eWeek Security Watch
Advertisement
Advertisement
April 23, 2008 12:28 PM

LendingTree Warns of Insider Password Heist



Credit Card Theft LendingTree, an IAC subsidiary that connects online borrowers with mortgage, credit card and auto loans, has suffered a major insider breach that exposed sensitive user files to lenders.

The company sent out e-mails to customers affected by the breach, warning that "several former employees may have taken Company passwords and given them to a handful of lenders."

LendingTree identified three lenders that received the stolen data and said lawsuits have been filed. The lenders are Newport Lending Group, of Irvine, Calif.; Home Loan Consultants Inc., of Newport Beach, Calif.; and Sage Credit Co., of Irvine, Calif.

The company did not say when the password heist occurred or how many customers were affected.

From a FAQ posted on the LendingTree Web site:

These lenders then used the passwords to access LendingTree customer information files, normally available only to LendingTree-approved lenders, to market loans to LendingTree's customers. The files contained loan request data such as name, address, email address, telephone number, Social Security number, income and employment information.

The company said no credit card information (account numbers or account balances) were involved in the data hijack.

"We have no evidence that any identity theft or consumer fraud has resulted from this situation," according to the LendingTree FAQ.

As StillSecure's Alan Shimel points out, this looks and smells like big-time corporate espionage.

* Photo credit: d70focus (Creative Commons 2.0).

Create, Communicate, Collaborate with IT Professionals at Ziff Davis Enterprise IT Link

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/13392

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise