{"id":16776,"date":"2019-11-05T09:00:02","date_gmt":"2019-11-05T17:00:02","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/11\/05\/news-10515\/"},"modified":"2019-11-05T09:00:02","modified_gmt":"2019-11-05T17:00:02","slug":"news-10515","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/11\/05\/news-10515\/","title":{"rendered":"Trend Micro Discloses Insider Threat Impacting some of its Consumer Customers"},"content":{"rendered":"<p><strong>Credit to Author: Trend Micro| Date: Tue, 05 Nov 2019 15:45:47 +0000<\/strong><\/p>\n<p><span data-contrast=\"auto\">W<\/span><span data-contrast=\"auto\">e<\/span><span data-contrast=\"auto\">\u00a0recently\u00a0<\/span><span data-contrast=\"auto\">became aware of a security incident that resulted in the unauthorized disclosure of\u00a0<\/span><span data-contrast=\"auto\">some personal data\u00a0<\/span><span data-contrast=\"auto\">of an isolated number of customers<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">of our consumer product<\/span><span data-contrast=\"auto\">.\u00a0\u00a0<\/span><span data-contrast=\"auto\">We<\/span><span data-contrast=\"auto\">\u00a0immediately started investigating the situation and foun<\/span><span data-contrast=\"auto\">d that this was the result of a<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">malicious\u00a0<\/span><span data-contrast=\"auto\">insider threat<\/span><span data-contrast=\"auto\">. The suspect was\u00a0<\/span><span data-contrast=\"auto\">a Trend Micro employee who\u00a0<\/span><span data-contrast=\"auto\">improperly\u00a0<\/span><span data-contrast=\"auto\">accessed the data with a clear crim<\/span><span data-contrast=\"auto\">inal intent.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">We\u00a0<\/span><span data-contrast=\"auto\">immediately\u00a0<\/span><span data-contrast=\"auto\">began\u00a0<\/span><span data-contrast=\"auto\">taking the actions\u00a0<\/span><span data-contrast=\"auto\">necessary to ensure\u00a0<\/span><span data-contrast=\"auto\">that\u00a0<\/span><span data-contrast=\"auto\">no additional data c<\/span><span data-contrast=\"auto\">ould<\/span><span data-contrast=\"auto\">\u00a0be improperly<\/span><span data-contrast=\"auto\">\u00a0accessed,<\/span><span data-contrast=\"auto\">\u00a0and\u00a0<\/span><span data-contrast=\"auto\">have\u00a0<\/span><span data-contrast=\"auto\">involve<\/span><span data-contrast=\"auto\">d<\/span><span data-contrast=\"auto\">\u00a0law enforcement.\u00a0<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Our open investigation has confirmed\u00a0<\/span><span data-contrast=\"auto\">that\u00a0<\/span><span data-contrast=\"auto\">t<\/span><span data-contrast=\"auto\">his was not an external hack<\/span><span data-contrast=\"auto\">,<\/span><span data-contrast=\"auto\">\u00a0but rather the work of a<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">malicious\u00a0<\/span><span data-contrast=\"auto\">internal source that\u00a0<\/span><span data-contrast=\"auto\">engaged in a\u00a0<\/span><span data-contrast=\"auto\">premeditated infiltration<\/span><span data-contrast=\"auto\">\u00a0scheme<\/span><span data-contrast=\"auto\">\u00a0to bypass our sophisticated controls.\u00a0\u00a0<\/span><b><span data-contrast=\"auto\">\u00a0<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">That said, we hold ourselves to a higher level of accountability and\u00a0<\/span><span data-contrast=\"auto\">sincerely\u00a0<\/span><span data-contrast=\"auto\">apologize to\u00a0<\/span><span data-contrast=\"auto\">all\u00a0<\/span><span data-contrast=\"auto\">impacted customers for this situation.<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">Based on the current status of our investigation, we believe that all of the consumers who were potentially affected have already received individual notices from Trend Micro, but we will continue to investigate and provide further notices in the event that any further affected customers are identified.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">WHAT HAPPENED<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In early\u00a0<\/span><span data-contrast=\"auto\">August<\/span><span data-contrast=\"auto\">\u00a02019, Trend Micro became aware that some of our c<\/span><span data-contrast=\"auto\">onsumer c<\/span><span data-contrast=\"auto\">ustomers\u00a0<\/span><span data-contrast=\"auto\">running our home security solution\u00a0<\/span><span data-contrast=\"auto\">had<\/span><span data-contrast=\"auto\">\u00a0been receiving scam calls by criminals impersonating Trend Micro support personnel.\u00a0 The information that the criminals reportedly possessed in these scam calls led us to suspect a coordinated attack.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Although we immediately launched a thorough investigation, it was not until\u00a0<\/span><span data-contrast=\"auto\">the end of October\u00a0<\/span><span data-contrast=\"auto\">2019 that we were able to definitively conclude that\u00a0<\/span><span data-contrast=\"auto\">it was an insider threat. A<\/span><span data-contrast=\"auto\">\u00a0Trend Micro employee used fraudulent means to gain access to a customer support database that contained names, email addresses, Trend Micro support ticket numbers, and in some instances telephone numbers.\u00a0<\/span><span data-contrast=\"auto\">There are no indications that any other information such as financial or credit payment information<\/span><span data-contrast=\"auto\">\u00a0was involved,<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-contrast=\"auto\">or\u00a0<\/span><span data-contrast=\"auto\">that any data from our\u00a0<\/span><span data-contrast=\"auto\">business or government<\/span><span data-contrast=\"auto\">\u00a0customers was improperly accessed.\u00a0\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Our<\/span><span data-contrast=\"auto\">\u00a0investigation revealed that this employee sold the\u00a0<\/span><span data-contrast=\"auto\">stolen<\/span><span data-contrast=\"auto\">\u00a0information to a currently unknown third-party\u00a0<\/span><span data-contrast=\"auto\">malicious actor.\u00a0<\/span><span data-contrast=\"auto\">We took swift action to contain the situation, including immediately disabling the\u00a0<\/span><span data-contrast=\"auto\">unauthorized\u00a0<\/span><span data-contrast=\"auto\">account access and terminating the employee in question, and we are continuing to work with law enforcement on an ongoing investigation.<\/span><span data-contrast=\"auto\">\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">TREND MICRO DOES NOT CALL CONSUMERS UNSOLICITED\u00a0<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">If you have purchased our consumer product, you\u00a0<\/span><span data-contrast=\"auto\">should know that Trend Micro will never call you unexpectedly. If a support call is to be made, it will be scheduled in advance. If you receive an unexpected phone call claiming to be from Trend Micro, hang up and report the incident to Trend Micro\u00a0<\/span><span data-contrast=\"auto\">s<\/span><span data-contrast=\"auto\">upport using our official contact details below.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:257}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">We encourage you to please contact us for further assistance if you need any help related to any technical issues that may have arisen from interaction with the scammers.\u00a0 These technical assistance support services, as with all support services, are already covered by your active license subscription.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:257}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">ADDITIONAL IMPORTANT INFORMATION<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:257}\">\u00a0<\/span><\/p>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">We would like to reassure our business<\/span><span data-contrast=\"auto\">\u00a0and government<\/span><span data-contrast=\"auto\">\u00a0customers that our investigations have shown no indication that the criminal has accessed any enterprise customer data.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:257}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">While every maliciously accessed data set is one too many, our investigation<\/span><span data-contrast=\"auto\">\u00a0ha<\/span><span data-contrast=\"auto\">s<\/span><span data-contrast=\"auto\">\u00a0shown that this security incident affects less than\u00a0<\/span><span data-contrast=\"auto\">1<\/span><span data-contrast=\"auto\">% of Trend Micro\u2019s\u00a0<\/span><span data-contrast=\"auto\">12 million <\/span><span data-contrast=\"auto\">consumer customers<\/span><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:257}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"3\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Our investigation further shows that the criminals were only targeting English-speaking customers, and we have only seen data accessed in predominantly English-speaking countries.\u00a0<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:257}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><b><span data-contrast=\"auto\">FOR MORE INFORMATION<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Official contact information for Trend Micro technical support in your region can always be found at\u00a0<\/span><a href=\"https:\/\/esupport.trendmicro.com\"><span data-contrast=\"none\">https:\/\/esupport.trendmicro.com<\/span><\/a><span data-contrast=\"auto\">. Please contact us if you have any questions or concerns.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\/trend-micro-discloses-insider-threat-impacting-some-of-its-consumer-customers\/\">Trend Micro Discloses Insider Threat Impacting some of its Consumer Customers<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\"><\/a>.<\/p>\n<p><a href=\"https:\/\/blog.trendmicro.com\/trend-micro-discloses-insider-threat-impacting-some-of-its-consumer-customers\/\" target=\"bwo\" >http:\/\/feeds.trendmicro.com\/TrendMicroSimplySecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Trend Micro| Date: Tue, 05 Nov 2019 15:45:47 +0000<\/strong><\/p>\n<p>We\u00a0recently\u00a0became aware of a security incident that resulted in the unauthorized disclosure of\u00a0some personal data\u00a0of an isolated number of customers\u00a0of our consumer product.\u00a0\u00a0We\u00a0immediately started investigating the situation and found that this was the result of a\u00a0malicious\u00a0insider threat. The suspect was\u00a0a Trend Micro employee who\u00a0improperly\u00a0accessed the data with a clear criminal intent.\u00a0\u00a0 We\u00a0immediately\u00a0began\u00a0taking the actions\u00a0necessary to&#8230;<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\/trend-micro-discloses-insider-threat-impacting-some-of-its-consumer-customers\/\">Trend Micro Discloses Insider Threat Impacting some of its Consumer Customers<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\"><\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10413],"tags":[714],"class_list":["post-16776","post","type-post","status-publish","format-standard","hentry","category-security","category-trendmicro","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16776","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=16776"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16776\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=16776"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=16776"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=16776"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}