Data Breaches

April 4, 2016

Sources: Trump Hotels Breached Again

This post was originally published on this site Banking industry sources tell KrebsOnSecurity that the Trump Hotel Collection — a string of luxury properties tied to business magnate and Republican presidential candidate Donald Trump — appears to be dealing with another breach of its credit card systems. If confirmed, this would be the second such breach at the Trump properties in less than a year. Trump International Hotel in New York. A representative from Trump Hotels said the organization was investigating the claims. “We are in the midst of a thorough investigation on this matter,” the company said in a written statement. […]
April 6, 2016

After Tax Fraud Spike, Payroll Firm Greenshades Ditches SSN/DOB Logins

This post was originally published on this site Online payroll management firm Greenshades.com is an object lesson in how not to do authentication. Until very recently, the company allowed corporate payroll administrators to access employee payroll data online using nothing more than an employee’s date of birth and Social Security number. That is, until criminals discovered this and began mass-filing fraudulent tax refund requests with the IRS on large swaths of employees at firms that use the company’s services. A notice on the Greenshades Web site. Jacksonville, Fla.-based Greenshades posted an alert on its homepage stating that the company “has seen an abnormal increase […]
May 3, 2016

Fraudsters Steal Tax, Salary Data From ADP

This post was originally published on this siteIdentity thieves stole tax and salary data from payroll giant ADP by registering accounts in the names of employees at more than a dozen customer firms, KrebsOnSecurity has learned. ADP says the incidents occurred because the victim companies all mistakenly published sensitive ADP account information online that made those firms easy targets for tax fraudsters. Patterson, N.J.-based ADP provides payroll, tax and benefits administration for more than 640,000 companies. Last week, U.S. Bancorp (U.S. Bank) — the nation’s fifth-largest commercial bank — warned some of its employees that their W-2 data had been stolen […]
May 6, 2016

Crooks Grab W-2s from Credit Bureau Equifax

This post was originally published on this siteIdentity thieves stole tax and salary data from big-three credit bureau Equifax Inc., according to a letter that grocery giant Kroger sent to all current and some former employees on Thursday. The nation’s largest grocery chain by revenue appears to be one of several Equifax customers that were similarly victimized this year. Atlanta-based Equifax’s W-2Express site makes electronic W-2 forms accessible for download for many companies, including Kroger — which employs more than 431,000 people. According to a letter Kroger sent to employees dated May 5, thieves were able to access W-2 data merely by entering […]