News

Montana Based Brokerage Firm, DA Davidson Fined $375,000 for Unsecured Data

Brokerage firm DA Davidson http://www.davidsoncompanies.com/indv/ has agreed to pay a fine of $375,000 for failing to protect confidential client data from Latvian hackers who breached the company in 2007 in an online extortion scheme.

The hackers used a SQL injection attack to obtain access to the company’s database on Dec. 25 and 26, 2007.

The Financial Industry Regulatory Authority, which announced the fine agreement on Monday, said although the attack activity was reflected in the brokerage’s server logs, administrators failed to examine those logs. The intruders obtained data on about 192,000 customers, according to the press release announcing the fine. (Previous reports indicated that more than 300,000 customer files were stolen). The data included customer account numbers, Social Security numbers, names, addresses, dates of birth and other private information.

By Kim Zetter

Full Story: http://www.wired.com/threatlevel/2010/04/brokerage-firm-fined

Posted in:

Sorry, we couldn't find any posts. Please try a different search.

Leave a Comment

You must be logged in to post a comment.