Wednesday, May 14, 2008

Report: C-level execs more involved with security

The major data breaches that have received mass media coverage are driving so-called "C-level" executives to become actively involved in their organization's security policies, according to a new report from the (ISC)2.

There are several key "take-aways" from the report, titled "2008 (ISC)2 Global Information Security Workforce" and authored by Rob Ayoub, Frost & Sullivan's network security industry manager.

Ayoub told SCMagazineUS.com that these include the fact that C-level executives are paying attention to security...

"CEOs are asking their security professionals important questions about how they're prepared to not become another TJX," (answers) (more)

Labels: , , , , , , ,

SpyCam Story #446 - The Diogenes Dilemma

NY - Matt Walsh finally had his day in front of the NFL, and as far as commissioner Roger Goodell is concerned, this chapter of the Patriots videotaping saga is closed.

Walsh, a former Patriots video assistant who last week turned over eight tapes showing the team recording opposing offensive and defensive signals, met for more than three hours with Goodell yesterday. In the commissioner’s view, he offered no new information worth reopening the league’s investigation into the Patriots’ videotaping practices.

Goodell said Walsh told him there was no tape of the Rams walkthrough prior to Super Bowl XXXVI. He said Walsh was unaware of any other violations of league policy, including the bugging of locker rooms, manipulation of communications equipment, or miking of players to pick up opposing signals...

He also told the commissioner that he had helped a small number of players scalp between eight and 12 Super Bowl tickets. (more)

Labels: , , , , ,

Sunday, May 11, 2008

"Watch the donut, not the hole."

NY - Police arrested a Kings Park Dunkin' Donuts employee at 10:26 pm last Thursday for allegedly setting up an illegal surveillance camera in the shop's women's bathroom.

Danish Qureshi, 25, of Huntington Station, an employee of the Dunkin' Donuts at 101 Pulaski Road in Kings Park, allegedly installed a wireless pinhole surveillance camera in the women's bathroom, according to police. Qureshi was using his wireless laptop computer to observe occupants of the bathroom while he was sitting in his nearby vehicle, police claim.

An area resident who owns similar surveillance equipment called police after he intercepted the signal and observed the bathroom on his television, Suffolk police reported. (more)

Labels: , , , , , ,

Friday, May 9, 2008

Corporate Spies Killing The CIA

The CIA is having a growing problem with their analysts and spies being recruited away by corporations. One unpleasant, for government intelligence agencies, development of the last few decades has been the growing popularity of "competitive intelligence" (corporate espionage.) It's a really big business, with most large (over a billion dollars of annual sales) corporations having separate intelligence operations. Spending on corporate intel work is over $5 billion a year, and is expected to more than double in the next four years.

The corporate recruiters have a pretty easy time of it, as they can offer higher pay, better working conditions and bonuses. (more)

Labels: , , , ,

Tuesday, May 6, 2008

SpyCam Story #445 - More Workplace Voyeurism

Australia - Federal police (AFP) are investigating how women at SBS' headquarters in Sydney were filmed in a changing room two years ago.

The AFP told SBS management about two weeks ago they had found photos of three women on the home computer of a man who works there. It is alleged the photos were taken by a camera installed in the room in 2006.

SBS managing director Shaun Brown says the suspect has been suspended from his job.

"Clearly the AFP had in their possessions the photograph," he said.

"They obviously had the identity of the suspect, they knew where the suspect worked and they appeared to put two and two together and concluded that the offence took place on these premises." (more)
So, why did it take 2-years for the staff to be informed?

Labels: , , , ,

SpyCam Story #444 - Workplace Voyeurism

Employer Video Monitoring of Bathrooms and Locker Rooms
by The National Workrights Institute
"Electronic monitoring is a rapidly growing phenomenon in American businesses. By recent estimates, 92% of employers were conducting some form of workplace monitoring. This rapid growth in monitoring has virtually destroyed any sense of privacy as we know it in the American workplace. As technology has proliferated in the workplace, it has become ever more penetrating and intrusive... Most invasive of all is video monitoring. Some cameras are appropriate. Security cameras in stairwells and parking garages make us all safer without intruding on privacy. But employers often install cameras in areas that are completely indefensible. Many employers have installed hidden video cameras in locker rooms and bathrooms, sometimes inside the stalls..." (more, with examples)

Labels: , , , ,

Who's Watching You at Work?

"Surveillance is now routine business practice among American employers, both large and small, as the cost and ease of introducing have dropped. You leave your rights at the office door every day you go to work. Most surveillance is conducted without any individualized suspicion, and personal as well as business-related information is routinely collected," explained Jeremy Gruber, legal director at the National Workrights Institute.

Two-thirds of the companies included in the "2007 Electronic Monitoring & Surveillance Survey" said they monitor Internet connections. (more)

Labels: , , , , , , , ,

Thursday, May 1, 2008

Porsche CEO Eavesdropping Case (update)

The well-respected Strafor (a private strategic intelligence analysis service) today characterized the eavesdropping of Porsche CEO, Wendelin Wiedeking, this way...
"The aggressor’s tactics were amateur."


Given the target – Mr. Wiedeking – and business climate around Porsche, it is unlikely amateurs would be involved. This is a high-stakes assignment. Professionals only.

Think like a professional eavesdropper. "I know they are going to look. I'll plant something they can find fairly easily; a trophy for the sweepers, a little confusing, with no clear culprit, amateurish, but plausible.

Result...
Triumphant, the TSCM team waves their 'find' and goes for a beer.
The real bugs/taps are planted deeper – much deeper.


But wait... This half-baked story should never have hit the press. Something smells.

Porsche went from 0 to 60 in filing their police complaint.

Normally, corporate eavesdropping finds are kept quiet and investigated further. When enough evidence is gathered to actually prove something, the police might be called. Publicity undermines stockholder confidence.

Amateur? Yes. But, is it the eavesdropper who should wear that moniker? If what appeared in the press is really the truth, characterize the handling of the case as amateur.


Other possibilities...
• Porsche planted the eavesdropping device themselves. A PR stunt – thinking it would somehow enhance their business bargaining position.

• The baby monitor bug was planted by the TSCM technicians to make themselves look good. (When a TSCM team presents evidence of bugs they should also volunteer for polygraph testing. My guess is they won't.)

The rest of Strafor's Porsche bugging analysis is accurate...
"The use of a security contractor to employ technical security countermeasures (TSCMs)* was not only a smart move by Wiederking in 2007 (a previous eavesdropping problem), but a wise decision for other players in today’s corporate environment. Industrial espionage is a common occurrence in the modern business world."

Espionage is foreseeable.
When was the last time you checked for bugs? ~Kevin
* This should read, "technical surveillance countermeasures (TSCM)"

Labels: , , ,

Wednesday, April 30, 2008

The Headline Evil Word You Can Prevent

April 22, 2008 - "Sanford Hospital tightens security after baby taken"

The good news...
The child was rescued a short time later by a police officer who stopped a Chevy Blazer on Interstate 4 (more)

The bad news...
Most corporations are hedging their bets that the word "after" will not appear in a headline about their security efforts.

In the corporate world, stealing intellectual property is the real-life equivalent of a baby – the corporation's baby. The baby who is to be nurtured into the company's future.

Now is the time to tighten security;
• while it is inexpensive to do,
• while your stockholder good-will is high,
• while you still have a job.

1. Work with your Legal Department to upgrade and keep current: non-disclosure agreements, non-compete contracts, and pro-active programs to detect and deter eavesdropping and espionage.

2. Work with your IT department on: password protection, encryption, wireless LAN security audit and compliance surveys, and employee education.

3. Keep current with intellectual property threats.
Read the news.
Offer the boss proof!
You need funding to prevent eavesdropping and espionage problems.

P.S. Problems do happen...
Recent Problem #1
Recent Problem #2
Recent Problem #3
Recent Problem #4
Recent Problem #5
Recent Problem #6
Recent Problem #7
Recent Problem #8
Recent Problem #9
Recent Problem #10
And all this was just April's news!

Is it any wonder that this Hot Boardroom Topic was also in April's news?
~Kevin

Labels: , , , , , , , , ,

Tuesday, April 29, 2008

"...thus proving they could keep a secret, for decades."

Japan - The Ministry of Internal Affairs and Communications' regional information policy office has decided to warn local governments about using analog cordless phones after it was learned that people could listen in on calls with commercially available receivers. (more)

Labels: , , , , , , , ,

Industrial Espionage - Battle Bot Boy Bolts

Who Stole the Plans for iRobot's Battle Bots?

Jameel Ahed was 20 years old when he joined iRobot in May 1999, a biomedical engineering student at the University of Illinois on a summer internship. In those days, the company was just 80 or so geeks in the Boston exurbs designing toys for Hasbro and doing research for Darpa. Ahed stood out. He was hardworking, flirtatious, and outgoing...

In December 2001, he bought the domain name roboticfx.com, planning to launch his own startup...

Before he left, a company staffer demanded that he sign a final confidentiality agreement. Ahed complained but signed. The next day, an email was sent at 10:18 pm from his still-active iRobot account to his new Robotic FX address detailing how the PackBot's batteries were made. Shortly thereafter, Ahed packed up and returned to Chicago...

By 2004, Ahed had a bare-bones prototype he called the Negotiator. It weighed just 20 pounds and cost less than $30,000 — half what iRobot was charging for a comparable early version of the PackBot...

...the Army announced its biggest ground robot contract ever. The so-called xBot deal would be worth up to $300 million and cover as many as 3,000 units...

In February 2007, iRobot's lawyers sent a cease-and-desist letter to Ahed, demanding that he stop making and marketing the Negotiator...

On September 14, 2007, the Army awarded the five-year xBot contract to Ahed for $279.9 million. iRobot went into battle mode.
(more) (coda)

Lessons:
• Keep all confidentiality / nondisclosure agreements current.
• Create an environment which discourages intellectual theft.
• Don't delay. If you suspect something is wrong, trust your instincts.
• Implementing a defense after loosing a $279m contract is expensive.
• Implementing a defense at the outset is cheap insurance.

Labels: , , , , ,

Saturday, April 26, 2008

Eavesdropping Attempt Made on Porsche Chief

German police have launched a probe after an attempt was made to eavesdrop on Porsche boss Wendelin Wiedeking while he was staying in a luxury hotel.

Security staff from the the Ritz-Carlton hotel in Wolfsburg found a "babyphone" concealed under a sofa in his room, the media reports said, which had been turned on and was transmitting.

Porsche has filed a complaint with the prosecutors' office in Braunschweig, a company spokesperson told the AP news agency on Saturday, April 26.

The news magazines Der Spiegel and Focus said an investigation (a different investigation) is underway after a monitoring device was found in Wiedeking's room at the Ritz-Carlton in Wolfsburg in November. The reports said there was suspicion that the spying attempt took place one day before a meeting on Nov. 16.


Left behind?

The online news site Spiegel Online has reported that hotel security ruled out that a family with a child could have stayed in the s
uite previously and simply forgotten the device. For several weeks, there was no record of a family having spent an evening in the room.

Porsche told AP that other company officials had also been spied upon, including works council head Uwe Hueck, but did not supply any details. Focus has reported that his telephone conversations at Porsche headquarters in Stuttgart were allegedly wiretapped. It is not known who was behind the action but the company has reportedly notified prosecutors.

Porsche owns 31 percent of shares in Volkswagen, the biggest European automobile manufacturer, and wants to take full control of the firm.
Volkswagen has denied any role in espionage, Focus reported. (more)

Update...
Focus reports that the offices of Porsche workers’ organization head Uwe Hück are to be made bug proof after it was discovered that his phone was being tapped. And Der Spiegel says that a bug was found planted in the private flat of former VW chief Wolfgang Bernhard. (more)

Labels: , , , , ,

16 Extra Eyes in the Florida Eye Institute

SpyCam Story #441
The mysterious tale of 16 SpyCams, 16 Microphones, and a recorder!


FL - A 45-year-old Vero Beach woman has been arrested on eight felony charges that allege illegal electronic eavesdropping on doctors, copying hard drives from their computers and the theft of a laptop.

But the seven-page complaint filed by the State Attorney's Office against Brenda Doan-Johnson, of the 3400 block of Atlantic Boulevard, does not explain why she supposedly paid a Melbourne man to place cameras and microphones in the private offices of three doctors at the Florida Eye Institute in Vero Beach.

Both a Jan. 24 Vero Beach Police report and a Jan. 28 civil lawsuit filed by three of Dr. Paul V. Minotty's business partners, say Minotty, founder of the institute, had hired a private investigator and the police report identified her as Doan-Johnson.

According to the state attorney's complaint affidavit, Doan-Johnson paid Mark Lynch, of Spy Source Warehouse in Melbourne, with a $6,000 personal check as deposit on $13,000 to install 16 video cameras, 16 microphones and a digital recorder at various places in the Florida Eye Institute — including the offices of doctors Karen Todd, Mark Gambee and Val Zudan.

Lynch worked after business hours for six days, starting Jan. 11, to install the equipment, the affidavit states, noting that audio recording apparently did not function.

Investigators reported that Doan-Johnson introduced Lynch to two other people who also were working in the building, identifying them as computer forensic specialists who were copying the hard drives from the desk computers of doctors Gambee, Todd, Zudan and Thomas Baudo.

According to investigators, Lynch phoned Gambee (!?!?!) Jan. 24 and told him about installing the electronics in Florida Eye Institute offices — including Gambee's office. The Vero Beach police were called to Florida Eye Institute the same day.

Gambee told Vero Beach officers his computer was missing. Doan-Johnson returned it, saying it was thought to be company property... (more) ...and, more to come as this case unfolds.

Labels: , , , , , , ,

Thursday, April 24, 2008

Corporate Security Directors. Make your job easier.

Get your employees to love you.
Distribute this new book...
"Staying Safe Abroad."


Ed Lee, a retired U.S. diplomat and
Federal agent, spent most of his years in the U.S. State Department as a Regional Security Officer (RSO) in Asia, Latin America and the Middle East, where he successfully kept diplomats, their families and U.S. interests safe from terrorism and crime.

In 2002, Ed
returned to the State Department as a senior advisor to help institute post-9/11 anti-terrorism strategies, retiring again in 2006. He then formed Sleeping Bear Risk Solutions, which provides investigative, emergency planning and staff security services. He also regularly delivers speeches on terrorism and international security to corporate and governmental audiences. (ISBN: 978-0-9815605-0-2, 360 Pages, $22.95)

Staying Safe Abroad: Traveling, Working & Living in a Post-9/11 World "is the best book yet on travel security. This book is one that should be read and kept in every traveler’s briefcase for reference.” — John L. Makowski, Director - Global Security, Briggs & Stratton Corporation

"Every person who travels, whether abroad or domestically, should own this book." — Martha Miller, Ph.D., Cross Cultural Trainer to U.S. Diplomats and Multinational Executives

P.S. - Employees... A free copy of this should accompany the plane ticket whenever your employer sends you abroad. Ask your Security / Personnel / Travel Department Director for a copy. It's the least they could do for you. If all else fails, buy it yourself.

If you are my client, I'll buy it for you!
Contact me for a
free copy. ~Kevin

Labels: , , , , , ,

Wednesday, April 23, 2008

Cautionary Tale: Prevention = Cost-Effective

Hannaford spending millions to upgrade after security breach.
Background...
Yet Another Corporate Info-Loss Confession
"But, IT said our data was secure."

Hannaford Bros. Co. said it is spending millions of dollars to enhance the security of its data network following a massive security breach that exposed up to 4.2 million credit and debit card numbers to fraud...

Hannaford President and CEO Ron Hodge apologized again Tuesday to customers for concerns and inconvenience they experienced because of the breach...

In a conference call with reporters, Hodge and Bill Homa, senior vice president and chief information officer, declined to address the cause, scope and nature of the breach, citing the ongoing criminal investigation and pending litigation.

The Hannaford case is among the largest security breaches on record but is much smaller than the tens of millions of credit cards that were exposed at TJX Cos. of Framingham, Mass., which has 2,500 stores and includes the T.J. Maxx and Marshalls chains. (more)

The "millions" figure is likely just a system fix number. The final cost, which will include: public embarrassment, loss of customer good-will and
customer ill-will lawsuit losses, can not be tallied just yet.

Recommendation:
Be smart.
Be frugal.
Be a corporate hero.
Spend the bucks to protect your company's communications privacy (voice and data)
. There is a good chance you will save money in the long run... a lot of money! ~Kevin

Labels: , , , , , , ,

Tuesday, April 22, 2008

Putting the squeeze on Blackberry to get the juice

Talks between Indian officials and Canada's Research In Motion (RIM, the BlackBerry Bunch) would seem not to have gone very smoothly...

The backstory here is that the top brass at India's burgeoning and powerful state security services are concerned that Blackberry's advanced communications technology cannot be breached by their operatives and thus the "authorities" are currently unable to eavesdrop Blackberry users.

They have asked RIM to provide them with the capability to conduct covert surveillance on Blackberry users by requiring the company to install local servers and provide secret back door access to services, but the Canadian vendor has so far refused to comply. (more)

Labels: , , , , , ,

Get the PR team some O2, stat!

UK - O2’s PR team mistakenly connected a journalist of tech website The Register to a call earlier this month, allowing him to eavesdrop on their conversation about his news enquiry.

Turns out, O2 (a UK cellular service provider) reckons The Register’s readers are “techie nerds” and “Muppets” for wanting to move to 3. O2 duly apologised on the website, and said to Mobile News: “Hey, we’re techie nerds ourselves.” (more)

Labels: , , ,

Thursday, April 17, 2008

Corporate Espionage - Contractor Pleads Guilty

A U.S. Department of Defense (DOD) contractor from Baltimore pleaded guilty today to conspiring to steal competitive information concerning contracts to supply fuel to DOD aircraft at locations worldwide, the Department of Justice announced.

Matthew W. Bittenbender has entered into a plea agreement, filed in U.S. District Court in Baltimore, where he was originally charged on January 7, 2008. According to the terms of the plea agreement, which is subject to court approval, Bittenbender has agreed to cooperate in the government's investigation...

...Bittenbender conspired to steal trade secrets from his employer Avcard, a division of Kropp Holdings LLC, and sell that information to his competitors, FERAS, and Aerocontrol. In return, Bittenbender received cash and a percentage of the profit earned on the resulting fuel supply contracts. According to the plea agreement, Cartwright, Wilkinson, FERAS and Aerocontrol, in turn, used that information to underbid Avcard at every location where the companies were bidding against each other. Avcard ultimately lost each of the contested bids. (more)

Labels: , ,

Wednesday, April 16, 2008

"...and she went to the hospital to have it removed! Blahaaaaaa..."

Australia - Attorney-General Robert McClelland says the proposal to let some employers access workers' emails without consent is only being considered as a way to stop cyber terrorist attacks.

He says it would not be targeted at personal communications.

"What you would be looking and permitting access to is information that would reveal an attempted infiltration," he said.

But deputy Opposition leader Julie Bishop says...
"Employers should not be burdened with the responsibility of intercepting emails involving staff suspected of behaviour that threatens Australia's national security."

"This places an unfair surveillance responsibility upon employers and effectively requires them to undertake what is a potential criminal investigation." (more)

Seriously bad idea...
- Pay IT guy to do a government intelligence agents' work?
- Pay twice!?!? Salary for IT guy and (via taxes)
government intelligence agents'.
- Conflict of interest? Employees spying on friends and colleagues?
- Entrust national security to an army of untrained private employees...
- ...whose work product might equal less than educated guesswork?
- ...who may be tempted to use the snoop power for personal gain?
- Not to mention: loss of regular business productivity, opening new avenues of corporate espionage, data vulnerabilities, etc.
Outsourcing your job responsibilities should not be an option; especially when you have been entrusted with national security.

Labels: , , , , , , ,

Tuesday, April 15, 2008

Data Land Mines

1. A slip of the finger reveals the company secret.
- Turn off that auto-fill feature.
2. People give away passwords and other secrets without thinking.
- Engage brain. Shut mouth.
3. A trusted partner ends up not being so trustworthy with your data.
- Share sparingly.
4. Web-based apps can be portals to leaks and thieves.
- VPN it instead.
5. Hoping the worse doesn’t happen only makes it worse.
- Plan for disasters.
6. Avoiding or diluting response leadership makes breaches worse.
- Designate a buck-stopper.
7. Handling breach details sloppily tips off the perp.
- Practice 'need-to-know'.
8. Trusting "silver bullet" technology hides real threats.
- There ain't no Lone Ranger.
9. Spending unthinkingly wastes resources you might need for important threats.
- Gauge threats.
10. Don't save the wrong data.
- Only store what you need.
(more)

Labels: , , , , , ,

Saturday, April 12, 2008

SpyCam Story #440 - The Dentist

TX - An Ennis dentist accused of videotaping his female employees in their changing room with a hidden camera pleaded guilty...

The employees went to authorities in August after finding a video camera in a room where they changed into and out of medical scrubs at Durbin's dental office. According to an affidavit, the women confronted Durbin, who admitted making video recordings.


Stephen C. Durbin, also a city commissioner in Ennis, got five years of community supervision with deferred adjudication in the plea agreement on a state jail felony charge of improper photography or video recording. (more)
"She said my boy I think someday
You'll find a way
To make your nat-u-ral tendencies pay!
Yooou'llll be a Den-tist!"


Labels: , , , ,

Thursday, April 10, 2008

Blackemail, Espionage or Just Coincidence?

MA - Two staff members in the school superintendent’s office spied on e-mails sent to Cambridge School Committee members over the span of one month. (more)

...administration officials did not tell the School Committee they were receiving committee e-mails from parents and others. A School Committee member only found out the two school officials were copied into School Committee e-mails after they hit “reply all” and found the duo copied in the e-mail. 14 days after it was discovered, School Committee members voted to enter contract negotiations with Superintendent Thomas Fowler-Finn. (more)

Labels: , , , , , , ,

News Flash? "Covert video surveillance becomes widespread in Russian offices"

from Pravda...
"Most of you work in companies equipped with video surveillance systems. As it turns out, video surveillance affects employee’s work more significantly than other control methods (wiretapping, looking through emails and reading the most frequently visited websites)." (more)

Labels: , , , ,

"Pick-up in aisle Ten."

Supermarket chain Lidl has apologised to staff after being accused of systematically spying on them.

It took out of series of newspaper adverts in Germany saying: "We regret it profoundly and apologise explicitly if co-workers feel discredited and personally hurt by the described procedures."

Earlier German magazine Stern reported that Lidl had hired detectives who installed surveillance cameras to monitor the staff's work performance, and even to find out how often they used the toilets and whether they had affairs with co-workers. (more)

But wait! There's more!
Germany was shocked to learn that Stasi-like techniques were used to spy on employees of supermarket giant Lidl. Now a report has emerged showing that the chains Plus and Edeka may have done the same... (more)

And, more!
BT has admitted that it secretly monitored customers' internet surfing activities in trials of new software in 2006 and 2007. (more)

Labels: , , , ,

Tuesday, April 8, 2008

"What's in your IT department?"

by Naomi Grossman, bmighty.com
Caught up in the high profile case of Anthony Pellicano -- the detective on trial for racketeering and wiretapping in a case that involves lots of big names in Hollywood -- is the manager of IT security for Conde Nast publications. How exactly did that guy get his job?...


On Gawker, Ryan Tate asks the second most obvious question: "The guy who runs tech security for Condé Nast has admitted lying to the FBI and lending his services to private detective Anthony Pellicano even though he knew Pellicano was tapping people's phones. He's also been accused, in the course of Pellicano's racketeering and wiretap trial, of leaking a pre-publication copy of Vanity Fair that Pellicano mysteriously obtained, and of bragging about bugging the office of his Condé Nast supervisor. So why does he still have a job?"...

...the lessons here go beyond the need to move decisively in hiring and firing. If Reynolds could do that stuff in a huge company like Conde Nast, imagine the damage your IT guy could do in your smaller business -- where there aren't the same resources to weather a disaster. Put the time and effort into checking your IT guys out. Each one could mean the difference between life and death for your company. (more)
Well said!
You've been warned.

Labels: , , , , , , , ,

Monday, April 7, 2008

India Wants to Eavesdrop on BlackBerrys

BlackBerry users, beware of the snoops. India's Telecommunications Dept. told telecom carriers, Internet service providers, and officials at Research In Motion (RIM), the Canadian company that makes BlackBerrys, that it wants to eavesdrop on transmissions from every BlackBerry phone in the country. To comply, RIM might have to route calls and e-mails through government computer servers based in India. (more)
FutureWatch... Look for other countries to jump on this bandwagon.

Labels: , , , , , , , ,

Hot Boardroom Topic - Counterespionage

Security is becoming a board-level issue as the number of cyber-attacks and corporate espionage incidents are growing significantly each year...

Few people would dispute the mystique that surrounds the boardroom. This allure has been around for some time, but it was recently heightened by the popular TV series "The Apprentice" with business icon Donald Trump. Boards of directors deal with sensitive issues and handle privileged information, and board meetings themselves call to mind strategy discussion, stock discussions and major contracts.

Taking advantaged of privileged information is illegal. As you can imagine, access to privileged financial and stock information could easily be used for insider trading. The sensitive information and financial data must be controlled in order to comply with Securities and Exchange Commission disclosure requirements.

What you may not think of are the discussions around information security, which has become a board-level issue. Cyber-attacks and corporate espionage are growing significantly year-over-year. In a training program developed by Spy-Ops, the company notes that corporate espionage worldwide is now more than a trillion-dollar problem annually and growing. Data breaches, theft of intellectual property, insider trading and other criminal acts now demand the attention of the board of directors.

"Enterprise risk management discussions and strategies have moved into the executive suites and boardrooms. This is due primarily to the significant implications associated with security breaches," said Paula Cordaro of Spy-Ops.
(more)

Labels: , , ,

Sunday, April 6, 2008

Price Drop!!! GSM Bugs now on sale - $35.00

Alert - The hottest new bugging devices are now among the least expensive. GSM SIM bugs are like cell phones, but without the keypad. Eavesdroppers call and listen from anywhere in the world.

At one time these devices sold for $250.-$500. The price has plummeted to $35.-$55. Why? The same reason their sister product (the cell phone) is often a give-away item... Economy of scale; thus proving consumer demand is fueling mass production.

Corporate Concern...
At these prices, "salting" offices with bugs becomes practical. Imagine... Buy in bulk and get custom silk screening - "Air Quality Monitor - Do Not Disturb." Even if accidentally seen, it might be accepted - "Every office has one of these."

Corporate Solution...
Periodic Eavesdropping Detection Audits are now an integral part of corporate security. Not having an eavesdropping detection program is negligence.

from a seller's web site...
"The GSM SIM Bugs are advanced audio surveillance devices. The SIM spy ear comes with compact design and embedded microphone system. This audio surveillance listening system no need software and no configuration required. Very easy to use. The only one thing you need to do is insert a pre-paid GSM SIM card into SIM card slot of the spy sim bug. Then you could hide it in an inconspicuous location and starts excellent listening surveillance." (more)

Labels: , , , , , , , , ,

Thursday, April 3, 2008

Spy Buster Locates Sophisticated Wireless Eavesdropping Devices

According to the Freedonia Group, a market research group in Cleveland, Ohio, companies spend over $95 billion annually on corporate security.


One of the fastest
growing areas for this spending is corporate espionage prevention.

Factors in this growth include everything
from globalization to decreased employee loyalty and the fact that the most valuable asset of a corporation these days is information, which can be easier to steal than a piece of machinery.

So what’s a worried executive or security professional to do?
Increasingly, companies and government agencies are turning to firms that specialize in detecting and removing eavesdropping and other surveillance devices... (more)

Labels: , , , , , , ,

Tuesday, April 1, 2008

Corporate Espionage Arrest - AMX Corp. V.P.

Short version: AMX Corporation's Vice President, David Goldenberg, was "arrested for allegedly participating in corporate espionage practices against a competing manufacturer's representative firm."

The following is from the Bergen County (NJ) Prosecutor's press release...
NJ - Bergen County Prosecutor John L. Molinelli announced the arrest of David A. Goldenberg, D.O.B. 05/18/1962, of 432 Golf Dr., Oceanside NY. Goldenberg was arrested on March 28, 2008, on charges of Unlawful Access of a Computer System / Network (2C:20-25b); Unlawful Access of Computer Data / Theft of Data (2C:20-25c); and Conducting an Illegal Wiretap (2A:156A-27)...


The arrest stemmed from an investigation concerning the following: The Paramus Police Department received a complaint from a Paramus based corporation known as Sapphire Marketing, who specializes in high-end audio/visual systems. Representatives of Sapphire reported that they were being suspiciously and consistently underbid for contracts by a competitor for whom David Goldenberg works. They expressed suspicion of corporate espionage. Based on anomalies that the complainant noticed within their computer network and more specifically their electronic mail (e-mail) system, they suspected that the company’s e-mail system had been compromised and that e-mail was being intercepted. The Paramus Police Department (a member of the Computer Crimes Task Force) and the Bergen County Prosecutor’s Office Computer Crimes Unit initiated an investigation.

The investigation revealed that Mr. Goldenberg had engineered the passwords protecting several of the complainant’s e-mail accounts. For a period of time,