Originally published Friday, July 1, 2005 at 12:00 AM
Banks increasingly view workers as security threat
When two of the nation's largest banks were forced to notify thousands of customers that their financial records might have been stolen...
The Associated Press
CHARLOTTE, N.C. — When two of the nation's largest banks were forced to notify thousands of customers that their financial records might have been stolen, there wasn't a hacker, a missing laptop or a lost box of backup computer tapes to blame.
This time, police believe, customers of Wachovia and Bank of America were the victims of bank employees, workers whose jobs at the banks granted them access to information valuable enough to sell for $10 an account.
Security experts believe it's that battle against insiders — the theft of Social Security numbers and other sensitive data by those with the authority to access it — that will consume banks and other financial institutions as they fight a recent run of security breaches that doesn't appear to be waning.
"We've got a nasty problem and it keeps getting worse over the past couple of months," said Peter Neumann, a security expert with SRI International in Menlo Park, Calif. "Insiders have always been a concern, it's just that [institutions] are finally admitting it."
Security experts like Neumann believe inside jobs have the potential to be far more damaging to consumers than accidental losses of data, or attacks by hackers similar to one disclosed June 17 at Atlanta-based CardSystems Solutions, which exposed 40 million credit- and debit-card accounts.
And the protections banks use to thwart hackers — firewalls and encryption, for example — have no ability to stop ill-intentioned employees who have authorized access to secure information.
The insider case at Bank of America, Wachovia and two other banks — involving a much-smaller number of accounts than the hackers' assault on CardSystems Solutions — could prove to be far worse for consumers, said Avivah Litan, an analyst with Stamford, Conn.-based Gartner, an information-technology research firm.
"It may not be bigger, but that stuff is a lot more dangerous," Litan said. "These are people who have access to a lot more personal information, so it's very serious."
Wachovia and Bank of America were forced to alert more than 100,000 customers in May after police in New Jersey charged nine people, including seven bank workers, in a plot to steal financial records of thousands of bank customers.
"About 70 to 80 percent of the risk is from insiders, although not all of them are as malicious as the case in New Jersey," said Steve Roop, vice president of marketing at San Francisco-based Vontu, a firm specializing in data-loss prevention. "Sometimes it is well-meaning but poorly informed workers."
As might be expected when the subject is security, neither Wachovia nor Bank of America is willing to explain in detail efforts they take to protect sensitive data from employees who want to illegally sell private account information.
"All of our associates must adhere to a code of ethics and to company policy," said Tara Burke, a spokeswoman for Bank of America. "And our bank associates only have access to the information they need to provide service to our customers."
![]()
The bank does perform criminal-background checks on all new employees, using fingerprinting and other screening methods. Contract-labor suppliers must perform criminal checks on temporary employees they supply to the bank, she said.
But the problem with background checks is that they don't work, said Jim Stickley, chief technology officer at TraceSecurity, a Baton Rouge, La.-based security company.
"Sure, [it works] if you are looking at a murderer or someone with a criminal record. But there are a million idiots out there who are lucky so they don't have a record," he said. "No matter what you do, all it takes is one person who is down on his luck or realizes he can make a lot of money doing this. Then you have your biggest nightmare."
In all, Burke said, Bank of America spends about $250 million annually on various security measures and protections, and has hundreds of associates whose sole function is to protect information.
Wachovia spokeswoman Christy Phillips said the bank employs similar protections, including offering programs and training to educate employees on how to safeguard information. Background screening is a longtime policy at Wachovia, and there are tools and procedures that limit access to information to employees whose jobs require such access. "We routinely review our processes and make changes as appropriate," she said.
Among the other difficulties the banks face when working with employees, Roop said, is a high level of turnover. "These banks hire hundreds of new people every month," Roop said.
Among the steps banks can take to fight insider ID theft is to individually limit each employee's access to customer information, Litan said. Such a system specifies exactly what customer information each employee can see, touch and update.
Another way to police insider theft is "the intimidation factor," Stickley said. While some workers might complain that their rights are being infringed by aggressive monitoring of their work activities, Stickley said, they need to understand "they are dealing with extremely confidential information that can wreck a lot of peoples' lives."
But in the end, even the experts said protecting sensitive information from insiders comes down to basic human honesty.
"If someone wants to do it, they are going to do it," Stickley said.
UPDATE - 09:46 AM
Exxon Mobil wins ruling in Alaska oil spill case
UPDATE - 09:32 AM
Bank stocks push indexes higher; oil prices dip
UPDATE - 08:04 AM
Ford CEO Mulally gets $56.5M in stock award
UPDATE - 07:54 AM
Underwater mortgages rise as home prices fall
NEW - 09:43 AM
Warner Bros. to offer movie rentals on Facebook

Entertainment | Top Video | World | Offbeat Video | Sci-Tech
- Madrona dad killed by stray bullet as he drove through Central Area
- SPU surprises neighbors with sale of Queen Anne rec property
- Beer-drinking bridge builders will get training from a counselor
- Matt Flynn has good day in Seahawks' 3-way QB competition
- Boy's pat on president's head captured for history
- Why dealing for Kellen Winslow makes sense for Seahawks | Steve Kelley
- Police arrest New Jersey man who confessed to killing Etan Patz
- Amazon addresses criticism at meeting
- Driver fatally shot in Central Area
- Sources: DOJ sends letters to city blasting police-reform efforts
- Opponents of gay-marriage law say they have enough signatures
739 - Mariners try to extend some other team's misery for a change
337 - Komen controversy hurting Race for the Cure
203 - Madrona dad killed by stray bullet as he drove through Central Area
198 - Sources: DOJ sends letters to city blasting police reform efforts
135 - Typical CEO made $9.6M last year, AP study finds
93 - Driver caught in crossfire, fatally shot in Central Area
89 - Mariners manager Eric Wedge says releasing Chone Figgins not a consideration and that Casper Wells was odd man out
65 - The Seattle area's scandalous lack of adequate transit capacity
61 - It's been great; see you soon in my new columns
59
- Dig into colorful history at Oregon's John Day Fossil Beds
- Madrona dad killed by stray bullet as he drove through Central Area
- Get a sitter — please — for these 10 great date-night restaurants | All You Can Eat
- SPU surprises neighbors with sale of Queen Anne rec property
- Beer-drinking bridge builders will get training from a counselor
- Boy's pat on president's head captured for history
- Zumiez rebounds from recession better than most
- Driver fatally shot in Central Area
- Downtown building fetches $55M, thanks to Amazon effect
- Gates Foundation grants give local groups a boost
