09.04.2010
FICORA's CERT-FI information security review 1/2010: Poorly-protected services prone to information leaks
In March, user information was stolen from the Älypää game site. As a result, more than 125,000 usernames, passwords and e-mail addresses were published on the internet, which compromised the information security of users registered with the service. Again in February, credit card information belonging to more than 100,000 holders was stolen from a hacked computer of a cafe in Helsinki.
There is an underlying challenge in the implementation of information-secure network services. The effects of a service without proper information security may be large-scale, because the user information can also be exploited elsewhere, for example in e-mail accounts and various community services.
Autoreporter statistics show growth in malware
According to the statistics of CERT-FI's Autoreporter system, there is definite growth in malware incidents from the previous year. Nearly half the notifications related to malware were due to the Conficker worm, which has contaminated millions of computers around the world. CERT-FI has actively contacted users of contaminated computers in Finland and provided guidance on how to remove the malware.
Finnish online banks no longer in safe
Even Finnish online banks are troubled by malware that hijack online banking connections. The banks are introducing additional security measurements in order to combat unauthorized money transfers. The number of malware targeted at online banking users is still small in Finland, but the phenomenon is here to stay.
CERT-FI publishes a quarterly overview of information security, which deals with the most significant threats to information security. The objective of the reviews is to support companies and organisations in their attempts to improve the management of information security risks. The CERT-FI information security review 1/2010 is available in Finnish on the CERT-FI website at www.cert.fi. An English version will be published soon.
Further information:
Duty officer of CERT-FI, tel. +358 9 6966 510
Ari Husa, Information Security Adviser, tel. +358 40 722 3130