Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Incidents

October 19th, 2009, 14:07 GMT · By

Payroll Processor Hacked Twice in a Single Month

SHARE:

Adjust text size:


Online Employer system taken offline after hacking attack
Enlarge picture
The online system of a large U.S. payroll processing company was attacked by hackers for the second time in a few weeks. Stolen credentials were used to create fake employees for companies in an attempt to siphon out funds out of their accounts.

Onlineemployer.com, an online system belonging to PayChoice, one of the largest payroll processors in U.S., was taken offline due to a security breach last Thursday. The attack occurred on October 14 and was the second of its kind in less than a month.

At the end of September, we reported that PayChoice was hit by cybercriminals who managed to steal customer names, email addresses, login IDs and partial passwords. The company announced that computer forensic experts were called in to investigate the incident.

Subsequently, some of the 125,000 organizations and business partners that use the company's online system to process payrolls have reportedly received phishing emails. The messages advertised a link allegedly pointing to a PayChoice-sanctioned browser toolbar.

The Web page actually contained an exploit cocktail that attempted to infect computers with an information stealing trojan. In order to make the scheme more credible, the attackers incorporated the stolen account information into the phishing emails.

It seems that last week's new attack made use of compromised accounts. "After investigation, we determined that valid user credentials for an Online Employer user were used in an unauthorized manner to add these fictitious employees in an attempt to have payments made to fraudulent bank accounts," an e-mail sent by the company to its customers on Thursday reads.

The online system has since been re-opened, but the "password reset" function has been temporarily disabled. Apparently, a vulnerability was identified in this component, which represented a "key mechanism" in the latest attack. "PayChoice reopened the site with limited functions as it continues to tighten the security based on forensic findings from Wednesday's attack," Robert Digby, PayChoice's chief executive officer, told Security Fix.

TELL US WHAT YOU THINK:

2,024 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Major Payroll Processing Provider Breached

Data Breach at Radisson Hotels, Stolen Credit Card Numbers

TV Lamps Online Merchant Suffers Data Breach

Major Security Breach at Network Solutions

Online Merchant's Server Hacking Results in Data Breach

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM