Security Market Segment LS
Friday, 02 March 2018 09:41

UpGuard silent on why it pulled Capital One breach claims


Security firm UpGuard is remaining silent about the removal of a blog post from its website wherein it was claimed that a cloud-based data storage repository, used by business analytics software provider Birst, was left unsecured, resulting in data about financial services firm Capital One, among others, being exposed.

All that the site says is, "This post is currently unavailable. For any press inquiries, contact us at". It has had that legend since Thursday morning.

Dan Barnhardt, a spokesman for Infor, the parent company of Birst which provides analytics for Capital One, wrote to iTWire today and said that the original story was based on a false premise and requested its removal. Given that UpGuard has not backed up its claims, iTWire has taken down the original story.

Barnhardt said: "A Birst employee placed a copy of certain non-production components of the Birst software in a publicly-available S3 bucket to provide a prospective customer in the financial services industry non-production, read-only access to the software (a proof-of-concept).

"These components were not populated with data; no data from the financial institution was ever present in the test environment at any time, although the filename contained the name of the financial institution.

"Under Birst standard procedures, these software components should have been set up for distribution with authentication and access control enabled, but in this case was not.

"There was no 'data breach' or 'data leak' because at no time were any data, credentials, or configuration information from the financial institution compromised. Nevertheless, upon receiving notice in January, Birst immediately removed and disabled access to the Amazon S3 file.

"Because the premise of the article is based on factual inaccuracies, we ask that you remove it as UpGuard has done with the source blog post."

The UpGuard report claimed that Birst’s private encryption keys plus administrative credentials and passwords assigned by Birst to Capital One were found in the exposed S3 bucket.

In a statement to Gizmodo, Barnhardt confirmed that a Birst employee uploaded the software to the unsecured Amazon server.

UpGuard pulled its blog post from the Web soon after Capital One reacted to the original story on Thursday and said the claims were untrue.

iTWire's original story was based on UpGuard's claims; feedback sent by Capital One was incoporated into the story.

UpGuard was then contacted for comment but the company did not respond. 

A second contact was initiated this morning but thus far (midday AEDT Friday) UpGuard has stayed silent. Capital One did not respond to a request for comment either.

UpGuard has released several similar breach reports before this, many of which iTWire has reported on. There has been no denial of any of these claims.

WEBINAR event: IT Alerting Best Practices 27 MAY 2PM AEST

LogicMonitor, the cloud-based IT infrastructure monitoring and intelligence platform, is hosting an online event at 2PM on May 27th aimed at educating IT administrators, managers and leaders about IT and network alerts.

This free webinar will share best practices for setting network alerts, negating alert fatigue, optimising an alerting strategy and proactive monitoring.

The event will start at 2pm AEST. Topics will include:

- Setting alert routing and thresholds

- Avoiding alert and email overload

- Learning from missed alerts

- Managing downtime effectively

The webinar will run for approximately one hour. Recordings will be made available to anyone who registers but cannot make the live event.



Security requirements such as confidentiality, integrity and authentication have become mandatory in most industries.

Data encryption methods previously used only by military and intelligence services have become common practice in all data transfer networks across all platforms, in all industries where information is sensitive and vital (financial and government institutions, critical infrastructure, data centres, and service providers).

Get the full details on Layer-1 encryption solutions straight from PacketLight’s optical networks experts.

This white paper titled, “When 1% of the Light Equals 100% of the Information” is a must read for anyone within the fiber optics, cybersecurity or related industry sectors.

To access click Download here.


Sam Varghese

website statistics

Sam Varghese has been writing for iTWire since 2006, a year after the site came into existence. For nearly a decade thereafter, he wrote mostly about free and open source software, based on his own use of this genre of software. Since May 2016, he has been writing across many areas of technology. He has been a journalist for nearly 40 years in India (Indian Express and Deccan Herald), the UAE (Khaleej Times) and Australia (Daily Commercial News (now defunct) and The Age). His personal blog is titled Irregular Expression.



Recent Comments