Job hunters blackmailed in Monster.com hack

Monster, the world's largest recruitment website, was left reeling this week when thousands of jobseekers were targeted in a sophisticated phishing blackmail scam.

American users who had registered with the site received e-mails last week inviting them to download a Job Seeker Tool from Monster. What they got was a Trojan horse virus that encrypted their files and a message from a group called Glamorous Team demanding a $300 ransom to decrypt their files.

Coverage in the UK newspaper, The Guardian, recounted the experiences of several people who were affected by the attack. One of the reasons it proved so effective was that it presented a plausible scenario from a site that would have been known and trusted by its users. What is almost as worrying as the blackmail technique is how the criminals were able to crack the Monster database to get hold of the users' e-mail addresses.

According to Symantec, which identified a Trojan virus called Infostealer.Monstres on August 16th, the attack started by accessing employer sections of Monster.com and uploaded details on several hundred thousand people to the remote website.

The second part of the attack spammed the e-mails harvested with an executable file Trojan.Gpcoder.E, which was carried as an attachment with an icon designed to look like the Monster.com logo.

When researchers from the UK security company Prevx reverse-engineered the encryption virus and used victims' details to log into the website where data was being held hostage, they were able to download personal information on several people and decrypt personal data such as system passwords and PayPal account details.

According to Prevx, the attack targeted Monster.com users in America and appropriated data from around 1,000 PCs.

By John Stokdyk, for our sister site, AccountingWEB.co.uk

Voice of the Editor

Even though any accounting auditor would tell you it seems like there are an awful lot of tax accountants out there, surely one-third of the country isn't made up of tax preparers, so it's rather startling news to learn that one-third of Americans like to do their taxes. Who knew?
ADVERTISEMENT

This Week on AccountingWEB

Bill Walter of Gross, Mendelsohn & Associates and Harold Gaar of TravisWolff LLP weigh in on mobile technology use while employees are at work.
WestArk RSVP and Fayette County Community Action Agency – organizations that received grant funding through the IRS Tax Counseling for the Elderly (TCE) program – spoke with AccountingWEB about how they assist senior citizens in their communities.
CPA Robert Raiola, who heads the Sports & Entertainment Group of Fazio, Mannuzza, Roche, Tankel, LaPilusa, LLC, talks NFL player income taxes with AccountingWEB.
Retiring KPMG Centennial Professor of Accounting at the University of Texas at Austin McCombs School of Business Robert May, PhD talks with AccountingWEB about his rewarding forty-three-year career.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT