YOUR BUSINESS AUTHORITY

Springfield, MO

Log in Subscribe

Springfield Director of Information Systems Jeff Coiner says a 2012 hacker cost the city $35,000 in initial damage and prompted long-term security upgrades.
Springfield Director of Information Systems Jeff Coiner says a 2012 hacker cost the city $35,000 in initial damage and prompted long-term security upgrades.

Hacker's Playground: Security breaches threaten local businesses

Posted online
For Champions Committed to Kids Executive Director Randy Wright, defending against online hackers seems like a waste of money for an organization that helps children with chronic illnesses enjoy playing in a team environment.

But it has become a necessity for the nonprofit and many small businesses alike.

“We found out on our website that certain buttons would redirect you to other websites,” Wright said of a March 22 security breach at ChampionsCommittedToKids.com.

A quick fix the next day minimized the damage of CCK website visitors redirected to an undesirable destination. But costs will soon follow.

Wright said the initial work, done free of charge as a donation, was valued at $1,200, and board members would soon request bids on future information technology services.

The new business reality for CCK: “You pretty much have to invest in a good management system,” Wright said.

City breach
CCK is not alone. Others have learned firsthand the threat of hackers.

Springfield Information Systems Director Jeff Coiner didn’t know a hacker infiltrated city websites to publish personal information about job applicants in 2012 until an FBI tip put police on alert.

Coiner said IS staff was able to confirm the city had been victimized by a Structured Query Language injection attack, a technique on common code allowing hackers to control a Web application’s database server.

“There were about 2,000 Social Security numbers in the database that this person got access to,” he said. “We worked with the FBI and provided them with some information they requested, and eventually, they arrested the person who hacked the website.

“The reason a lot of hackers do that is they want recognition and they want to cause havoc for police departments or (government agencies), in general.”

As part of the response, the city paid for a year’s subscription of identity theft coverage for the roughly 2,100 people impacted, and the overall cost for shoring up the breach was roughly $35,000. The perpetrator was a man from Toledo, Ohio.

That event also factored heavily into the city’s move to outsource its Web hosting to Manhattan, Kan.-based CivicPlus. The service package costs about $20,000 a year, he said.

“It really made us think about how we could be more secure,” Coiner said.

The hacker approach
Marc Moyer, owner of Springfield-based IT support firm Cyberguard LLC, said there are a variety of ways hackers can hurt businesses and organizations, but more often than not, they are driven by a single motive.

“It’s really all about money. The image of the kid in the basement that is just doing it for a laugh – there’s not a lot of that,” he said.

Countries such as Russia, Ukraine and China are known to have organized cybercrime groups comprising teams of hackers to take over websites and computers, Moyer said. Common redirect destinations are pornography sites.

When hackers get individuals to go to their sites, Moyer said they track the users to their Web servers or where they go online.

“Through tracking, these teams can find personal financial information, which is really what they value,” he said. “The more people that click on their links, the more likely the hackers are to eventually secure someone’s personal information.”

That’s why hacking often seems so indiscriminate, he said. But websites can be targeted, too, as was the city of Springfield in 2012.

Another hacker approach to securing financial data is to pretend via email to be a trustworthy source in need of information, such as a bank representative updating an account.

“If someone wants to spoof your email, there’s not a ton you can do about it. The Internet, and especially email, is an inherently insecure medium,” Moyer said. “If you know what you’re doing, you can make yourself look like Bill Gates sending email out.”

Moyer recommends business owners and employees directly visit a website instead of clicking on an email link.

Otherwise fixes can be costly.

Moyer said Cyberguard’s basic security-essentials package starts at $249 per month.

According to the Kaseya 2016 Global MSP Pricing Survey, which last year gathered findings from owners and operators of nearly 400 managed service providers, 66 percent charge between $125 per month and $250 per month for server support and maintenance. The average size contract of monthly managed services ranged between $1,000 and $5,000 for 54 percent of respondents, while 34 percent charged below $1,000 per month.

White hats, black hats
Staying up-to-date with the latest software versions is an important and an easy security measure for businesses, said Scott Bratcher, director of technology at national marketing agency Marlin.

The company offers Web development, security patches and website hosting services for large and small clients alike. Bratcher declined to disclose for which customers and websites he provides services, but when it comes to larger firms, Marlin in Springfield has an advertising client list that includes Starbucks, Nestle and Unilever, according to Springfield Business Journal archives.

“The larger clients are more likely to have an enterprise site and enterprise solution,” Bratcher said, drawing a distinction from popular website platform WordPress, which he said is a common target of hackers. “These criminal organizations can set up scripts to just crawl the Internet and look for particular files that they know have a vulnerability in a WordPress website, and if they find a site that has not been updated, then it is easy for that script to exploit that in an outdated WordPress site and gain access they shouldn’t have.”

Bratcher said that doesn’t mean WordPress is necessarily more vulnerable than other sites or content management systems. Updates and security fixes are routinely available.

He also said password characters should be complex, and default user names such as “admin” should be changed.

Bratcher said custom-built or enterprise websites can have a security advantage just because they’re unique – known in the industry as “security by obscurity.”

Even custom sites can be breached by determined individuals, which is where adopting a criminal mindset is handy.

“With our larger clients, our job is to be proactive. There are situations where we work closely with the clients and sometimes outside consulting companies or individuals that we call in the industry white-hat hackers,” Bratcher said. “They use the same techniques and practices as black-hat hackers would use to gain malicious access to your Web property, yet they just reveal that vulnerability so it can be repaired.”

Comments

No comments on this story |
Please log in to add your comment
Editors' Pick
Fall 2026 Architects & Engineers Project Report

This installment of Springfield Business Journal’s Architects & Engineers Project Report showcases 26 endeavors by area design and engineering professionals.

Most Read
Update cookies preferences