Organized Crime Syndicates Infultrate Call Centers.
Organized crime syndicates are ridiculously powerful forces within the IT realm – stealing corporate/national secrets, forming netbot armies, finding 0-day exploits, identity theft, or even holding sensitive information for ransom. Consider this…if a criminal organization can fund the constructing of a submarine to transport cocaine from South America to North America, it’s a pretty safe bet they can construct a ‘military-like’ capable Internet presence for a fraction of the price of that submarine. I wouldn’t at all be surprised if some crime syndicates have launched their own satellites into the atmosphere to obfuscate law enforcement’s ability to track/eavesdrop on their data communications.
Historically, HIPAA has been a fairly casual regulation and didn’t differentiate between paper offices and electronic offices. However, the new American Recovery and Reinvestment Act (ARRA) is the government’s hefty attempt to not only coerce all Healthcare providers (doctor’s offices, hospitals and all medical service facilities) to go electronic but also to create a national standard format so healthcare companies can exchange information and therefore service the patient with better medical treatment. It’s definitely a step in the right direction [more efficient], but a centralized repository of medical records created from a multitude of hospitals/healthcare providers/etc. all sharing back and forth is a recipe for disaster. You know…since the US government is so efficient about sharing information back and forth between the different agencies (devilish grin); connecting separate healthcare companies using completely different encryption strategies – piece of cake (bigger devilish grin)!!
A professional hacker targeting a healthcare organization for identity theft data “might” take 4 or 5 weeks to complete from start to finish (depending on how aggressive they were). All and all not a horrible payday for a couple months of work (~1 month to perform the crack plus the 2-3 months finding the target company) but syndicates have found a new more efficient way to penetrate the company’s defenses and in half the time – plant an insider.
Insider threats are nothing new to the IT industry…but planting an insider in a call center where employees need to authenticate the callers by asking sensitive questions is similar to that of ‘cherry picking’! As the malicious employee gathers sensitive information from the caller over the phone they can easily start to collect a list of identities to steal. The attacker is neither accessing information they shouldn’t nor creating an extensive amount of internal traffic (as would the stealing of an entire database). It’s the perfect ‘low and slow’ attack. One insider hurts but isn’t crippling, but consider 10 or 15 insiders working together to capture as much ePHI as possible – it quickly starts to add up!
Unfortunately, other than not hiring them in the first place, there is absolutely no way for a corporation to mitigate this attack. Background checks are the only possible way an employer could avoid this attack…AND that banks on the fact that the malicious adversary has been caught! My advice to readers is check with your HR firm to ensure that proper background screenings are occurring! And even, take it a step further and request people that have access to sensitive information undergo an annual background check (if you have the budget for it).




