Ads by TechWords

See your link here
Receive the latest technology news and information.
Networking
Networking Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Trojan horse captured data on 2,300 Oregon taxpayers from infected gov't PC

The Trojan horse was in a pornographic file downloaded by a former state worker

June 15, 2006 12:00 PM ET

Computerworld -

The Oregon Department of Revenue has been contacting some 2,300 taxpayers this week to notify them that their names, addresses or Social Security numbers may have been stolen by a Trojan horse program downloaded accidentally by a former worker who was surfing pornographic sites while at work in January.

Rosemary Hardin, a spokeswoman for the Salem, Ore.-based agency, said the malware was discovered on the worker's desktop computer on May 15, after the worker was fired for violating departmental policies that forbid inappropriate Web surfing at work. The Trojan horse was found after IT workers investigated performance problems with the computer. The worker is not being identified by the agency.

An investigation by agency security personnel and the Oregon State Police found that the malicious program was designed to capture keystrokes on the former employee's computer, Hardin said. The employee was an entry-level worker who was assigned to entering taxpayer name and address changes, as well as some Social Security numbers. "We know that the information that the Trojan gathered up was transmitted outside of the agency" to an unrelated Web site. The incident is still under investigation.

Officials at the Department of Revenue don't know whether any of the transmitted information was ever received, she said. None of the information included income tax or banking information for the affected taxpayers.

The Trojan horse was apparently included in a video download or some other similar file saved on the computer by the former employee. "This individual was surfing pornographic sites and other inappropriate sites," she said. The department uses Web blocking software, but the former worker was apparently able to access a porn site that had not yet been blocked by the software, she said.

Internet usage is monitored on a random basis for all 1,000 of the agency's employees, Hardin said, but workers at that time were allowed to conduct personal Web business, such as checking their banking or personal e-mail accounts, during lunch and other breaks. Since the incident, however, workers are no longer permitted to conduct any personal business on agency computers while at work. "We've changed our policy for now to prohibit personal use because we want to minimize the risk of this ever happening again."

The Trojan horse was of such a new variety that the agency's antivirus software, which is updated every two hours for security reasons, had not yet been updated to protect against it, Hardin said. The agency reported the malware's strain to the antivirus vendors, who then updated their software.

There have been no reports of identity theft connected to the incident so far, though about 200 people have called with questions, according to Hardin. "People seem to be understanding," she said. "Nobody has reported any kind of suspicious activity."

All 2,300 affected taxpayers have been offered help in guarding against identity theft. The agency is looking into providing a year's worth of free credit monitoring services for each of the taxpayers and will soon contact them about how to sign up for that program, Hardin said. The department also set up a Web page listing frequently asked questions about the Trojan horse to provide more information.

"This has been very difficult for us," Hardin said. "Protecting the confidential information of our taxpayers is at the core of what we do."

Read more about it in government in Computerworld's IT in Government Knowledge Center.



Jump to comments

Trojan

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

White Papers & Webcasts

Enterprise 2.0 Applications - Block or Not?
Learn what your organization should do to control Enterprise 2.0 Applications.  

Product Overview Brochure
Learn how to deliver secure data and applications wherever and whenever they're needed.  

How to Secure and Accelerate Your Oracle Applications
Learn about the escalating application performance and security challenges facing corporations, today!  

The Workday User Experience Video
Watch Workday's Creative Director, Scott Lietzke, discuss the business-centered design philosophy at Workday.

Enterprise Application Delivery: No User Left Behind
Gain the ability to deliver applications to all users, using any device, across any network.  

Business Process Framework Demo
Learn about Configurable Business Processes and Calculated Fields. Watch Now!

Accelerate SSL Encrypted Applications
Gain complete visibility into SSL application sessions, making it easy to apply appropriate acceleration and security controls to all SSL traffic.  

Manager Experience Demo
Go beyond self-service solutions to perform more effectively. Watch Now.


IT Jobs