Hackers Steal 19,000 Personal Customer Details from ATandT Online Store

Softarea51.com is your source for all the latest computer technology and software related press releases.
Browse our archive for more press releases!

Released on: 6, September 2006
, Author: Tamara Borg / Acunetix
, Audience: Software related

Recommended: System Errors? Click here to Fix your PC »


London, UK Â 06 September, 2006 Â Last weekend, hackerspilfered the personal data of nearly 19,000 DSL equipment customers through avulnerability in AT&TÂ's online store. The affected site was shut down within hoursof the attack being launched. In a statement, AT&T attributed the motive of theattack to a criminal market for illegally obtained personal information. In fact,the data also included customersÂ' credit card details.

To-date, AT&T has not provided details about how the site was hacked, however someunconfirmed reports attribute the website being vulnerable to Cross Site Scripting(XSS).

This attack did not come without cost to AT&T. The company notified each customerby e-mail and is now working with law enforcement officials to track down thehacker. AT&T committed to pay for credit monitoring services to protect thosecustomers purchasing Digital Subscriber Line (DSL) equipment online from possiblefraud.

Assessing the security of a website

Websites with web applications such as shopping carts, forms, login pages anddynamic content, in general, are always a prime target for attack. To functionfully, web applications require open and direct access to backend databases: ifimproperly coded, web applications become easy gateways to social security numbers,credit card details and even medical records. Hackers experiment heavily with a widevariety of techniques to lay their hands on this type of data since the pay-offs areenormous.

Acunetix WVS protects against these attacks including Cross Site Scripting and SQLInjection vulnerabilities. Furthermore, Acunetix protects against the embedding ofJavascript malware in a web-page through its JavaScript Analyzer. Such protectionsecures all AJAX applications.

An automated check of AT&TÂ's website (using Acunetix WVS) could have prevented thisattack and saved the company from denting its reputation and the subsequent loss ofcustomer trust.

Acunetix provides free audit to help companies determine the security of their websites

Enterprises who would like to have their website security checked can register for afree audit by visiting www.acunetix.com/security-audi t. Participating enterpriseswill receive a summary audit report showing whether their website is secure or not.Summary reports will be delivered within five business days of submission.

About Acunetix Web Vulnerability Scanner

Acunetix Web Vulnerability Scanner ensures website security by automaticallychecking for SQL injection, Cross site scripting and other vulnerabilities. Itchecks password strength on authentication pages and automatically audits shoppingcarts, forms, dynamic content and other web applications. As the scan is beingcompleted, the software produces detailed reports that pinpoint wherevulnerabilities exist.

About Acunetix

Acunetix was founded to combat the alarming rise in web attacks. Its flagshipproduct, Acunetix Web Vulnerability Scanner, is the result of several years ofdevelopment by a team of highly experienced security developers. Acunetix is aprivately held company with headquarters based in Europe (Malta), a US office inSeattle, Washington and an office in London, UK. For more information aboutAcunetix, visit: http://www.acunetix.com; http://www.acunetix.de.

All product and company names herein may be trademarks of their respective owners.

For more information:Please email Tamara Borg: tamara@acunetix.comAcunetix Ltd: Tel: (+44) 0845 6126712; Fax: (+44) 0845 6126716.URL: http://www.acunetix.com.


Source: Express-Press-Release.com
Related downloads


Chat server software provides a list of website visitors with full details likes his IP address, browsers, country, host name etc. Single operator live chat tool is based on AJAX technology and easily install without need of any plug-ins or DLL.

In Shop Lifter Pro free game your job is to steal as many valuable objects from the store without getting caught. Walk in the store and try to steal various items. Be careful of the clerk as it seems he has his eyes on you.

Symantec’s Norton Personal Firewall 2004 keeps hackers out and personal data in. It makes robust firewall protection easy by automatically hiding your PC on the Internet and blocking suspicious connections.

Powerful, easy to operate software system for storing and managing customer records, service locations and service history with the additional capability to share data in real time over the network.

Web Ecommerce solutions, shopping cart software, E-Commerce Web site design: Build a professional online store - Sell online and process orders in real-time at your own Web site - create both retail (B2C) and wholesale (B2B) online business at-once.

TermiNET program is an ideal security solution for SMEs (Small and Medium Enterprises) and home users who wish to connect to the Internet securely but do not have the resources to support a large security infrastructure.

VideoList is your complete movie, video, DVD, etc. organization software for Palm OS handhelds, Pocket PC or Windows Mobile handhelds, and Windows PCs! Keep track of VHS tapes, DVDs, home videos, etc. that you own, have seen, rented, etc.

ProtoPort Personal Firewall is powerful security utility that monitors all network traffic. Network packets are passed or blocked according to rules.

KF Whois makes it easy to look up and store domain registration details. It tracks changes to domain registrations and warns you when they are about to expire.

An online application developed to help people store data securely online. With this program, you safely store all your confidential information in one place while freely access them anytime from anywhere.
Softarea51.com RSS Feed

Get RSS updates on latest computer technology and software related press releases Subscribe to Latest Press Releases RSS feed    Subscribe



You are welcome to include these headlines in your own pages. If you want to find out how to parse this RSS file please read our tutorial How to parse RSS feeds with PHP.