Thousands of user IDs stolen in Red Cross blood drive hack

By Tim Conneally | Published November 28, 2007, 5:11 PM

Over a two-week period, over 278,000 e-mail addresses of Red Cross workers were swiped by a malicious user who found a back-door into a certain brand of non-profit fundraising software.

Convio Inc., an Austin, Texas-based software company that exclusively serves the needs of non-profit groups, admitted today that its GetActive software had been hacked and user data from 92 groups were stolen between October 23 and November 1.

Apparently, an unauthorized user accessed the Red Cross database with a stolen employee password. Fortunately, no Social Security numbers or bank account information was stolen, but the Red Cross confirmed that 278,000 of its e-mail addresses and an unspecified smaller number of passwords were pilfered.

The Red Cross was running a blood drive site on Convio's GetActive software platform.

Convio serves some of the largest American non-profit organizations with its online fundraising, advocacy, and e-mail marketing software. Some notable clients include Children's Cancer Research Fund, Easter Seals, and Paralyzed Veterans of America.

Update ribbon (small)6:30 pm EST November 29, 2007 - A spokesperson for Convio which manufacturers the software at issue contacted BetaNews this afternoon to say that the e-mail IDs swiped from the Red Cross database belonged to newsletter subscribers, not Red Cross employees.

"The intruder hacked into the Convio system electronically and from a distance," wrote corporate communications director Tad Druart, "after electronically compromising the password of a Convio employee...We also notified our clients in less than 48 hours after identifying and shutting down the breach on November 1, 2007."

Comments

View comments by with a score of at least

"a malicious user"

Also known as Dracula. Crime solved.

Score: 0

|

Wow, lets blame the software for the stolen password, that makes sense. I have never used the software mentioned in the article, but pretty much any software on any platform is "vulnerable" to this type of "attack". 'Apparently, an unauthorized user accessed the Red Cross database with a stolen employee password.' I suppose if that password was a hardcoded programmer backdoor, as was unclearly implied above, then is is a vulnerability in the software. I am just not sure if that was what the article was saying.

Score: 0

|

Uh Oh! I always cringe when I read about a non-profit organization getting hacked or having a hard drive or notebook stolen! :( Since no SSN or bank information was taken, a bit of spam is much better than a stolen identity.

Score: 0

|

And this is a surprise? Win2003Server can be hacked by anyone with a brain and some ambition.

Score: 0

|

Convio also serves TechSoup, which provides very-low cost software to non-profits (like SBS 2003 Premium for $60). I received an email from TechSoup telling me about the situation and that email addresses for the mailing lists(and the passwords used to manage them) were stolen. http://blog.techsoup.org/node/188

Score: 0

|

Mark Russinovich on MinWin, the new core of Windows

The next version of Windows three years hence will likely build onto a significant architectural change implemented in Windows 7 and Server 2008 R2.

Security firm: Windows patches not responsible for 'Black Screen of Death'

On second thought, maybe that access control list thingie with the lockdown something-or-rather didn't trigger an alleged, perhaps non-existent, pandemic.

My Windows 7 confession (and why you should confess, too)

I've held back the real reason for sticking with Windows 7, even as, gulp, iLife calls me to go back to the Mac.

Apple settles with Psystar except for 'circumvention devices'

The fracas with the Florida clone computer maker might have ended today had Apple not have muddled the issue over a cheap piece of Psystar software.

Google begrudgingly adjusts news crawling for paid publishers

If publishers want to make readers pay for news content, and thereby drive down its popularity and Google ranking, the company says, they can just go right on ahead.

Fee or free? Murdoch, Huffington square off over the cost of Internet news

Participants in an FTC workshop yesterday witnessed the two extremes of the Web news publishing debate, still centered on the issue of long-term profitability.

Microsoft denies latest 'Black Screen of Death' claims

After an anti-malware producer announced a fix to what it says is a swarm of recent KSoD problems, evidence of the swarm itself has yet to turn up.

Latest Firefox 3.6 beta fixes 133 bugs, promises faster page load times

A once-sluggish beta testing process has kicked into overdrive, with astonishing success at finding serious bugs. Will Mozilla be able to fix all the others in time?

Confirmed: Office 2010 to ship in June

Two weeks after Microsoft had been expected to draw a clearer roadmap for its principal applications suite, it's finally ready to commit to the end of H1.

New EU antitrust commissioner will oversee Microsoft, Oracle+Sun, Intel issues

As one of Europe's most prominent politicians shifts positions in January, her replacement remains a question mark over technology's biggest issues.

Without its own 'iTablet' yet, is Apple missing the boat?

Steve Jobs is on record as dissing "single-purpose" devices like e-readers. But given their recent popularity, was that a mistake?