Skip the navigation
)
News

FAQ: Epsilon email breach

Names and emails were exposed, but it could have been worse

April 5, 2011 05:15 PM ET

Computerworld - An email server breach at Epsilon Interactive exposed the names and email addresses of millions of people. The breach is being described as the worst of its kind.

Here's what you need to know:

What happened? Epsilon Interactive last Friday announced that unknown intruders had broken into one of its email servers and accessed the names and email accounts of some of its 2,500 corporate customers. Epsilon has not disclosed how many accounts in total were exposed in the breach. Some say it is the largest breach ever involving that kind of data, meaning that tens of millions of email addresses were likely compromised.

I've never heard of Epsilon. Why do they have my name and email address? Epsilon provides email and customer loyalty services to more than 2,500 corporations, including seven of the top 10 Fortune 100 companies. The company sends more than 40 billion emails annually on behalf of these clients. So even if you haven't heard of it before, chances are high that your bank or your favorite retailer or hotel chain is using Epsilon for email and other services. The company touts itself as the world's largest permission-based email marketing provider and is believed to store more than 250 million email addresses.

How did the breach happen? Epsilon has not divulged any details of the breach beyond saying that it was discovered on March 30.

If it's only names and email addresses that were exposed, why is everybody acting so concerned? The Epsilon breach, big as it is, could have been much worse. Right now, the biggest concern is that the stolen email addresses will be used by the intruders to launch sophisticated and highly targeted phishing attacks.

The stolen information will allow scammers to send authentic-looking email messages that appear to come from a bank or other business with whom the user has an existing relationship. The emails will try to trick people into parting with information such as their usernames and passwords for bank accounts or other online accounts, or they could try to trick people into downloading malware on to their systems. People who don't fall for such scams should be fine.

Will the stolen information allow the attackers to break into my bank account? No. Only email addresses and names were compromised, not login credentials.

I just received an email from my bank informing me about the breach. What steps do I need to take to protect myself? The first thing to do is relax. The stolen information by itself will not allow the intruders to break into any of your online accounts or to commit identity theft. The main thing to remember is not to respond to or follow links in any message that purports to come from your bank or another business asking you to update or validate your account information or to provide other personal details. Such links will take you to bogus websites set up to collect personal data or download malware to your system.

Don't respond to emails that threaten to close or suspend your account unless you provide certain personal information immediately. Never send your username and password in response to any email that asks for it, however authentic-looking the email might appear. Legitimate companies do not typically ask for such information in an email.

Should I change my email address? That probably would be the safest thing to do, but it can be a huge hassle. For the moment, the best option is to be extra vigilant in watching for phishing attempts.

What other information, besides names and email addresses, was compromised? So far, Epsilon has said that only names and email addresses were compromised in the breach. The company collects and sells a lot of other customer data, but it's not saying if any of that data was exposed.

Is there a complete list of all the companies affected by the breach? No. Epsilon has not released that yet. But blogger Brian Krebs has complied a (growing) list of the companies that have notified their customers about the breach so far. Close to 50 companies are on that list, including Best Buy, Citibank, Disney, JPMorgan Chase, The Home Shopping Network, Hilton, Marriott and the College Board.

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at Twitter @jaivijayan, or subscribe to Jaikumar's RSS feed Vijayan RSS. His e-mail address is jvijayan@computerworld.com.

Read more about Security in Computerworld's Security Topic Center.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Driving Secure Enterprise File Sharing and Syncing in the Enterprise
GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
The Enterprise File Sharing Option
Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
Security Strategies to Virtualizing Internet-Facing Applications
The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
Cloud Security Planning Guide
Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
Cloud Security Vendor Round Table
This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions...
All Security White Papers
Security Webcasts
Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
BlackBerry PlayBook OS 2.0 Security Overview
The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
BlackBerry NFC Security Overview
The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs