Skip the navigation
News

Geeks.com agrees to security audits in wake of data breach

Tech retailer to undergo third-party audits every other year, as part of settlement with FTC

By Grant Gross
February 6, 2009 12:00 PM ET

IDG News Service - The operator of the Geeks.com Web site will submit to five outside security audits over the next 10 years as part of a data-breach settlement deal with the Federal Trade Commission, which found that the online retailer had failed to adequately protect its customer data prior to the breach.

Geeks.com, which sells computer supplies and consumer electronics, disclosed the data breach in January 2008 after discovering it the month before. The retailer, which is formally known as Genica Corp., said that the compromised information included the names, street and e-mail addresses, telephone numbers and credit card numbers of affected customers.

The breach was notable because the Geeks.com site prominently displayed a "Hacker Safe" seal provided to companies by McAfee Inc. as part of its ScanAlert vulnerability scanning service. However, McAfee officials said at the time that the Hacker Safe certification — since renamed McAfee Secure — had been withdrawn from Geeks.com on multiple occasions during 2007 after scans found vulnerabilities in its systems.

According to a complaint filed by the FTC, Geeks.com routinely stored sensitive customer data in unencrypted form on its systems prior to discovering the breach. The retailer also didn't "adequately assess" whether its Web applications and network were vulnerable to commonly known and foreseeable hacking attempts, including SQL injection attacks, the FTC said.

Nor did Geeks.com implement "simple, readily available" and inexpensive defenses to thwart such attacks, the commission claimed. The FTC's complaint alleged that the shortcoming enabled hackers to repeatedly exploit the vulnerabilities in Geeks.com's systems from January to June 2007.

In addition, the retailer violated federal law by falsely stating that it had taken appropriate measures to protect personal data, the FTC said. Geeks.com's privacy policy states: "We use secure technology, privacy protection controls and restrictions on employee access in order to safeguard your information."

The settlement with the FTC, announced Thursday, bars Geeks.com from making deceptive privacy and data security claims and requires it to implement and maintain a comprehensive information security program. The deal also requires the company to undergo a third-party audit every other year for the next 10 years in order to ensure that the internal security program meets the standards spelled out in the settlement.

Peter Green, Genica's marketing manager, said the company has worked closely with state and federal law enforcement officials and with computer forensics experts to try to find out who was responsible for the breach and to fix any security problems in its systems. "We have taken this breach very seriously," he said.

Reprinted with permission from IDG.net. Story copyright 2010 International Data Group. All rights reserved.
Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Malware and Vulnerabilities White Papers
Reducing the Cost and Complexity of Web Vulnerability Management
Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.

Download this...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
All Malware and Vulnerabilities White Papers
Malware and Vulnerabilities Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Malware and Vulnerabilities Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs