()

()

Malware: How an accountant’s computer might unknowingly have revealed clients’ financial data

SEQUIM — The owner of a local computer repair company is warning area accountants to be vigilant against a digital thief capable of stealing sensitive information about their clients.

“We need to be aware of this,” said Jim Manderscheid, vice president and co-owner of Quality Assured Computer Services at 680 W. Washington St., Suite B-101.

“And I don’t care who is working on their computers, just as long as their customers are safe.”

Manderscheid discovered malicious software, or malware, in late March while providing routine services on a computer belonging to a local accountant.

He encourages area residents to question their certified public accountants about their security status.

“Go to your CPA and have them give you some sort of verification that they have a clean bill of health” and are “scanning their computers daily or weekly,” he said.

And if an accountants discovers they have been hacked, they should notify their customers and law enforcement immediately, Manderscheid added.

Malware is software used to disrupt computer operations, gather sensitive information, or gain access to private computer systems.

While servicing the computer last month, “what I found was disturbing, especially during tax season.” Manderscheid said.

“I found a single, serious malware tool hiding, embedded in the system” known as “MSIL.HackTool.IdleKMS.”

“This may have been a spurious or accidental infection that may be just bad luck,” Manderscheid said.

“But since it was just one malware specific to information harvesting, it was probably done with malicious intent.”

One possible avenue of invasion “would be to introduce it into your computer via a flash drive file,” Manderscheid speculated.

“Or they have set up an account with you and are sending you an email. And on that email you were looking at a QuickBooks file, or some sort of financial file, and that came onto your system.”

After being installed on a targeted computer, MSIL.HackTool.IdleKMS — also known as Trojan.Win32.IdleKMS.deinuh Artemis!1FADEE024CBE Suspicious_Gen4.FTGGO — proceeds quietly with its purpose of collecting sensitive financial information including social security numbers, birthdays and addresses.

It is probably more damaging than simply having a person’s debit or credit card information stolen, Manderscheid said.

“If it happens, it can be a very catastrophic event for the customer base.”

The malware is used in a way “similar to keystroke loggers, [which] keep track of keys pressed and transmits the data to a hacker, who can then use this information to access password-protected accounts, or to spread malware, or viruses, or perpetrate identity theft,” Manderscheid said.

“If this hack has been exploited, then all data on the CPA’s computer has been compromised. This is similar to the [recent] hacking of Target, Home Depot, Chase, and others. But since these large corporations have stepped up their security measures, it has become harder for the hackers to break in.”

That has made smaller businesses with less resources for digital security an appealing target.

“Most likely there is a computer, or relay of computers, that harvest all the information slowly over time so as not to be detected,” Manderscheid said.

“Not being detected while executing its main objective is the primary role of malware.”

The best way to defend against the malware is to prevent it from installing in the first place through the use of anti-virus software that is updated and operating correctly, Manderscheid said.

And folks should be skeptical about downloading or opening files embedded in emails, even from people they know.

For more tips about how to avoid malware infection, go online to http://tinyurl.com/PDN-Protect.

________

Sequim-Dungeness Valley Editor Chris McDaniel can be reached at 360-681-2390, ext. 5052, cmcdaniel@peninsuladailynews.com.

More in News

Sue Long, left, Vicki Bennett and Frank Handler, all from Port Townsend, volunteer at the Martin Luther King Day of Service beach restoration on Monday at Fort Worden State Park. The activity took place on Knapp Circle near the Point Wilson Lighthouse. Sixty-four volunteers participated in the removal of non-native beach grasses. (Steve Mullensky/for Peninsula Daily News)
Work party

Sue Long, left, Vicki Bennett and Frank Handler, all from Port Townsend,… Continue reading

Portion of bridge to be replaced

Tribe: Wooden truss at railroad park deteriorating

Kingsya Omega, left, and Ben Wilson settle into a hand-holding exercise. (Aliko Weste)
Process undermines ‘Black brute’ narrative

Port Townsend company’s second film shot in Hawaii

Jefferson PUD to replace water main in Coyle

Jefferson PUD commissioners awarded a $1.3 million construction contract… Continue reading

Scott Mauk.
Chimacum superintendent receives national award

Chimacum School District Superintendent Scott Mauk has received the National… Continue reading

Hood Canal Coordinating Council meeting canceled

The annual meeting of the Hood Canal Coordinating Council, scheduled… Continue reading

Bruce Murray, left, and Ralph Parsons hang a cloth exhibition in the rotunda of the old Clallam County Courthouse on Friday in Port Angeles. The North Olympic History Center exhibit tells the story of the post office past and present across Clallam County. The display will be open until early February, when it will be relocated to the Sequim City Hall followed by stops on the West End. The project was made possible due to a grant from the Clallam County Heritage Advisory Board. (Dave Logan/for Peninsula Daily News)
Post office past and present

Bruce Murray, left, and Ralph Parsons hang a cloth exhibition in the… Continue reading

This agave grew from the size of a baseball in the 1990s to the height of Isobel Johnston’s roof in 2020. She saw it bloom in 2023. Following her death last year, Clallam County Fire District 3 commissioners, who purchased the property on Fifth Avenue in 2015, agreed to sell it to support the building of a new Carlsborg fire station. (Matthew Nash/Olympic Peninsula News Group file)
Fire district to sell property known for its Sequim agave plant

Sale proceeds may support new Carlsborg station project

As part of Olympic Theatre Arts’ energy renovation upgrade project, new lighting has been installed, including on the Elaine and Robert Caldwell Main Stage that allows for new and improved effects. (Olympic Theatre Arts)
Olympic Theatre Arts remodels its building

New roof, LED lights, HVAC throughout

Weekly flight operations scheduled

Field carrier landing practice operations will be conducted for aircraft… Continue reading

Workers from Van Ness Construction in Port Hadlock, one holding a grade rod with a laser pointer, left, and another driving the backhoe, scrape dirt for a new sidewalk of civic improvements at Walker and Washington streets in Port Townsend on Thursday. The sidewalks will be poured in early February and extend down the hill on Washington Street and along Walker Street next to the pickle ball courts. (Steve Mullensky/for Peninsula Daily News)
Sidewalk setup

Workers from Van Ness Construction in Port Hadlock, one holding a grade… Continue reading