Business

Gmail Hacking Epidemic

Gmail Hacking Epidemic

On April 1, 2011, the Dallas-based email marketing giant Epsilon disclosed that hackers had breached its systems and made off with customer names and email addresses belonging to a subset of its roughly 2,500 corporate clients. By the following week, more than 30 companies — Chase, Citigroup, Capital One, Best Buy, Walgreens, Marriott, TiVo, Disney, and others — had told their own customers that their details were in the stolen databases.

The stolen data was limited: names and email addresses only, not passwords, card numbers, or addresses. That should have been reassuring. It wasn't. A personalized phishing email that addresses you by name and arrives "from" your bank can bypass every spam filter and every ounce of skepticism that a generic scam would trigger. The Epsilon data was tailor-made for spear-phishing at industrial scale — potentially affecting tens of millions of people.

Senator Richard Blumenthal warned Connecticut residents to be "hyper-vigilant" about emails asking them to click links or attachments, and called on the Department of Justice to investigate. The Connecticut Better Business Bureau put the risk plainly: an "extremely high risk for phishing attacks."

The practical advice hasn't changed since. Your bank will never ask you to verify login information by email. Don't click links in unexpected messages, even from brands you recognize. And the deeper lesson of the Epsilon breach: your email address is no longer "just" an email address once it sits in a corporate database — it's an entry point, and its safety depends on companies you'll never do business with directly.

The epidemic wasn't accounts being hacked. It was trust being harvested.

Related Stories

Driverless Cars Now A Reality
Business

Driverless Cars Now A Reality

California's legislature passed SB 1298 in August 2012, legalizing Google's driverless-car tests on public roads — the first step toward autonomy.