Phisher folk reel in Computacenter security vetting mailbox packed with sensitive staff data

Haul included employee passports, driving licences, bank statements and more

The third-party mailbox used by Computacenter employees and contractors to deposit data for security clearance applications has been hacked and used in phishing scams.

The company, one of Europe's largest resellers, counts some of the biggest names in financial services among its corporate client base, and sells to a raft of local and central government customers.

Computacenter wrote to its staff yesterday to confirm the incident:

We have established that a mailbox provided by a third party as part of the vetting service it provides to Computacenter UK Ltd has been the target of a cyber security attack. Unfortunately, we believe the mailbox may have included data relating to you.

The mailbox was used to collate data from individuals when information relating to their security clearance applications was deemed to be missing or incorrect. The information requested could include ID data, contact details, bank details, addresses and employment history.

The "attacker" gained entry and changed the password for the mailbox, which system audit logs showed prevented further access by Computacenter. The mailbox was then used to send phishing emails.

"However, these logs cannot tell us precisely what was in the mailbox at the time of the attack or whether the data was exported or just deleted," the mail to staff stated.

On being made aware of the attack, Computacenter said it initiated the Group Information Assurance compliance methodology, establishing that other systems connected to the security vetting process were unaffected and "secure workaround processes for security clearance have been implemented".

The reseller also, obviously, blocked further unauthorised access to the mailbox, stopped using it and "advised users not to send information to it".

"The mailbox will be permanently deleted once the investigation and root cause analysis is completed," the memo to staff added. "We would also like to re-emphasise that the attack was not on Computacenter's own email system."

That will come as small consolation to any employee or contractors whose details were exposed in the leak.

The company added: "Whilst we believe that the motive for the attack was disruptive rather than exploitative, you should consider the possibility of identification theft or fraud." Depending on the type of information provided, staff were urged to monitor account statements for "evidence of unauthorised activity".

Computacenter is offering a 12-month free ID monitoring service, but to access it staff and contractors need to email the UK Vetting Team.

One source who sent data to the affected mailbox told us it was used for vetting Computacenter workers for all sorts of sites and customers. He told us the company requested various forms of documentation including a passport, driving licence and bank statements.

"I was told if I did not provide them I could not be on-site. Now it's a custom identity fraud kit," one of our sources said.

Computacenter has told Britain's Information Commissioner's Office of the security breach. The Register asked the ICO and Computacenter to comment. ®

Updated 11.14BST to add:

An ICO spokesperson contacted us to say: “Computacenter has made us aware of an incident and we will assess the information provided”.

Broader topics

Other stories you might like

  • China’s COVID lockdowns bite e-commerce players
    CEO of e-tail market leader JD perhaps boldly points out wider economic impact of zero-virus stance

    The CEO of China’s top e-commerce company, JD, has pointed out the economic impact of China’s current COVID-19 lockdowns - and the news is not good.

    Speaking on the company’s Q1 2022 earnings call, JD Retail CEO Lei Xu said that the first two years of the COVID-19 pandemic had brought positive effects for many Chinese e-tailers as buyer behaviour shifted to online purchases.

    But Lei said the current lengthy and strict lockdowns in Shanghai and Beijing, plus shorter restrictions in other large cities, have started to bite all online businesses as well as their real-world counterparts.

    Continue reading
  • Foxconn forms JV to build chip fab in Malaysia
    Can't say when, where, nor price tag. Has promised 40k wafers a month at between 28nm and 40nm

    Taiwanese contract manufacturer to the stars Foxconn is to build a chip fabrication plant in Malaysia.

    The planned factory will emit 12-inch wafers, with process nodes ranging from 28 to 40nm, and will have a capacity of 40,000 wafers a month. By way of comparison, semiconductor-centric analyst house IC Insights rates global wafer capacity at 21 million a month, and Taiwanese TSMC’s four “gigafabs” can each crank out 250,000 wafers a month.

    In terms of production volume and technology, this Malaysian facility will not therefore catapult Foxconn into the ranks of leading chipmakers.

    Continue reading
  • NASA's InSight doomed as Mars dust coats solar panels
    The little lander that couldn't (any longer)

    The Martian InSight lander will no longer be able to function within months as dust continues to pile up on its solar panels, starving it of energy, NASA reported on Tuesday.

    Launched from Earth in 2018, the six-metre-wide machine's mission was sent to study the Red Planet below its surface. InSight is armed with a range of instruments, including a robotic arm, seismometer, and a soil temperature sensor. Astronomers figured the data would help them understand how the rocky cores of planets in the Solar System formed and evolved over time.

    "InSight has transformed our understanding of the interiors of rocky planets and set the stage for future missions," Lori Glaze, director of NASA's Planetary Science Division, said in a statement. "We can apply what we've learned about Mars' inner structure to Earth, the Moon, Venus, and even rocky planets in other solar systems."

    Continue reading
  • The ‘substantial contributions’ Intel has promised to boost RISC-V adoption
    With the benefit of maybe revitalizing the x86 giant’s foundry business

    Analysis Here's something that would have seemed outlandish only a few years ago: to help fuel Intel's future growth, the x86 giant has vowed to do what it can to make the open-source RISC-V ISA worthy of widespread adoption.

    In a presentation, an Intel representative shared some details of how the chipmaker plans to contribute to RISC-V as part of its bet that the instruction set architecture will fuel growth for its revitalized contract chip manufacturing business.

    While Intel invested in RISC-V chip designer SiFive in 2018, the semiconductor titan's intentions with RISC-V evolved last year when it revealed that the contract manufacturing business key to its comeback, Intel Foundry Services, would be willing to make chips compatible with x86, Arm, and RISC-V ISAs. The chipmaker then announced in February it joined RISC-V International, the ISA's governing body, and launched a $1 billion innovation fund that will support chip designers, including those making RISC-V components.

    Continue reading
  • FBI warns of North Korean cyberspies posing as foreign IT workers
    Looking for tech talent? Kim Jong-un's friendly freelancers, at your service

    Pay close attention to that resume before offering that work contract.

    The FBI, in a joint advisory with the US government Departments of State and Treasury, has warned that North Korea's cyberspies are posing as non-North-Korean IT workers to bag Western jobs to advance Kim Jong-un's nefarious pursuits.

    In guidance [PDF] issued this week, the Feds warned that these techies often use fake IDs and other documents to pose as non-North-Korean nationals to gain freelance employment in North America, Europe, and east Asia. Additionally, North Korean IT workers may accept foreign contracts and then outsource those projects to non-North-Korean folks.

    Continue reading
  • Elon Musk says Twitter buy 'cannot move forward' until spam stats spat settled
    A stunning surprise to no one in this Solar System

    Elon Musk said his bid to acquire and privatize Twitter "cannot move forward" until the social network proves its claim that fake bot accounts make up less than five per cent of all users.

    The world's richest meme lord formally launched efforts to take over Twitter last month after buying a 9.2 per cent stake in the biz. He declined an offer to join the board of directors, only to return asking if he could buy the social media platform outright at $54.20 per share. Twitter's board resisted Musk's plans at first, installing a "poison pill" to hamper a hostile takeover before accepting the deal, worth over $44 billion.

    But then it appears Musk spotted something in Twitter's latest filing to America's financial watchdog, the SEC. The paperwork asserted that "fewer than five percent" of Twitter's monetizable daily active users (mDAUs) in the first quarter of 2022 were fake or spammer accounts, which Musk objected to: he felt that figure should be a lot higher. He had earlier proclaimed that ridding Twitter of spam bots was a priority for him, post-takeover.

    Continue reading

Biting the hand that feeds IT © 1998–2022