KOKH FOX 25 News
Washington Guardian

FOX 25 SPECIAL REPORTS

Most news teams just scratch the surface, but Fox 25 Special Reports go beyond the headlines to give you the whole story.

Oklahoma Hacked: The Security Flaws That Put Your Information at Risk

Hackers are always working to get your money or your personal information.  You have undoubtedly seen the emails or received the phone calls that want you to give up details about your life or bank account.  Those hacking attacks don t stop even when you are at work; even if you work for the state.

I can't tell you how many times I ve seen that fishing scam where you get the notification your email inbox is full, said Alex Pettit, Oklahoma s Chief Information Officer. 

Pettit is in charge of the state s information technology, or IT, network.  Legislation a few years ago put his office in charge of consolidating the state s computer system and all the various IT departments. 

At first the consolidation began an agency at a time, but Pettit soon made an alarming discovery.  We'd found that many of the groups had not had very good security practices in place.  

Those security holes included missing anti-virus and anti-spam software to faulty firewalls.  In some cases agencies tried to cut corners on their budgets by not updating or not paying for virus protection.  In some cases we had agencies that were running freeware software for their virus protection, Pettit told Fox 25.  Or they had purchased virus protection software, but they had let the licensing lapse.

Those security mistakes were prominent within the Oklahoma Department of Tourism.  It was during consolidation that Pettit s team discovered hackers had managed to infiltrate computers used as cash registers at one tourism location.  Hackers installed malware designed to find and send out banking information.  Emails received by Fox 25 reveal there were multiple computers infected by malware at various Tourism locations.  However it appears only one computer had all the software needed to complete the invasive program.

Pettit says ultimately they only believe two people s personal information was compromised.  Though when asked if they are certain the breech only affected two individuals Pettit said, The direct answer to the question is we don't know what we don't know.

If you can't trust the folks you do business with then you're not going to do business with them.   Pettis says they cleared up the tourism security holes and moved immediately to make security solutions a priority for every agency regardless of if they had gone through the IT consolidation. 

However the problems do not end there.  It turns out the Tax Commission is also putting your personal information at risk because of its encryption procedures.  Potentially we have a vulnerability, Pettit said.

Right now when your tax records are sitting on the state server, or at rest, they are not encrypted.  While there are other security procedures in place to help block hackers, Pettit says encryption is a helpful final block against hackers.  We have different security protocols and what kind of remote access we allow, Pettit said. 

However the at rest data encryption is the same security flaw that hackers exploited in South Carolina.  The world learned of that hack in October of 2012.  Oklahoma was aware that just like South Carolina, all it takes is a careless employee to fall for a phishing scam and give out access codes to put records at risk. 

The hackers in South Carolina compromised nearly 4 million tax records, so you would think Oklahoma would be eager to prevent a similar attack.  Pettit wanted to move the tax records to a more secure server.  When that is accomplished all that data when it is at rest will be encrypted.

However the Tax Commission requested a delay in making their servers secure.  Pettit said the commission wanted the delay to get them through the busy tax season; a time when all Oklahomans are required by law to get their information in on time. 

The tax commission refused multiple requests for an interview on this subject saying they would not discuss security procedures.  However no one from the agency would answer questions about why they did not immediately move to ensure Oklahomans tax records were safe when hackers proved the same vulnerability could be exploited. 

Instead the agency released a statement that said they comply with the Internal Revenue Service s guidelines for security.  In addition the statement from communications director Paula Ross said, The agency also utilizes COBIT, the security standards used by the State of Oklahoma s State Auditor and Inspector as another primary source of security control guidance. Furthermore, for a number of years the OTC has hired a nationally-known security firm to conduct Network Penetration Audit and Vulnerability Assessments in addition to Internet and Dial-up Vulnerability Assessments.

Pettit says because state employees still have to do their jobs and work with sensitive data we will never be able to make our network hack proof.   However he says implementing standards for security will help make sure it is less likely information will be compromised. 

Still the biggest threat to the state s network is still out there.  The greatest vulnerability we have is from our own people.   Pettit said that is why education and practicing good security procedures is necessary to make sure mistakes do not happen.  Oklahoma Hacked: The Security Flaws That Put Your Information at Risk

Posted: Thursday, February 7 2013, 09:57 PM CST

NEWS TIPS

Full Name:
Street Address:
City:
State:
Email:
Daytime Phone:
Evening Phone:
Comments or Story Ideas:
Captcha:
Retype

You will be returned to the News page upon submission.
(Please only hit the submit button once.)

VIDEO LIST

FOX 25 TOP STORIES

  • FOX 25 News Features
  • Community Features
No Text Zone No Text Zone
Texting While Driving Kills Thousands of People Each Year. Many More are Seriously Injured. You Can Help Make Our Roads a “NO TEXT ZONE”.
Click Here for more info!
Newsroom - Health Care Reform Health Care Reform
The Supreme Court ruling to uphold the Affordable Care Act sparked a new battle. Check here daily for the latest developments, locally and across the country.
Click Here for more!
Washington Guardian Washington Guardian
The Washington Guardian is an online newspaper committed to providing watchdog journalism from the nation's capital aimed at safeguarding everyday Americans' tax dollars, security and freedoms.
Click Here for more!
KOKH FOX 25 :: Waste Watch Waste Watch
How are your tax dollars being spent? Waste Watch tracks whether local, state and federal governments or any groups are using your money wisely...or wasting it. !
Click here for more!
KOKH FOX25 :: Newsroom - Your Voice. Your Future. Your Voice. Your Future.
As the country faces challenges from federal budget issues to jobs and national debt, your voice is critical to the future.
Click Here for more!
KOKH FOX 25 :: Jaime's Favorite Things Jaime's Favorite Things
FOX 25's Jaime Cerreta reveals her favorite things in OKC Thursday nights on the Primetime News at Nine.
Click here for more!
KOKH FOX 25 :: Liz's Blog Liz's Blog
FOX 25's Liz Dueweke gives you the in-front-of-the-camera and behind-the-scenes lowdown from "Good Day Oklahoma"!
Click here for more!
KOKH FOX 25 :: Sports - High School Football High School Football
Check out your favorite highschool teams progress this football season.
Find your favorite team!
KOKH FOX 25 :: News Tips News Tips
If you see breaking news or have a news story you would like FOX25 to look into, give us your news tips.
Give Your Tip Now!
KOKH FOX 25 :: Oklahoma's Most Wanted Oklahoma's Most Wanted
Saturday night following "America's Most Wanted", Phyllis Williams profiles Oklahoma's Most Wanted.
It's your chance to take a bite out of crime!
KOKH FOX 25 :: Entertainment - Court Corner Blog Court Corner Blog
Judge Marilyn Milian answers important legal questions in the Court Corner Blog!
Click here for more!
Automotive Automotive
Find valuable information about buying your next car, including price quotes and your latest automotive news.
Click Here for More!
In the Loop In the Loop
Receive Life Advice from Leadin Experts, Share Music, videos and much more!
Click Here for Advice!
KOKH FOX 25 :: Community - Firehouse Favorites Firehouse Favorites
Watch Jeff George and Oklahoma firefighters as they whip up recipes and proudly present the official "Firehouse Favorites" cookbook!
Click Here for more!
Cash For Clunkers
The Federal government is giving away cash for clunkers!
Click here to find out more.
amber alert Wireless Amber Alerts
You can sing up to receive wireless Amber Alerts on your cell phone
Sign up today!
will rogers Will Rogers Airport Info
Get up to the minute flight information.
Just Click here!
stations tours Station Tour Information
Are you and your group interested in touring Oklahoma City's FOX & THE CW station?
Click here to submit your request.
sex offender Oklahoma Sex Offenders Database
Get public information on sex offenders in Oklahoma required to register pursuant to the Sex Offenders Registration.
Start Searching Now!

OKLAHOMA WEATHER

62°
web 7 day

From the FOX 25 First Forecast Center..

Good morning everyone...

Not expecting organized severe weather but showers and t'storms from time to time could hamper tornado relief efforts. ...

details

Business News

Bernanke signals Fed to maintain stimulus efforts

WASHINGTON (AP) -- Chairman Ben Bernanke is telling Congress that the U.S. job market remains weak and that it is too soon for the Federal Reserve to end its extraordinary stimulus programs.

more...

Consumer Info

BC-US--Dow Record-Three Personal Stories, 1st Ld-Writethru,1173
Dow Record: Three tales of ups, downs and changes
AP Photo FX102, FX103
Eds: With BC-US--Dow Record. Adds photos.
By SCOTT MAYEROWITZ
AP Business Writer
   NEW YORK (AP) -- When the Dow first crossed 14,000, investors were overjoyed. ...

more...

Science/Tech News

IN THE NEWS: TEEN ONLINE FAREWELL SONG ATTRACTS MILLIONS OF VIEWS

LAKELAND, Minn. (AP) -- High school student Zach Sobiech (SOH'-bee-eck) says he wanted to be remembered as "a kid who went down fighting and didn't really lose."

more...

Get This

SWINGERS CLUB LAWSUIT-VEGAS

LAS VEGAS (AP) -- David Cooper wants to bring a little more sin -- to Sin City.

more...

IE6 Float Fix