CENTURY 21 Bay Properties - Bellingham
CENTURY 21 Bay Properties

Bellingham Real Estate - LOW TECH RISK - Trouble down the SOHO line…

Posted on September 24, 2008
CALL ME!

Call me, my life
Call me, call me, any, anytime
Call me, for a ride
Call me, call me for some overtime
Take me out, and show me off
Put me on the scene                Deborah Harry ~ Blondie ~ 1980

Tech-Risk We all mitigate it on many levels.  Internet, emails, firewalls, anti-virus, anti-spam, website defense...
 
But, allow me to take you down to what may be the lowest level in the tech protection pecking order pyramid. What's that you ask? The business owner themselves. People who have a SOHO. (Small Office / Home Office). Real estate brokers and agents...Small business owners and managers. You know, the folks that do their own honest best to keep their anti-virus updated and their operating system software updated, and smugly know about Nigerian 419 scams and the everyday stuff. More interested in preventing pop-ups, stopping spam emails, and blocking malicious websites than to worry about a gaping hole in their SOHO tech risk mitigation program. Ok - you deal with the internet stuff and computer stuff . OK? Have you thought about the telephone?  Ho hum Who'd be interested in hacking that? Who indeed.

Let me tell you about a friend of mine. (Smart, tech savvy, handsome, small business owner, and staff of 35 in two Bellingham locations, real estate brokerage services) All right you guessed it.....me.

He, correction, I just got off the phone with calls from the Fraud Departments of AT&T, MCI, Ameritell, Startech, and Qwest. Seems our little PBX voicemail system (that I thought was properly secured with pass codes and so forth) was garnering charges for calls from our seven business telecom lines to such exotic locales as India, the Philippines, Nepal, Liberia, Qatar, Eritrea, Senegal, Kenya, Pakistan, Saudi Arabia, and Afghanistan. Hacked to the an amount approaching $4,000 from 1:00 AM to about 7:00 AM on a Saturday morning in September... Ouch!

Symptoms: Incoming calls didn't ring at the reception station but the lines were lit! Staff thought it was a slow day with all the media hype on the Bellingham real estate meltdown, who could fault their logic?

Hack: Bad guys hacked a voicemail extension to call forward and auto-dial 1010 and international calling access codes and also set voicemail announcement to audibly say, "YES" at timed intervals to computer generated collect calls or third party billing authorizations. Clever buggers.

Duration of Attack: Under four hours on a Saturday morning.

The Fix: Vendor reset system, upgraded the software for the telecom hardware, new random generated pass codes, system audit, disallowed remote line access and setting changes.

Financial Ramifications? 

According to the FCC it is the responsibility of an individual or business to secure and maintain their telecommunications system (even if it is a single home phone.) Ergo, were responsible for paying the charges even though it is an outright determined fraud on our business.

According to our long distance provider (and the companies that have billed them) It's our responsibility to pay the charges on the bill even though they know we were compromised illegally. They have offered a 10% discount on the charges, which they say, is the cost they are being billed. Gee, thanks.

Current Action Plan?

  • Add ongoing telecom audit to security program.
  • Change pass codes regularly.
  • Keep upgrading security options on software and hardware for all systems.
  • Company Policy Revision No personalization of extensions on office telecom system.
  • Contact Department of Homeland Security (considering some of the call destinations)
  • Contact Sheriffs department.
  • Pay the bills.
  • Sell Bellingham real estate.
  • Move on.
It's a constant struggle, isn't it? Literally from the bottom of the pecking order to the top.

I'll end with a phrase I learned in 4 years of Latin class in school,

"Noli nothis permittere te terere!"

Comments Posted on "Bellingham Real Estate - LOW TECH RISK - Trouble down the SOHO line…"
1 Art Salazar
Posted January 3, 2009 3:57 PM

Karl,

I am sorry to hear that happened to you, I just can not believe such a thing could happen.

2 Tim Cornwell
Posted September 25, 2008 4:19 PM

Unbelievable!!! Thanks for the heads up. I just emailed my tech guy to make sure our iron curtain is up. Yikes!

Post a Comment on "Bellingham Real Estate - LOW TECH RISK - Trouble down the SOHO line…"
Name
Email
Website
Comment
CENTURY 21 Bay Properties
 
Semiahmoo Homes, Inc. dba CENTURY 21 Bay Properties - 8045 Birch Bay Drive Blaine, WA 98230 USA - 1313 East Maple, Suite 214 Bellingham, WA 98225
©2012 GraphicalData, Inc.   Site Map