Pakistanis angry over detentions in Times Sq. case Monday, May 24, 2010
ISLAMABAD – Relatives of three men detained by Pakistan for alleged links to the suspect in the attempted Times Square bombing say the men are innocent.
They
AFP - Thursday, August 6TAIPEI (AFP) - - Taiwan's Beijing-friendly government on Wednesday denied boycotting an Australian film festival amid a row over the e
BERLIN (Reuters) - Chancellor Angela Merkel suffered a double blow on Thursday as a senior party ally in east German
Minister seeks closure of anti-Berlusconi websites Wednesday, December 16, 2009
ROME (AFP) - – The Italian government moved Tuesday to close down Internet sites encouraging further violence against Prime Minister Silvio Berlusconi, who
By ELAINE KURTENBACH,AP Business Writer AP - Wednesday, March 18SHANGHAI - Asia's stock market rally seemed to be running out of steam Wednesday, despite an
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Home
Business
Business Home
Economy
Davos 2012
Technology
Media
Small Business
Legal
Deals
Earnings
Summits
Business Video
The Freeland File
Markets
Markets Home
U.S. Markets
European Markets
Asian Markets
Global Market Data
Indices
M&A
Stocks
Bonds
Currencies
Commodities
Futures
Funds
peHUB
World
World Home
U.S.
Brazil
China
Euro Zone
Japan
Mexico
Russia
India Insight
World Video
Reuters Investigates
Decoder
Politics
Politics Home
Election 2012
Issues 2012
Candidates 2012
Tales from the Trail
Political Punchlines
Supreme Court
Politics Video
Tech
Technology Home
MediaFile
Science
Tech Video
Tech Tonic
Opinion
Opinion Home
Chrystia Freeland
John Lloyd
Felix Salmon
Jack Shafer
David Rohde
Bernd Debusmann
Nader Mousavizadeh
Lucy P. Marcus
David Cay Johnston
Bethany McLean
Edward Hadas
Hugo Dixon
Ian Bremmer
Mohamed El-Erian
Lawrence Summers
Susan Glasser
The Great Debate
Steven Brill
Geraldine Fabrikant
Jack & Suzy Welch
Breakingviews
Equities
Credit
Private Equity
M&A
Macro & Markets
Politics
Breakingviews Video
Money
Money Home
Tax Break
Global Investing
MuniLand
Unstructured Finance
Linda Stern
Mark Miller
John Wasik
James Saft
Analyst Research
Alerts
Watchlist
Portfolio
Stock Screener
Fund Screener
Personal Finance Video
Money Clip
Investing 201
Life
Health
Sports
Arts
Faithworld
Business Traveler
Entertainment
Oddly Enough
Lifestyle Video
Pictures
Pictures Home
Reuters Photographers
Full Focus
Video
Reuters TV
Reuters News
Article
Comments (3)
Editor's Choice
Analysis: Facebook's daunting Asian challenge
Sony sees $2.9 billion loss, new CEO warns
Hacked companies still not telling investors
Angelic "Steve Jobs" loves Android in Taiwan TV ad
Birth control recall raises risk of unplanned pregnancy
Judge: health labels may stem tobacco co rights
Europe freeze kills 89, fears rise over Russian gas
Opinion: IPOverload, Facebook goes public
Video: Red flags in the Facebook S1 filing
Slideshow: Facebook, tagged at new HQ
Follow Reuters
Facebook
Twitter
RSS
YouTube
Read
After Florida win, Romney stumbles in comments on poor
|
7:06am EST
Israel says Iran has material for four A-bombs
9:45am EST
Egyptians incensed after 74 die in soccer tragedy
|
10:20am EST
U.S. plans to halt Afghan combat role early
|
8:15am EST
Facebook's Zuckerberg to keep iron grip after IPO
|
8:08am EST
Discussed
145
U.S. outrage as Egypt bars Americans from leaving
90
Romney wins Florida Republican presidential primary
79
Taliban ”poised to retake Afghanistan” after NATO pullout
Watched
Beckham unveils underwear for H&M
Wed, Feb 1 2012
Iran sends toy drone to Obama
Sun, Jan 29 2012
At least 73 killed in Egypt soccer riot
Wed, Feb 1 2012
Exclusive: Hacked companies still not telling investors
Tweet
Share this
Email
Print
Related News
Key Internet operator VeriSign hit by hackers
7:36am EST
Analysis & Opinion
How to avoid the insider trading net
Corporate Governance: proxy advisory guidelines and the shifting landscape of benchmarking executive compensation
Related Topics
Tech »
Media »
The Lockheed Martin plant in Fort Worth, Texas that builds F-35 fighter jets, in a March 2010 image.
Credit: Reuters/Fred Clingerman-Lockheed Martin
By Joseph Menn
SAN FRANCISCO |
Thu Feb 2, 2012 10:13am EST
SAN FRANCISCO (Reuters) - At least a half-dozen major U.S. companies whose computers have been infiltrated by cyber criminals or international spies have not admitted to the incidents despite new guidance from securities regulators urging such disclosures.
Top U.S. cybersecurity officials believe corporate hacking is widespread, and the Securities and Exchange Commission issued a lengthy "guidance" document on October 13 outlining how and when publicly traded companies should report hacking incidents and cybersecurity risk.
But with one full quarter having elapsed since the SEC request, some major companies that are known to have had significant digital security breaches have said nothing about the incidents in their regulatory filings.
Defense contractor Lockheed Martin Corp, for example, said last May that it had fended off a "significant and tenacious" cyber attack on its networks. But Lockheed's most recent 10-Q quarterly filing, like its filing for the period that included the attack, does not even list hacking as a generic risk, let alone state that it has been targeted.
A Reuters review of more than 2,000 filings since the SEC guidance found some companies, including Internet infrastructure company VeriSign Inc and credit card and debit card transaction processor VeriFone Systems Inc, revealed significant new information about hacking incidents.
Yet the vast majority of companies addressing the issue only used new boilerplate language to describe a general risk. Some hacking victims did not even do that.
"It's completely confusing to me why companies aren't reporting cyber risks" if only to avoid SEC enforcement or private lawsuits, said Jacob Olcott, former counsel for the Senate Commerce committee. The chair of that committee, John D. Rockefeller, urged the SEC to act last year.
Stewart Baker, a corporate attorney and former assistant secretary of the Department of Homeland Security, said the SEC guidance was detailed enough that companies that know they have been hacked will "have to work pretty hard not to disclose something about the scope and risk of the intrusion."
Otherwise, "this is an opportunity for enforcement that practically hands the case to the SEC on a platter," Baker said.
Lockheed spokesman Chris Williams said hacking was covered under the company's most recent annual securities filing, which has as one of many risk factors "security threats, including threats to our information technology infrastructure, attempts to gain access to our proprietary or classified information, threats to physical security of our facilities and employees, and terrorist acts."
Williams said the May attack had "no material effect on our business."
Mantech International Corp, CACI International Inc and other defense and technology firms that have been reported by security researchers as hacking victims were likewise silent in their most recent filings. Neither Mantech nor CACI responded to interview requests.
"It's common knowledge" that most large defense contractors have been penetrated, said Olcott.
Sikorsky Aircraft, mindful of a strict New Hampshire law warning individuals at risk of identity theft, wrote to that state's attorney general in August that hackers had gotten into its system and could have accessed Social Security numbers of 55 employees who lived in the state.
Sikorsky said the employee data likely was not the hackers' target, which suggests that they might have been after designs or other trade secrets. But Sikorsky parent United Technologies Corp did not mention the May intrusion in subsequent SEC filings.
"Like other companies, our businesses are subject to (information technology) security attacks at times. We monitor systems and cooperate closely with the government when appropriate," said United Technologies spokesman John Moran.
DEARTH OF CONFESSIONS
Melissa Hathaway, a former intelligence official who led U.S. President Barack Obama's initial cybersecurity policy review and helped push the SEC to enact a disclosure policy, said she was "surprised" at the dearth of new confessions.
"The SEC division of corporate finance has an obligation to ask these companies why they didn't disclose," she said. "We need to have transparency on the state of the situation, and we need to have a national conversation regarding the near-term impact of economic espionage and the long-term health of the nation."
The SEC declined to comment. The agency's guidance officially clarifies previous policy instead of establishing a new rule, a process that takes longer and requires a vote of the commissioners. A person close to the agency said it expects fuller disclosures in annual 10-K filings that will begin appearing in volume this month.
Cybersecurity has been an increasing concern in Washington, and Obama asked during his State of the Union speech for action on legislative proposals. Security experts believe hackers are frequently targeting valuable digital information including strategic plans, blueprints and secret formulas.
But security experts in and out of government have complained for years that most companies don't disclose even very successful hacking attacks, because they never find out about them or simply don't want to spook investors, customers or business partners.
The U.S. National Counterintelligence Executive, in a landmark November report that openly accused China of sponsoring military and economic cyber espionage, said that it is hard for companies to estimate the impact of losses that might not be apparent for years.
One Pentagon contractor that did go into some detail recently about the threat was Northrop Grumman Corp, which warned: "Cybersecurity attacks in particular are evolving and include, but are not limited to, malicious software, attempts to gain unauthorized access to data, and other electronic security breaches that could lead to disruptions in mission critical systems, unauthorized release of confidential or otherwise protected information and corruption of data. These events could damage our reputation and lead to financial losses from remedial actions, loss of business or potential liability."
A few technology companies gave even more specific warnings, including Juniper Networks Inc, which makes gear for routing Internet traffic, and chip-maker Intel Corp. Intel had been one of the few to disclose a successful breach in the past, along with Google Inc, which has complained of attacks originating in China.
In a November filing, Intel repeated that hackers had gotten inside and warned that "the theft or unauthorized use or publication of our trade secrets and other confidential business information as a result of such an incident could adversely affect our competitive position and reduce marketplace acceptance of our products."
Some companies asserted that they had not been hacked, or at least averred that they had not been subject to a "material" or "catastrophic" intrusion.
Others confessed to breaches for the first time, including VeriSign and VeriFone Systems, which said it had experienced "security breaches or fraudulent activities related to unauthorized access to sensitive customer information."
The company did not respond to requests for elaboration. Point-of-sale terminals including VeriFone's models are popular targets for criminal hackers, who can tamper with them in order to record passwords and card numbers.
VeriFone has been reported as a supplier of machines to Michaels Stores Inc, a retail chain of hobbyist stores that had to replace more than 7,000 terminals last year after discovering tampering in 20 states.
Two other companies said they disclosed breaches because of the SEC guidance. Tumi Holdings, the luggage maker that is pursuing an initial public offering, said in a stock prospectus that security systems in some of its retail stores had been compromised in the past.
In an interview, Tumi Chief Financial Officer Michael Mardy said there had been no theft of a database or other massive breach. Instead, he said there had been occasions where store employees had conspired with outsiders on a small scale, for example by giving refunds to people who had not made purchases.
"We felt it was necessary to list as a risk factor because it actually is a risk factor," Mardy said.
University of Phoenix parent Apollo Group Inc, which in the past had noted attempted breaches, for the first time said some attempts had succeeded.
"We are facing an increasing number of threats to our computer systems of unauthorized access, computer hackers, computer viruses, malicious code, organized cyber attacks and other system disruptions and security breaches, and from time to time we experience such disruptions and breaches," it wrote in a 10-Q.
Apollo spokesman Rick Castellano declined to say how extensive the breaches had been. "Cybersecurity is an area of growing area of concern for all companies", Castellano said. "We devote significant resources to manage any potential threat."
(Reporting By Joseph Menn)
Tech
Media
Related Quotes and News
Company
Price
Related News
Tweet this
Link this
Share this
Digg this
Email
Reprints
We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (3)
AndiV wrote:
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Back to top
Reuters.com
Business
Markets
World
Politics
Technology
Opinion
Money
Pictures
Videos
Site Index
Legal
Bankruptcy Law
California Legal
New York Legal
Securities Law
Support & Contact
Support
Corrections
Advertise With Us
Connect with Reuters
Twitter
Facebook
LinkedIn
RSS
Podcast
Newsletters
Mobile
About
Privacy Policy
Terms of Use
Copyright
Our Flagship financial information platform incorporating Reuters Insider
An ultra-low latency infrastructure for electronic trading and data distribution
A connected approach to governance, risk and compliance
Our next generation legal research platform
Our global tax workstation
Thomsonreuters.com
About Thomson Reuters
Investor Relations
Careers
Contact Us
Thomson Reuters is the world's largest international multimedia news agency, providing investing news, world news, business news, technology news, headline news, small business news, news alerts, personal finance, stock market, and mutual funds information available on Reuters.com, video, mobile, and interactive television platforms. Thomson Reuters journalists are subject to an Editorial Handbook which requires fair presentation and disclosure of relevant interests.
NYSE and AMEX quotes delayed by at least 20 minutes. Nasdaq delayed by at least 15 minutes. For a complete list of exchanges and delays, please click here.