Reporters' phone records hacked in HP hunt

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

The personal telephone records of two CNET News.com reporters were accessed by a contractor hired by HP to uncover the source of boardroom leaks to the media, according to the California attorney general's office.

The investigation conducted by a company hired by HP used a controversial technique called "pretexting" to obtain the personal phone records of reporters Dawn Kawamoto and Tom Krazit, of ZDNET UK's sister site, CNET News.com, state prosecutors said. Pretexting is a sometimes-illegal method of obtaining personal records through misrepresentation of someone's identity.

Kawamoto and Krazit co-wrote a 23 January article outlining a private, long-term strategy session held by HP's board of directors. The article, which quoted an unnamed source at length, prompted HP chairman Patricia Dunn to authorise an investigation into HP's board to determine the identity of the story's source.

Kawamoto and Krazit were apparently not the only reporters targeted by HP's investigators. The personal phone records of nine journalists, including a reporter from The Wall Street Journal, were accessed, HP spokesman Mike Moeller said late on Thursday afternoon. He declined to comment on the timeframe over which the incidents took place or any of the organisations other than the Journal and CNET News.com.

The Journal reported on its Web site that reporter Pui-Wing Tam was targeted. Among other HP stories, Tam wrote in January 2005 about the board's unhappiness with ex-chief executive Carly Fiorina.

The California attorney general's office on Tuesday first alerted reporters at News.com and possibly elsewhere that their private phone records may have been accessed. On Wednesday night, attorneys for HP supplied to the attorney general's office a partial list of reporters' names whose phone records may have been compromised, a prosecutor said.

On Thursday, an investigator with the attorney general's office contacted Kawamoto and said AT&T confirmed that her records had, indeed, been accessed. Kawamoto said she never authorised her home phone records to be shared with anyone, and she noted her home phone number is under her husband's name, not her own. Krazit was notified later on Thursday that a similar breach had occurred with his mobile phone account.

The attorney general's office said HP's attorney is asking for permission to contact reporters whose records were apparently accessed.

"HP is dismayed that the phone records of journalists were accessed without their knowledge and we are fully co-operating with the attorney general in his investigation," HP's Moeller said.

In a filing on Wednesday with the Securities and Exchange Commission, HP acknowledged that the pretexting technique was used to obtain the personal records of board member Tom Perkins.

The SEC filing also said that in conjunction with the leak investigation, longtime board member George Keyworth will not be nominated to another term on the board. At a board meeting in May, Dunn presented the results of the investigation and revealed that Keyworth was the source of the leaks, which he acknowledged, according to the filing. Keyworth was asked by the board to resign at that meeting but refused, leading to the board's decision.

The filing made no mention of reporters' personal records.

AT&T confirmed to Perkins that someone had used two different Yahoo email addresses to gain entry to his records, according to documents made public on Wednesday. The person who gained access to Perkins' records created an online account with Perkins' telephone number and the last four digits of his Social Security number. It's unclear how they obtained his Social Security number.

Whoever gained access to the records only looked at Perkins' January bill, the month the News.com article that angered Dunn was published. Perkins resigned from the HP board in May to protest the internal investigation and the way it was handled.

"I resigned solely to protest the questionable ethics and the dubious legality of the chairman's methods," Perkins wrote in a letter to the board of directors.

In Kawamoto's case, AT&T said that on 30 January, someone used the last four digits of her husband's Social Security number to establish an online account, and provided the email address red@yahoo.com.

"As was the case with the Perkins account," AT&T general attorney Travis Dodd wrote in an email to the attorney general's office, "the IP address associated with the browser of the person who established the account was 68.99.17.80. As was also the case with the Perkins account, this appears to have been the only date of access to the account."

Details regarding Krazit's phone records were not immediately available.

Given the recent increase in the Federal Government's attempts to discover the identity of confidential sources, it's not all that shocking that corporations would feel "empowered" to try the same kind of techniques, said Christine Tatum, president of the Society of Professional Journalists and a business writer for the Denver Post.

However, "people have to realise that these are not issues that just journalists have to concern themselves with", Tatum said. Pretexting is a very common practice, and it's troubling to think that companies could use these techniques against disgruntled customers or debtors, she said.

CNET News.com's Tom Krazit contributed to this report.

Talkback

Both HP and the phone company deserve a severe reprimand if not prosecution in this instance.
Firstly, doesn't the US have a data protection act (as the UK does) which makes it illegal to impersonate another individual in order to obtain personal information. Are HP's directors being prosecuted?
Secondly, why is the telephone system so insecure that all you need is knowledge of the phone number and part of the social security number to gain online access to the account. This is not secure - look up the person in the phone book, then do a SSN search (as an employer) to get the SSN of that person, then you can access the records.
In this day and age I would expect a minimum of identity checking before the phone company gives out personal data. All the phone company needs to do is ask for the date of the last bill and the amount to ensure the attempted access is at least from someone with sight of the last bill. This is trivial security. By not applying such basic checks before releasing personal information, a UK company would be breaking the law. Is the US so far behind?

via Facebook 8 September, 2006 11:08
Reply

I think they dost protest too much.....

Journalists can be pretty cavalier when it comes to privacy of others. Take the recent behaviour of the News of the World reporters bugging the telephones of various members of the Royal Family.

This doesn't make whats happened right of course, just if jounalists spy and bribe to get information they should expect to suffer the same fate.

via Facebook 8 September, 2006 12:25
Reply

surely this is illegal on many levels, a global corporation accessing the mobile phone records of unsuspecting individuals, its not even as if they were company issued phones, does this mean that anyone associated with media needs to expect a call from HP from now on telling them that there phone has been watched by them for the pass 9 months? when we take out contracts or talk plans with operators we expect our history to be kept safe and secure, after al thats what the data protection act was for, now how is it, i cant order a new top up card without answering various questions and confirming my dob and address,yet HP can gather all they need without that, or do they have refuse collectors on the payrole as well now, delivering fresh supplies of person information ready for the data vultures and office monkeys at HP, HP once a trusted brand now the symbol of a tarnished brand that will have to do more than perform a few wonders and memory erase's to get any of their much desired reputation back, unless of course their happy with the new one? from what i can gather from various blogs and internet surfing this isnt the first occurance either, how many other companys outthere are doing similar things, we know about sony and the data protection fieasco on their disks, and many other drm cases. will HP and the pedigree office monkeys face any charges for this - i hope so, nothing short of good old slap with a wet fish will do! i apologise if i have confused or bored you in any way, not that i care really, but i didnt force you to read it did i?.....

via Facebook 20 September, 2006 23:34
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

BrownieBoy

@Jack, > Works really well for thieves.... Nice attempt to deflect the argument by tossing in a point that's totally irrelevant, even it were...

8 hours ago by BrownieBoy on AMD Ultrathins to challenge Intel Ultrabooks
bootlegger

Make that 13 people now - I got refused today at Manchester airport. I thought I was up to date on this legislation - I knew of the EU ruling from...

11 hours ago by bootlegger on UK airport body scans will not be opt out
tinycg

Don't forget to check out apps like GoodReader or SlideShark either, they're indispensible for people on the go in presentation situations. Best...

13 hours ago by tinycg on Four top iPad apps for people on the move
TerryRK

Well it seems there is something a number of us agree on. Why is the Ubuntu Unity launcher so ugly? I thought perhaps it was something to do with...

18 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

1 day ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

2 days ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

2 days ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

2 days ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

2 days ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

2 days ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

2 days ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint