Menu
Browse

Cyber Incident Victim: Perspectives

Date:

Sep 2014

Location:

United States of America

Summary

Hackers exploited a vulnerability in the Perspectives website, compromising a database containing eCheck payment information and injecting unauthorized advertisements promoting abortion pills. The organization temporarily disabled payment processing during peak registration periods and treated accessed data as compromised despite no confirmed theft. Attackers likely used hidden ads to manipulate search engine rankings, though malvertising risks were also considered. The victim enhanced security protocols post-incident, including strengthening encryption, reconstructing databases, conducting regular vulnerability testing, and collaborating with law enforcement to identify perpetrators.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In September 2014, attackers exploited a vulnerability in the Perspectives religious education website, gaining unauthorized access to a database containing eCheck payment information for transactions. The breach was not discovered until months later, prompting the organization to temporarily disable payment processing options during spring registrations, one of its busiest operational periods. Intruders additionally published hidden advertisements for abortion pills on sections of the site, though these were not visible to regular visitors. Perspectives leadership speculated these ads were placed to manipulate search engine rankings for pages controlled by the attackers, though malvertising risks could not be ruled out. The organization acknowledged employing encryption standards comparable to major financial institutions for transmitting financial data but treated all accessed information as compromised despite finding no evidence of personal data theft.

Cyber Incident Image

The incident prompted Perspectives to implement enhanced security protocols, including increased encryption measures beyond previous levels and regular vulnerability testing. Immediate response actions involved reconstructing the production database to restore data integrity and collaborating with law enforcement to identify the perpetrators. Affected individuals who used eCheck payments were advised to consult their financial institutions regarding potential risks. Perspectives framed its post-breach measures as long-term operational changes focused on continuous security improvements rather than temporary fixes. The organization’s National Director, James Mason, publicly detailed these steps in customer communications while emphasizing the ongoing nature of the security enhancements.

Sources
Sources available to members
1 source