Tiversa
   HOME

TheInfoList



OR:

Tiversa was an American
cybersecurity Computer security (also cybersecurity, digital security, or information technology (IT) security) is a subdiscipline within the field of information security. It consists of the protection of computer software, systems and networks from thr ...
firm headquartered in
Pittsburgh Pittsburgh ( ) is a city in Allegheny County, Pennsylvania, United States, and its county seat. It is the List of municipalities in Pennsylvania#Municipalities, second-most populous city in Pennsylvania (after Philadelphia) and the List of Un ...
, Pennsylvania. It was founded by a retired chiropractor and real estate entrepreneur named Robert Boback in 2004. The company specialized in trawling the
deep web The deep web, invisible web, or hidden web are parts of the World Wide Web whose contents are not indexed by standard web search-engine programs. This is in contrast to the " surface web", which is accessible to anyone using the Internet. Co ...
, investigating
peer-to-peer network Peer-to-peer (P2P) computing or networking is a distributed application Distributed computing is a field of computer science that studies distributed systems, defined as computer systems whose inter-communicating components are located on d ...
s, and helping businesses counteract data breaches and other cybersecurity risks. Its main product was EagleVision X1, a piece of software that monitored the deep web -- the parts of the Internet that are not easily accessible to general browsers, such as peer-to-peer networks -- for sensitive data.


History

Before entering the cybersecurity field, Boback was a chiropractor and real estate entrepreneur. He started Tiversa in 2004 as a two-person shop. Tiversa quickly obtained a high-profile board of advisers, including
Maynard Webb Maynard G. Webb Jr. (born 1955) is an American business person and is the author of the ''New York Times'' bestseller ''Rebooting Work: Transform How You Work in the Age of Entrepreneurship'', and the national bestseller ''Dear Founder: Letters of ...
(former eBay executive and chairman of Yahoo),
Howard Schmidt Howard Anthony Schmidt (October 5, 1949 – March 2, 2017) was a partner with Tom Ridge in Ridge Schmidt Cyber LLC, a consultancy company in the field of cybersecurity. He was the Cyber-Security Coordinator of the Obama Administration, operating in ...
(
Obama Barack Hussein Obama II (born August 4, 1961) is an American politician who was the 44th president of the United States from 2009 to 2017. A member of the Democratic Party, he was the first African American president in American history. Ob ...
-era cybersecurity chief), and
Wesley Clark Wesley Kanne Clark (born Wesley J. Kanne, 23 December 1944) is a retired United States Army officer. He graduated as valedictorian of the class of 1966 at United States Military Academy, West Point and was awarded a Rhodes Scholarship to the U ...
(former
Supreme Allied Commander Supreme Allied Commander is the title held by the most senior commander within certain multinational military alliances. It originated as a term used by the Allies during World War I, and is currently used only within NATO for Supreme Allied Co ...
of
NATO The North Atlantic Treaty Organization (NATO ; , OTAN), also called the North Atlantic Alliance, is an intergovernmental organization, intergovernmental Transnationalism, transnational military alliance of 32 Member states of NATO, member s ...
).


Marine One hack

In 2009, Tiversa claimed to have discovered a major security breach involving then-President
Barack Obama Barack Hussein Obama II (born August 4, 1961) is an American politician who was the 44th president of the United States from 2009 to 2017. A member of the Democratic Party, he was the first African American president in American history. O ...
's helicopter,
Marine One Marine One is the call sign of any United States Marine Corps aircraft carrying the president of the United States. As of 2024, it is most frequently applied to a presidential transport helicopter operated by Marine Helicopter Squadron One (HMX ...
. The breach involved the leak to
Iran Iran, officially the Islamic Republic of Iran (IRI) and also known as Persia, is a country in West Asia. It borders Iraq to the west, Turkey, Azerbaijan, and Armenia to the northwest, the Caspian Sea to the north, Turkmenistan to the nort ...
of sensitive procurement information about the helicopter as well as the helicopter's blueprints. According to Tiversa's CEO, the breach was caused by a defense contractor employee whose daughter downloaded a peer-to-peer file-sharing client onto a disused laptop which contained the sensitive materials. This discovery made national news, but a
whistleblower Whistleblowing (also whistle-blowing or whistle blowing) is the activity of a person, often an employee, revealing information about activity within a private or public organization that is deemed illegal, immoral, illicit, unsafe, unethical or ...
later claimed that the Iranian hack was actually fabricated by Tiversa employees. Boback, the CEO of Tiversa, denied the allegation.


LabMD scandal

In May 2008, a Tiversa executive contacted LabMD (a urology testing laboratory) claiming to have discovered evidence of a major data breach and offered to sell LabMD monitoring services to counteract the breach. When the head of LabMD declined to purchase the monitoring services, Tiversa allegedly leaked information about the breach to the U.S.
Federal Trade Commission The Federal Trade Commission (FTC) is an independent agency of the United States government whose principal mission is the enforcement of civil (non-criminal) United States antitrust law, antitrust law and the promotion of consumer protection. It ...
, which pursues cybersecurity issues. The FTC launched a probe into LabMD's practices under section 5 of the Federal Trade Commission Act in 2010, which evolved into a formal administrative complaint in 2013. LabMD's revenues fell and the business itself collapsed in 2014 as clients declined renewal contracts and partners ended their agreements. However, in November 2014, an administrative law judge threw out the complaint against LabMD, citing a lack of reliability in the evidence provided by Tiversa to the FTC. This stemmed from a whistleblower complaint by a former Tiversa employee, Richard Wallace, who claimed that he was the one who breached LabMD's systems and that LabMD's data was never leaked outside of its network. He also alleged that Tiversa was responsible for the FTC complaint against LabMD, which was made in retaliation for LabMD's refusal to purchase Tiversa's monitoring services. In sworn testimony, Wallace admitted to fabricating data to instill fear of breaches against "probably every company we've ever done business with".


Federal probe

Following Wallace's whistleblower complaint, the federal government began probing Tiversa under allegations that it deliberately provided false information about data breaches to the FTC to retaliate against companies that declined to purchase its data protection services. The
Department of Justice A justice ministry, ministry of justice, or department of justice, is a ministry or other government agency in charge of the administration of justice. The ministry or department is often headed by a minister of justice (minister for justice in a ...
launched a criminal investigation in 2015 following the whistleblower complaint and the FTC also launched a probe of whether Tiversa had lied about any among the 80 companies that it had reported to them.


Corporate Armor acquisition

In August 2016, Tiversa acquired Corporate Armor, a US-based IT security provider.


Acquisition by Kroll Inc.

In June 2017, Tiversa was acquired by
Kroll Inc. Kroll (formerly Duff & Phelps) is a financial and risk advisory firm established in 1932 and based in New York City. In 2018, Kroll was acquired by Duff & Phelps. In 2021, Duff & Phelps decided to rebrand itself as Kroll, a process it completed i ...
and its employees were hired to maintain the Tiversa investigation systems. In January 2019, the system was still operational and a person in England reported via
Twitter Twitter, officially known as X since 2023, is an American microblogging and social networking service. It is one of the world's largest social media platforms and one of the most-visited websites. Users can share short text messages, image ...
: "Care to tell me why you are snooping my I.P. address?"


Prominent clients

*
Capital One Capital One Financial Corporation is an American bank holding company founded on July 21, 1994, and specializing in credit cards, auto loans, banking, and savings accounts, headquartered in Tysons, Virginia, with operations primarily in the ...
*
Lehman Brothers Lehman Brothers Inc. ( ) was an American global financial services firm founded in 1850. Before filing for bankruptcy in 2008, Lehman was the fourth-largest investment bank in the United States (behind Goldman Sachs, Morgan Stanley, and Merril ...
*
Goldman Sachs The Goldman Sachs Group, Inc. ( ) is an American multinational investment bank and financial services company. Founded in 1869, Goldman Sachs is headquartered in Lower Manhattan in New York City, with regional headquarters in many internationa ...
*
American Express American Express Company or Amex is an American bank holding company and multinational financial services corporation that specializes in payment card industry, payment cards. It is headquartered at 200 Vesey Street, also known as American Expr ...


References


External links

* {{Webarchive, url=https://web.archive.org/web/20180420200019/http://www.tiversa.com/, title=Official website, date=April 20, 2018 Data protection Security companies of the United States Computer security software companies Technology companies established in 2004 American companies established in 2004 Information technology companies of the United States Corporate crime