and remediate the person's method of access. The next day (December 8) we referred this incident to the U.S. Secret Service, who have begun their own investigation. Of course, our investigation is ongoing, and we will continue to cooperate fully with law enforcement in its investigation as well. To prevent any further unauthorized access of your personal information, we have also deleted all of your credit card information from our customer database."
The letter from Colbert was provided to Computerworld by Michael Kessler, president of Kessler International, a New York-based computer forensics investigation company. A Guidance spokeswoman confirmed the information contained in the letter, but declined to comment further because of the ongoing investigation.
Guidance also said it is confident, based on an immediate forensic analysis, that the intrusion was effectively terminated and its network secured. In addition, the company said it is reviewing its operations and redoubling efforts to ensure that customer information is secure.
"Our office's credit card [information] was stolen and one individual in particular had over $20,000 put on their corporate card for pay-per-click advertising at Google," Kessler said.
Four people in Kessler's office received letters from Guidance saying credit card information had been stolen, letters they got after they had already received their American Express bills.
"I got the letter Monday, Dec. 19 but Friday, [Dec. 16], I got the American Express bill and cancelled the cards. We were all scratching our heads trying to figure out how we could have had someone get our American Express Cards and we couldn't figure it out. And then Monday we got the [Guidance] letter, which they claim was sent Dec. 13. But they said they discovered [the breach] on Dec. 7.
"My question is


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Capture-Enabled Business Process Management
- Organizations today must deal with a vast amount of incoming information from many different sources. Efficient, automated business processes are critical to managing...
- Using Case Management to Empower Employees and transform Customer Service
- This Kofax paper shows how successful customer service organizations have transformed customer service by empowering their employees. We will see how Dynamic Case...
- Case Study: Audi-Volkswagen Improves Procurement Control
- Audi-Volkswagen required a user-friendly, easy-to-use Business Process Management system that did not require programming skills or high levels of technical expertise in-house. This...
- AIIM Market Intelligence: The paper-free office, dream or reality?
- In this Aiim Market Intelligence report, produced in association with Kofax, we look at the success of paper-elimination projects, where and why paper...
- Information Governance: Turning Data Into Business
- This whitepaper explores current information governance practices, challenges, and ROI among US, UK, and German firms. All BI and Analytics White Papers
- Live Webcast
How to Reduce Complexity and Automate Your Partners for Efficient E-Business: - Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - BMC Control-M - Single Point of Control Demo
- With BMC Control-M, you schedule and manage everything - down to the very last platform and application - from one simple interface. It's...
- Sun Chemical Customer Success Story
- Sun Chemical, the world's largest producer of printing inks and pigments, quadrupled its complex batch environment with zero extra headcount using BMC Control-M's...
- Service-Enabling CICS Applications: Best Practices
- This informative webcast provides an informed, thorough look into CICS service-enablement options and how they can affect your environment. You'll learn how to...
- Teaching Legacy Application Elephants How to Dance
- This four-minute video podcast shows how you can create services to continuously reuse enterprise applications, however and whenever needed, while leaving legacy logic...
- Verastream Host Integrator
- This six-minute product demo shows how you can use Verastream Host Integrator to modernize and service-enable legacy assets for use across your enterprise.... All BI and Analytics Webcasts