09 Nov 2007
Salesforce.com has admitted that its customer database has been breached after a member of its staff fell for a phishing scam.
"A Salesforce.com employee had been the victim of a phishing scam that allowed a customer contact list to be copied," said a letter from the company.
Salesforce.com, which has almost one million subscribers, admitted that the stolen data included first and last names, company names, email addresses, telephone numbers and related admin data.
The letter told customers to be aware that they were likely to be targeted by further attacks, including viruses and key-logging software, and asked them to be vigilant against bogus invoices that appear to come from the company.
"Unfortunately, one of the company's employees appears to have fallen for the phishing emails and inadvertently handed over access to the firm's customer database," said Geoff Sweeney, chief technology officer at behavioural analysis company Tier-3.
"As if that wasn't bad enough, Salesforce.com has reportedly tracked a second wave of forged emails that contain malware.
"The fact that the emails are addressed to specific customers and purport to come from Salesforce.com means that the chances of a customer's PC being infected are quite high."
Latest stories from Web
Related articles
Related jobs
Poll
What will be the biggest change to corporate technology in the future?
TFL director of Games transport Mark Evers discusses how the public transport network is preparing for this summer's event
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
Head of Compliance My client is currently seeking...
THis role is working for a multi national Financial organisation...
Professional Services Consultant - Data Protection, Backup...
Web Support Analyst (Drupal, Joomla or Wordpress, CMS...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
on screen keyboard
i understand that by using the on screen keyboard when keying in sensitive data such as credit card numbers and bank details on known good sites is one way of defeating phishing, and of being wary of all incoming emails...
Posted by: len eyre 27 Nov 2007