Retail News CRM

Tag: breach

  • Global Hotel Giant Booking.com Hit by Customer Data Breach: Is Your Information Safe?

    Global Hotel Giant Booking.com Hit by Customer Data Breach: Is Your Information Safe?

    Travel booking platform, Booking.com, recently experienced a data breach, potentially exposing user data to unauthorized individuals. This discovery was made following the observation of suspicious activities related to several reservations. The compromised data might consist of booking details, user names, email addresses, phone numbers, and other information shared by customers during their booking process.

    Despite the security breach, the Netherland-based company assured its users that their financial data and home addresses were not compromised. The company said, “We have dedicated teams and employ machine learning tools to monitor, detect, and block suspicious activity around the clock. We are continuously working to enhance the robust security measures we have in place.”

    Scale of the Breach

    Booking.com, being one of the largest hotel reservation platforms globally, did not reveal more information about the extent of the breach, including the number of users affected.

    There have been reports from some customers who claim to have received phishing messages through WhatsApp that contained their booking details and personal information. This suggests that the hackers could be using the stolen data to target Booking.com customers.

    In response to this issue, Booking.com took immediate action to contain the situation and issued new PINs to users with reservations. They also cautioned their customers to stay alert to suspicious emails or phone calls pretending to be from the properties or the platform itself. The company emphasized that they would never ask for credit card details through an email, phone call, text message, or WhatsApp.

    History of Cybersecurity Challenges

    The recent breach is one of many cybercrime attempts targeting Booking.com, which has been dealing with an increase in scams on its platform. Fraudsters, posing as legitimate entities, have been known to ask for payment details under the guise of pre-authorization or trip verification, leading to sizeable unauthorized charges.

    A similar incident happened in 2018 when attackers used phishing techniques to gain login credentials from hotel employees in the United Arab Emirates. This breach allowed them to access booking information of over 4,000 users on the platform.

    Despite these security challenges, Booking.com has recorded a high number of bookings. Since 2010, it has facilitated reservations for about 6.8 billion customers, making it one of the leading players in the travel and hospitality industry.

    Questions & Answers

    What kind of customer information was potentially exposed in the data breach?
    Email addresses, phone numbers, booking details, and any other information shared by the customers during the booking process might have been compromised.

    What steps has Booking.com taken in response to the data breach?
    Booking.com has issued new PINs to affected users and taken immediate action to contain the issue. They have also warned their customers to be wary of suspicious communication that could be impersonating the platform or associated properties.

    Has Booking.com experienced cybersecurity issues in the past?
    Yes, Booking.com has faced challenges with cybercrime in the past. For instance, in 2018, attackers used phishing techniques to access the booking information of more than 4,000 users on the platform.

  • Coupang’s Q4 Revenue Takes a Hit Following Major Data Breach: Analysts’ Insight and Predictions

    Coupang’s Q4 Revenue Takes a Hit Following Major Data Breach: Analysts’ Insight and Predictions

    E-commerce behemoth, Coupang, endured a significant blow following a data breach in South Korea, leading to a loss in its fourth quarter. The company’s profits plummeted and its revenue failed to meet analyst predictions, reflecting the extensive impact of the breach.

    Financial Impact

    Coupang Korea, responsible for over 90% of the group’s total revenue, experienced severe backlash after a data breach was revealed in November. This breach impacted nearly 34 million customers. The revenue for the company for the time frame of October-December was reported at $8.8 billion, falling short of the anticipated $8.9 billion. The fourth quarter saw Coupang spiral into a $26 million loss, compared to a profit in the same period the previous year, although its New York-listed shares did see a 1.9% increase.

    CFO Gaurav Anand spoke out in an earnings call, indicating that active customers in their product commerce sector increased by 8% from the previous year to 24.6 million in the fourth quarter. However, this was a reduction from the third quarter’s 24.7 million, a change likely due to the data breach.

    Anand stated that they have observed stabilization since Q4’s end, with numerous customers reactivating their accounts and customer growth trends improving. Despite this, he expressed that growth and profitability are expected to remain subdued in the coming months due to the ongoing consequences of the data breach, but he anticipates that this impact will gradually diminish over the year.

    Details of the Data Breach

    The data breach led to the exposure of users’ names, phone numbers, and shipping addresses. However, Coupang confirmed that login credentials and payment details remained secure. The company pledged to take all necessary steps to mitigate future damage and strengthen preventative measures to avoid another breach.

    The interim head of Coupang’s South Korean division, Harold Rogers, assured customers that the company has not found any misuse of customer data linked to the incident or evidence of any further harm. Rogers explained that the breach was the result of a targeted attack by a former employee who exploited their knowledge of Coupang’s systems.

    Despite these claims, South Korea’s Science Ministry attributed the breach not to a sophisticated cyberattack, but to management failures at Coupang. In the wake of the incident, competitor platforms have capitalized on Coupang’s struggles, enticing customers away from the platform.

    Regulatory Challenges

    Additionally, Coupang is contending with proposed regulatory changes that could intensify competition in ultra-fast overnight deliveries, a sector that has been crucial to its market leadership. In a separate incident, South Korea’s antitrust regulator imposed a 2.2 billion won (US$1.53 million) fine on Coupang for pressuring vendors to reduce prices and carry extra costs to meet profit targets and delaying payments to suppliers. This penalty is not directly related to the data breach.

    Questions & Answers

    What steps is Coupang taking post-data breach?
    Coupang pledges to take all necessary measures to mitigate further harm and strengthen safety measures to avoid recurrence of such breaches.

    What caused the data breach at Coupang?
    The breach was attributed to a targeted attack from a former employee who exploited inside knowledge of Coupang’s systems.

    How has the data breach impacted Coupang’s financial standing?
    As a result of the data breach, Coupang’s revenue fell below predicted values, and the company reported a loss of $26 million for the fourth quarter.

  • Woolworths Faces Potential New Zealand Regulatory Breach Amid Alleged Grocery Industry Competition Act Violations

    Woolworths Faces Potential New Zealand Regulatory Breach Amid Alleged Grocery Industry Competition Act Violations

    Woolworths, a prominent supermarket chain, has recently been cautioned about potentially violating the Grocery Industry Competition Act. This situation arose due to the delisting of certain products in its New Zealand branches.

    Grocery Industry Competition Act: Purpose and Management

    The Grocery Industry Competition Act is governed by the New Zealand Commerce Commission (NZCC). Its primary objective is to regulate the relationship between suppliers and supermarkets. By demanding greater transparency when products are delisted from store shelves, it seeks to protect the interests of smaller suppliers.

    The act, which was established in 2023, is expected to incorporate the Grocery Supply Code in May. Non-compliance with the code could lead to penalties, as per the statement from the commission.

    Investigation into Non-Compliance

    The NZCC has been scrutinizing the product-range review methods of leading supermarkets to ensure they are complying with the code.

    A spokesperson commented on the situation, saying, “Through this process, we identified and investigated situations where it appeared that Woolworths New Zealand might not be fulfilling its responsibilities.” Post investigation, Woolworths New Zealand was issued a warning for a probable breach of the Grocery Industry Competition Act. However, the spokesperson noted that only a court can establish whether an actual breach has occurred. Since the warning, Woolworths has amended its procedures to comply with the regulations.

    Impact on Groceries and Suppliers

    Alice Hume, the head of groceries at NZCC, stated that this action was taken in response to suppliers’ concerns. She highlighted the pressure on suppliers with the possibility of their products being delisted. This situation could further exacerbate the imbalance of power between major supermarkets and smaller suppliers.

    “The fear of losing market access can pressure suppliers into accepting unfavorable conditions and foster distrust towards supermarkets’ decision-making processes,” Hume explained. “The code is instrumental in equalizing the power dynamics between large supermarkets and smaller suppliers, so we treat compliance with the utmost seriousness.”

    Hume also mentioned that the NZCC continues to assess the product ranges available at supermarkets, inviting any worried suppliers to reach out to the commission.

    Questions & Answers

    What is the purpose of the Grocery Industry Competition Act?
    The Grocery Industry Competition Act is designed to govern the relationship between supermarkets and suppliers, with a demand for more transparency during product delisting to protect smaller suppliers.

    What are the consequences of breaching the Grocery Supply Code?
    Non-compliance with the Grocery Supply Code, which is part of the Grocery Industry Competition Act, can result in penalties.

    What are the concerns of the smaller suppliers?
    Smaller suppliers are concerned about potential product delisting, which could reinforce power imbalances with major supermarkets, pressurize them into accepting unfavorable conditions, and induce a lack of trust in supermarkets’ decision-making processes.

  • Coupang CEO Steps Down Amidst South Korea’s Largest Data Breach Scandal: Security Measures Revamped

    Coupang CEO Steps Down Amidst South Korea’s Largest Data Breach Scandal: Security Measures Revamped

    In light of a severe data breach, one of the most significant in South Korea’s history, Coupang Corp’s CEO, Park Dae-jun, has resigned. The cyberattack exposed the personal details of approximately 33.7 million customers, including their names, email addresses, phone numbers, shipping addresses, and certain order histories. However, payment details and login credentials were not compromised in the breach.

    Park’s Tenure and Resignation

    Park Dae-jun had been a part of Coupang Corp since 2012, ascending to the position of co-CEO in 2020, and subsequently becoming the sole CEO in May amid a company-wide leadership restructuring. Following the data breach incident, Park accepted responsibility for the breach and its handling, expressing his deep regret for letting down the public. He announced his decision to resign from all his positions within the company.

    In response to the significant breach, the e-commerce giant issued an apology, expressing deep regret for the anxiety caused by the data leak. The company pledged to work diligently to regain customer trust and strengthen security protocols to prevent future data breaches.

    Leadership Transition

    In the wake of Park’s resignation, Coupang Inc., Coupang Corp’s US-based parent company, has appointed Harold Rogers, the company’s chief administrative officer, as the interim CEO for the Korean branch.

    The appointment comes in the aftermath of one of South Korea’s most devastating data breaches, believed to have originated in June.

    South Korean Prime Minister Kim Min-seok announced earlier this week that the government would be investigating any possible legal violations made by the company. In response, police subsequently initiated a raid on the company’s office in Seoul.

    Under the new interim CEO, the company’s key focus will be on relieving customer anxiety, resolving the data breach issue both from within and outside the company, and restoring stability to the organization. The leadership transition signifies the parent company’s proactive approach to managing the fallout from the data leak incident.

    Questions & Answers

    Why did Coupang Corp’s CEO, Park Dae-jun, resign?
    Park Dae-jun resigned from his position due to a major data breach that exposed personal information of about 33.7 million customers.

    Who has been appointed as the interim CEO following Park’s resignation?
    Harold Rogers, the chief administrative officer of Coupang Inc., the US-based parent company of Coupang Corp, has been appointed as the interim CEO.

    What are the company’s plans following the data breach?
    The company has pledged to restore customer trust, enhance security measures, and focus on resolving the data breach issue, both internally and externally, under the new interim CEO.

  • Optus Faces Hefty $826K Fine Over Coles Mobile Scam Breach: A Deep Dive into Australia’s Telco Scandal

    Optus Faces Hefty $826K Fine Over Coles Mobile Scam Breach: A Deep Dive into Australia’s Telco Scandal

    Optus Mobile, a renowned telecommunications firm, has been hit with another hefty fine of $826,320 for breaching anti-scam regulations. This recent violation pertains to its business operations under the Coles Mobile brand.

    Investigation and Breaches

    The Australian Communications and Media Authority (ACMA) served the penalty after a thorough investigation into the infractions committed by Optus. The probe revealed that the company had infringed anti-scam provisions on 44 separate instances during September and October of the previous year. These infractions were carried out through Coles Mobile, a collaborative venture enabling consumers to register for a mobile contract via the Coles supermarket chain.

    Investigators unveiled that scammers had managed to exploit a security loophole in a third-party identity verification system employed by Optus. This loophole permitted the fraudsters to sidestep certain parts of the obligatory verification procedure. As a result, these unscrupulous individuals managed to seize control of a minimum of four client mobile services and infiltrate their bank accounts. The reported losses from these scam activities totalled $39,000.

    Implications and Responses

    Samantha Yorke, a member of the ACMA, conveyed the severity of such fraudulent activities. She highlighted the resultant monetary losses and lingering trauma emanating from the task of reclaiming digital identities. Yorke stated that although this was a solitary issue that was promptly addressed, the lack of a sturdy customer ID verification system is unacceptable. This holds particularly true for a prominent provider in the industry such as Optus, which is currently Australia’s second largest.

    Yorke also pointed out that the imposed fine is the maximum monetary penalty that the ACMA has the jurisdiction to enforce in this case. The severity of the fine reflects the seriousness of the breaches committed by Optus.

    The recent penalty adds to the already considerable financial repercussions that Optus has faced this year due to regulatory contraventions. Earlier in September, the firm was directed by the Federal Court to pay a staggering $100 million for engaging in unfair sales practices. These unethical practices affected over 400 customers and were carried out at 16 Optus outlets between August 2019 and July 2023.

    Questions & Answers

    What led to the recent $826,320 fine imposed on Optus Mobile?
    Optus Mobile was fined for breaching anti-scam regulations, specifically in relation to its business operations under the Coles Mobile brand.

    How were scammers able to exploit Optus’s systems?
    Scammers exploited a security loophole in a third-party identity verification system used by Optus, which allowed them to bypass parts of the obligatory verification process and gain control of several consumer mobile services.

    What were the consequences of the scam activities?
    The fraudulent activities resulted in reported losses of $39,000 and caused distress to consumers who had to recover their digital identities.

  • Spanish Retail Giant Mango Suffers Data Breach: Customer Marketing Data Compromised

    Spanish Retail Giant Mango Suffers Data Breach: Customer Marketing Data Compromised

    Mango, a global fashion retail corporation based in Spain, has recently announced a data breach. An external marketing service provider affiliated with the retailer experienced an unauthorized intrusion, compromising customer data.

    Details of the Data Breach

    On October 15, Mango informed its customers via email about the data breach incident. The breach compromised certain customer information used for marketing purposes. This included data such as first names, countries, postal codes, email addresses, and phone numbers.

    The company was quick to reassure customers that the breach did not involve financial information, passwords, or other identification details.

    Mango’s Response to the Breach

    Mango emphasized the continued security of its infrastructure and internal corporate systems. It also confirmed that the company’s operations are continuing uninterrupted.

    Upon learning about the breach, Mango immediately implemented all its security protocols. The company has also reported the issue to the Data Protection Agency and the Authorities, in accordance with current regulations and their internal protocol.

    As a precaution, Mango sent out a notice to its customers about the breach. It advised customers to be vigilant for suspicious emails or phone calls asking for personal information or prompting them to take unusual actions.

    Contacting Mango

    Clients who have any concerns about the breach can reach Mango’s customer service at [email protected]. Alternatively, they can make a direct phone call to +34 93 860 24 24.

    In closing, Mango expressed regret for the incident. The company conveyed their sincere apologies for any inconvenience caused by the situation.

    Questions & Answers

    What kind of customer data did the breach compromise?
    The breach compromised data used for marketing purposes, including customers’ first names, countries, postal codes, email addresses, and phone numbers.

    Did the breach involve any financial or identification information?
    No, the breach did not involve any financial information, passwords, or other identification details.

    What steps has Mango taken in response to the breach?
    Mango has implemented all its security protocols and reported the issue to the Data Protection Agency and the Authorities. The company has also advised customers to be alert for suspicious emails or phone calls.

  • Qantas Faces Cyberattack: Personal Data of Six Million Customers Breached in Major Security Incident

    Qantas Faces Cyberattack: Personal Data of Six Million Customers Breached in Major Security Incident

    In an alarming development, Australian airline Qantas has confirmed a significant data breach that has jeopardized the personal information of up to six million customers. This breach came to light following a cyberattack on a third-party customer service platform linked to a call center based in Manila, Philippines.

    A Shocking Vishing Attack

    The cyber intrusion, detected on June 30, involved a sophisticated form of voice phishing known as vishing, where malicious actors masquerade as trusted entities over phone calls to extract sensitive information from unsuspecting victims.

    Exposed Information and Assurances

    The compromised customer service platform housed a trove of personal data, including customers’ names, email addresses, phone numbers, birthdates, and frequent flyer numbers. However, Qantas has reassured customers that no financial information, credit card details, or passports were stored within the affected system. Additionally, the integrity of frequent flyer account credentials, passwords, and PINs remains intact.

    Robust Response and Investigation

    Operations and flight safety have not been compromised, as the airline emphasized. In response to this breach, Qantas has notified Australian intelligence agencies, including the Australian Cyber Security Centre, and law enforcement agencies such as the Australian Federal Police. The Office of the Australian Information Commissioner has also been apprised of the situation.

    To bolster customer assurance, the airline has initiated a comprehensive investigation and established a dedicated support line and website to keep affected customers updated. Those impacted will receive direct communication from the company.

    A Heartfelt Apology

    Qantas Group CEO Vanessa Hudson publicly addressed the situation, offering an apology to customers. “Our customers trust us with their personal information, and we take that responsibility seriously. We are contacting them directly and offering necessary support,” Hudson stated. It’s clear that trust, once broken, can be harder to mend than a wing on a seasoned aircraft.

    Questions & Answers

    What was the cause of the Qantas data breach?
    The breach stemmed from a cyberattack on a third-party customer service platform in the Philippines, involving a voice phishing scheme known as vishing.

    What type of personal information was compromised in the breach?
    The exposed information included customers’ names, emails, phone numbers, birthdates, and frequent flyer numbers, but no financial data or passwords were at risk.

    How is Qantas responding to the breach?
    Qantas has launched a full investigation and established a support line for customers while notifying relevant authorities and directly contacting affected individuals.

  • Louis Vuitton hit by massive Hong Kong data breach

    Louis Vuitton hit by massive Hong Kong data breach

    Louis Vuitton’s Hong Kong branch faces scrutiny following a significant data breach that may have left the personal details of approximately 419,000 customers exposed.

    Investigation Launched

    The luxury brand’s Hong Kong office reported a data breach to the Office of the Privacy Commissioner for Personal Data (PCPD) on July 17. This was over a month after the company’s French head office first identified suspicious activity on June 13. The PCPD confirmed receipt of the report the following day.

    The initial analysis indicates that the compromised data includes personal information such as names, passport numbers, birth dates, addresses, email addresses, phone numbers, and detailed customer transactions including purchase history and product preferences.

    Despite not yet receiving any complaints or inquiries about the incident, the PCPD announced that a formal investigation had been initiated. The investigation will follow established procedures and will also look into whether there was a delay in reporting the breach.

    Swift Response

    Louis Vuitton Hong Kong has confirmed that an unauthorized entity accessed its customer data. However, it promptly responded by launching an investigation into the issue and taking steps to contain the breach, bringing in external cybersecurity professionals for assistance.

    In a statement, the company clarified that no payment information was included in the accessed database. The company also stated: “While our investigation is ongoing, we can confirm that no payment information was contained in the database accessed.”

    Louis Vuitton further affirmed its commitment to enhancing its security systems and ensuring communication with both relevant regulatory bodies and affected customers. “We sincerely regret any concern or inconvenience this situation may cause,” the company added.

    The PCPD also confirmed that it has begun an investigation into the incident at Louis Vuitton Hong Kong, giving particular attention to whether the company reported the breach in a timely manner. The PCPD reiterated that it has yet to receive any relevant complaints or inquiries in relation to the issue.

    Questions & Answers

    What personal information was exposed in the data breach at Louis Vuitton Hong Kong?
    The compromised data includes personal details such as names, passport numbers, birth dates, addresses, email addresses, phone numbers, along with purchase history and product preferences.

    Has Louis Vuitton Hong Kong received any complaints or inquiries related to the data breach?
    As of the current report, no complaints or inquiries have been received in relation to the data breach.

    What measures has Louis Vuitton taken in response to the data breach?
    Louis Vuitton has launched an investigation with the help of external cybersecurity experts. It is also working on upgrading its security systems and has promised to keep regulators and affected individuals updated.

  • Louis Vuitton Korea Customer Data Breach: No Financial Details Compromised, Other Luxury Brands Under Investigation

    Louis Vuitton Korea Customer Data Breach: No Financial Details Compromised, Other Luxury Brands Under Investigation

    In June, Louis Vuitton Korea experienced a systems breach that resulted in the exposure of certain customer data, including contact information. However, the company’s South Korean division clarified last Friday that the breach did not compromise customers’ financial details.

    Unauthorized Access to Company System

    Regrettably, an unauthorized third party gained temporary access to the company’s system, leading to the leak of some client information. The company released a statement in response to the incident, expressing their concern and regret over the breach.

    The organization first became aware of the breach on Wednesday and promptly alerted the relevant government authorities. Additional measures are now in place to contain the situation and enhance the existing system security.

    Government Investigations Into Other Luxury Brands

    In related news, the South Korean divisions of two other major luxury brands are currently facing government investigations. Christian Dior Couture and Tiffany, both part of the world’s largest luxury group, are under investigation for customer data leaks they reported earlier in the year. The investigations were initiated by the Personal Information Protection Commission, South Korea’s main authority for data protection.

    Questions & Answers

    What type of data was leaked in the Louis Vuitton Korea’s system breach?
    Client contact information was exposed in the breach. However, no financial information was compromised.

    Who is investigating the data leaks at Christian Dior Couture and Tiffany?
    The Personal Information Protection Commission in South Korea is conducting the investigations into these two luxury brands’ reported data leaks.

    What measures has Louis Vuitton Korea taken in response to the breach?
    Following the breach, Louis Vuitton Korea took action to contain the situation and augment its system security. They also alerted the relevant government authorities about the breach.

  • UBS Faces Major Darknet Data Breach Exposing Personal Details of 130,000 Employees

    UBS Faces Major Darknet Data Breach Exposing Personal Details of 130,000 Employees

    A significant cybersecurity breach has rattled UBS, as sensitive data concerning 130,000 of its employees has surfaced on the darknet following a hacker attack on its procurement service provider. But UBS isn’t the only one feeling the heat from this incident.

    Chain IQ: The Breach Exposed

    The breach traces back to Chain IQ, a procurement service provider and former UBS spinoff, which has also served other prominent clients such as Pictet, Manor, and Implenia. The troubling news was first reported by the Swiss daily Le Temps, shedding light on a severe data theft that occurred in June.

    Among the leaked information are names, email addresses, landline numbers, and, in some instances, mobile numbers—one of which belongs to UBS CEO Sergio Ermotti. Other details include job levels, languages spoken, and office locations within the bank.

    Service Provider in the Spotlight

    Chain IQ, headquartered in Baar with additional offices in Geneva and Zurich, has established itself firmly in the procurement sector, delivering services that cover human resources, IT systems, waste management, and more.

    The Victorious Hacker’s List

    The data leak is not just a concern for UBS. Chain IQ’s client list is also up for grabs on the darknet; a troubling revelation. The firm has previously engaged with over 400 partners, and now exposed are the details of contracts, service types, and the internal contacts for each partner. Noteworthy clients include Pictet, insurance giants like Swiss Life and Axa, and global entities such as FedEx and IBM.

    UBS’s relationship with Chain IQ includes support in managing supply chain due diligence and company credit card administration. The leaked dataset spans 137,192 rows, each representing an employee.

    Darknet Deals and Criminal Risks

    Concerns escalate as reports confirm that the leaked file has been sold multiple times on the darknet. Such information poses a risk of being exploited for criminal activities, including identity theft and fraud.

    In response, Chain IQ is treating this situation with the utmost seriousness. The company has activated its security protocols, assembled a dedicated team of internal and external experts, and contacted the Zug cantonal police. They also aim for transparency, having informed all stakeholders promptly.

    A UBS spokesperson confirmed their awareness of the cyberattack on Chain IQ, assuring that they are monitoring the developments closely.

    Pictet’s Invoice Data Under Scrutiny

    In an additional twist, the leaked data allegedly includes information from Pictet, detailing “tens of thousands of invoices.” While the invoices themselves are not part of the leak, the records describe various expenditures by companies and employees, including groceries, dining, travel, and security services.

    A representative from Pictet stated that the compromised data does not include sensitive employee information or customer data, but mostly concerns invoice details from select suppliers. Precautionary measures are being implemented to mitigate further risks.

    As the world turns more digital, will we see a rise in such cyber capers, or can the industry step up its defenses to combat these digital bandits?

    Questions & Answers

    What type of data was leaked in the UBS incident? The data includes names, email addresses, phone numbers, and job-related details for 130,000 UBS employees.

    Which companies are involved in the breach? Chain IQ, former UBS spinoff, is the main service provider affected, alongside other clients like Pictet and Manor.

    What actions are being taken in response to the breach? Chain IQ has activated security protocols, mobilized a dedicated response team, and contacted law enforcement while keeping stakeholders informed.

  • Jollibee data breach may impact almost 11 million customers

    Jollibee data breach may impact almost 11 million customers

    Jollibee Foods Corporation (JFC) has reported a potential unauthorised access to its data, which might affect approximately 11 million customers.

    The breach compromised sensitive personal information, including dates of birth and senior citizen identification numbers, according to the company’s report to the Philippines’ National Privacy Commission (NPC).

    “Approximately 11 million data subjects are affected, the majority of whom are Jollibee customers,” the NPC said. “Other impacted brands include Mang Inasal, Red Ribbon, Chowking, Greenwich, Burger King, Yoshinoya, and Panda Express.”

    The company has requested an additional 20 days to complete its internal investigation.

    By law, companies processing personal data must notify the NPC and individual affected subjects within 72 hours of discovering a breach.

    JFC said that its e-commerce platforms, including its subsidiaries, were unaffected by the incident and remained operational.

    “JFC recognises the value and importance of the confidentiality of its stakeholders’ personal information,” said the company.

    “The company assures the public of its commitment to prioritise the protection and confidentiality of such personal information, including customer data, by continuously fortifying its defences against future threats,” it added.

  • Samsung allegedly fell victim to a data breach

    Samsung allegedly fell victim to a data breach

    There has been a new security breach in the tech industry. This time, the victim was reportedly Samsung Electronics. The hackers taking responsibility for the data breach are from the Lapsus$ hacking group. Lapsus$ has leaked around 190GB of what it claims to be confidential data from Samsung, which includes source code and biometric unlocking algorithms.

    As proof of the data breach, Lapsus$ has also provided a screenshot of C/C++ code directives, alleging that they came from Samsung. In a description of the 190GB of stolen data the hacking group teased before the big leak, they wrote that these 190GB contain “confidential Samsung source code” and listed exactly what the hacking group managed to steal from Samsung.

    With its hack, Lapsus$ got its hands on the source code for every Trusted Applet (TA) installed in Samsung’s TrustZone. Samsung TrustZone is a secure environment utilized for operations such as hardware cryptography, binary encryption, and access control.

    Lapsus$ also managed to steal algorithms for all biometric unlock operations, the source code used for booting all recent Samsung devices, and confidential source code allegedly originating from Qualcomm. With its attack, Lapsus$ also stole the source code for Samsung’s activation servers, аs well as that used for authorizing and authenticating Samsung accounts, including APIs and services.

    Although the information above is what Lapsus$ listed as the stolen data, it is unknown if Lapsus$ stole additional secret information from Samsung. What is known, however, is that the hacking group has split the leaked data into three compressed files and made it available for download via a torrent.

    As for a comment from Samsung about the data breach, Samsung officials told the media outlet that they ‘are now assessing the situation.’

  • McDonald’s hit with breach of advertising rules over Instagram mix-up

    McDonald’s hit with breach of advertising rules over Instagram mix-up

    Ad Standards has found that McDonald’s Australia breached rules for distinguishable advertising, as set out in the Australian Association of National Advertisers (AANA) Code of Ethics, Section 2.7.

    The breach occurred in an Instagram post by @southaussiewithcosi, which featured a man, woman and two children in matching McDonald’s pyjamas and holding McDelivery bags. Andrew ‘Cosi’ Costello, who fronts the Instagram account, is also a co-host of SAFM’s breakfast show on the Hit Network in Adelaide.

    The post, which has since been deleted, had the following caption: “Verified @maccas_sa have been serving South Australians for 50 years. How cool is that? Tonight we are celebrating their birthday with delivery and my girls are wearing the @peteralexanderofficial limited edition maccas PJ’s”.

    In one of the complaints submitted to Ad Standards’ community panel, it was noted that it was unclear whether it was a sponsored post or not as it did not contain the hashtags #ad or #sponsored.

    In McDonald’s initial response, the company argued that the code was not applicable in this case as the products provided were gifts, and there was no formal agreement with @southaussiewithcosi to post on social media.

    In its response, McDonald’s said: “McDonald’s has a partnership with SAFM, which is a commercial radio station that broadcasts to Adelaide. McDonald’s gifted the products as a gesture of goodwill and to support SAFM. The talent in question is part of the breakfast radio crew with SAFM and has his own personal brand/TV show called ‘South Aussie with Cosi’. McDonald’s does not have any commercial relationship with “South Aussie with Cosi” or the talent directly. As such the content posted on the account ‘South Aussie with Cosi’ is entirely outside of the McDonald’s reasonable control.”

    McDonald’s continued: “Unlike the previous cases that the panel has determined, in the current case it is not reasonable to assume that the motivation to provide free products is that they will post about the products or otherwise draw the attention of their followers to the brand given that McDonald’s does not have any affiliation with ‘South Aussie with Cosi’”.

    McDonald’s also highlighted that if the post was found to be advertising, it was distinguishable as another brand is mentioned, the caption refers to McDonald’s delivery service and 50th-anniversary celebrations, and both the products and label on the products are clearly visible.

    A majority of the panel found the post did meet the definition of advertising as while the advertiser did not have direct editorial control over the post, “the influencer was motivated to publish positive content about his employer’s sponsor, and in the context of the relationship would not, for example, have posted similarly about a competitor to the employer’s sponsor”.

    The panel further found that tagging the brand in the caption was not sufficient to distinguish the post as advertising, as per its Practice Note for the Code. The post needed to be clear, obvious, and upfront as sponsored content.

    McDonald’s responded to the finding: “McDonald’s takes its responsibility as an advertiser seriously. We are disappointed with the outcome of the complaint, however, we respect the final decision from the panel. We have communicated with the influencer, and the influencer has agreed to remove the post.”

  • SFC Fines UBS Over Regulatory Breaches

    SFC Fines UBS Over Regulatory Breaches

    Hong Kong’s Securities and Futures Commission reprimanded and fined UBS over regulatory breaches covering various areas including transparency client suitability.

    The SFC fined UBS AG and UBS Securities Asia Limited HK$9.8 million ($1.26 million) and $1.75 million, respectively, over various regulatory breaches, according to a statement.

    The issues covered areas ranging from lacking disclosures to client suitability issues.

    The SFC’s probe found that UBS failed to make proper disclosure of its financial interest in some Hong Kong-listed companies covers in its research reports for 14 years, between May 2004 and May 2018.

    The failure was caused by multiple data feed logic errors in a legacy data source used by UBS for tracking its shareholding positions, the securities regulator said.

    The SFC also found that UBS failed to fulfill various processes across client suitability and sales.

    It said the Swiss bank, in various time periods, failed to obtain valid standing authorities from clients who were not qualified as professional investors; record client order instructions; fully assess client derivatives knowledge; and disclose the stop loss event feature in a structured note.

    The SFC considers that UBS failed to act with due skill and care and put in place adequate systems and controls to ensure compliance with the applicable regulatory requirements,» the regulator said in the statement.

  • Humans cause 90% of cloud data breaches

    Humans cause 90% of cloud data breaches

    Incidents in public cloud infrastructure are more likely to happen because of a customer’s employees rather than actions carried out by cloud providers, according to a new Kaspersky Lab report.

    Companies expect cloud providers to be responsible for the safety of data stored on their cloud platforms, the report found. However, around 90% of corporate data breaches in the cloud happen due to social engineering techniques targeting customers’ employees, not because of problems caused by the cloud provider.

    Cloud adoption allows organizations to benefit from more agile business processes, reduced capex and faster IT provision. However, they also worry about cloud infrastructure continuity and the security of their data. At least a third of both SMB and enterprise companies are concerned about incidents affecting IT infrastructure hosted by a third party. The consequences of an incident may make the benefits of cloud redundant and instead evoke painful commercial and reputational risks.

    Even though organizations are primarily worried about the integrity of external cloud platforms, they are more likely to be affected by weaknesses far closer to home. A third of incidents (33%) in the cloud are caused by social engineering techniques affecting employee behavior, while only 11% can be blamed on the actions of a cloud provider.

    The survey shows there is still room for improvement to ensure adequate cybersecurity measures are in place when working with third parties. Only 39%  of SMBs and half (47% ) of enterprises have implemented tailored protection for the cloud. This may be the result of businesses largely relying on a cloud infrastructure provider for cybersecurity. Alternatively, they could have false confidence that standard endpoint protection works smoothly within cloud environments without diminishing the benefits of cloud.

    “The first step for any business when migrating to public cloud is to understand who is responsible for their business data and the workloads held in it,” Kaspersky Lab VP of global sales Maxim Frolov said.

    “Cloud providers normally have dedicated cybersecurity measures in place to protect their platforms and customers, but when a threat is on the customer’s side, it is no longer the provider’s responsibility. Our research shows that companies should be more attentive to the cybersecurity hygiene of their employees and take measures that will protect their cloud environment from the inside.”