Tag: cyber attack

  • Client data exposed in Gucci, Balenciaga and McQueen cyberattack

    Client data exposed in Gucci, Balenciaga and McQueen cyberattack

    Luxury brands Gucci, Balenciaga, and Alexander McQueen have fallen victim to a cyber attack, leading to the potential theft of millions of customer’s private details. The assault targeted Kering, the French corporation that owns these prestigious labels.

    Kering recognized and confirmed the breach but did not publicly name the brands impacted. In a statement made in June, they reported that “an unauthorized third party momentarily gained access to our systems and accessed limited customer data from some of our Houses”.

    This incident is not an isolated event but seems to be part of a broader trend impacting luxury brands and retailers throughout the year. Other brands that suffered similar breaches include Cartier, owned by Richemont, and labels under LVMH. In July, a data leak affecting approximately 419,000 customers at LVMH’s Louis Vuitton was being investigated by Hong Kong’s privacy watchdog.

    The stolen customer data reportedly includes names, email addresses, phone numbers, addresses, and the total amounts spent at the brands’ stores. Notably, Kering has reassured that no financial information, such as credit card or bank account numbers, was stolen during the attack.

    The hackers, referring to themselves as “Shiny Hunters,” allege to have data associated with 7.4 million unique email addresses.

    In response to the breach, Kering stated that its brands promptly reported the incident to the relevant authorities and notified customers in accordance with local regulations. However, Kering did not provide a response when questioned about the countries impacted by the cyber attack.

    Questions & Answers

    What brands were affected by the cyber attack?
    The affected brands include luxury labels Gucci, Balenciaga, and Alexander McQueen, all owned by French parent company Kering.

    What kind of customer information was stolen during the breach?
    Reportedly, the stolen client data includes names, email addresses, phone numbers, addresses and the total amounts spent at the brands’ stores. However, no financial information like credit card or bank account numbers were compromised.

    How did Kering respond to the cyber attack?
    Kering reported that its brands immediately disclosed the breach to relevant authorities and notified customers as per local regulations. However, they did not comment on the specific countries affected by the attack.

  • Cartier tells customers some data stolen in cyberattack

    Cartier tells customers some data stolen in cyberattack

    Cartier, the luxury jewellery brand owned by Richemont, recently experienced a cyber attack that led to the theft of some customer data. This information was relayed to clients through an email.

    Cyber Attack on Cartier

    This incident is the latest in a string of cyber attacks on companies, with several retailers, including Marks & Spencer and Victoria’s Secret, reporting similar occurrences. Cartier, known for its watches, necklaces, and bracelets, which have been sported by celebrities like Taylor Swift, Angelina Jolie, and Michelle Obama, stated that an unauthorized party had gained temporary access to their system.

    The compromised data included limited client information, such as names, email addresses, and countries. Cartier reassured customers that more sensitive data, including passwords, credit card details, or other banking information, were not accessed during the breach. The company has since resolved the issue.

    Enhanced Security Measures

    In response to the attack, Cartier has taken measures to strengthen the protection of its systems and data. The company has informed the relevant authorities about the breach and is also collaborating with leading external cybersecurity experts to prevent future incidents.

    Julius Cerniauskas, CEO of web intelligence firm Oxylabs, highlighted that no brand is immune to cybercrime. According to him, cyber criminals are becoming increasingly opportunistic and sophisticated, targeting brands that hold valuable customer data.

    Other Retailers Affected

    Victoria’s Secret, a U.S. lingerie company, also recently reported a security incident related to its information technology systems. This forced the company to temporarily shut down its website for a few days. Victoria’s Secret claimed that the breach did not significantly impact its financial results for the first quarter but warned that its second quarter could be affected by the additional expenses incurred following the incident.

    Last month, British retailer Marks & Spencer revealed that a highly sophisticated and targeted cyber attack in April would cost the company about 300 million pounds (US$405 million) in lost profits.

    Fashion brand The North Face also reported a small-scale attack in April. The hackers used a method known as “credential stuffing,” in which they try usernames and passwords stolen from other data breaches, hoping that customers have reused the credentials across multiple accounts.

    Last month, Harrods, a London department store, reported attempts to infiltrate its systems, following similar incidents at Marks & Spencer and the Co-op Group.

    Questions & Answers

    What type of data was stolen in the cyber attack on Cartier?
    Names, email addresses, and countries of some customers were stolen in the cyber attack on Cartier.

    What measures has Cartier taken in response to the cyber attack?
    Cartier has enhanced the protection of its systems and data, informed the relevant authorities about the breach, and is working with leading external cybersecurity experts.

    Have other retailers been targeted by cyber attacks recently?
    Yes, Victoria’s Secret, Marks & Spencer, The North Face, and Harrods have all reported cyber attacks recently.

  • Indonesia Firms Face $34b in Losses Due to Cyber-Attacks

    Indonesia Firms Face $34b in Losses Due to Cyber-Attacks

    Cyber-attacks on Indonesian companies in 2017 will eventually cost domestic businesses $34 billion due to direct financial losses and long-term reputation damage, according to a recent study commissioned by global technology giant Microsoft.

    The study — which was carried out by research consultancy firm Frost & Sullivan by surveying 1,300 businesses and IT companies in the Asia-Pacific region — also put total potential losses to the region from cyber-attacks at $1.745 trillion, or 7 percent of the region’s current GDP.

    Almost half of Indonesia’s companies could have already been affected by cyber-attacks last year. The study found 22 percent of companies surveyed in Indonesia reported they had a security breach, while 27 percent were unsure if they had had one, due to a lack of data forensics assessments.

    Sixty-one percent of organizations either do not think about cybersecurity at all, or only after starting a new project. Almost seven out of 10 companies which had cyber attacks saw job losses in the last 12 months.

    “Companies face the risk of significant financial loss, damage to customer satisfaction and market reputation — as has been made all too clear by recent high-profile breaches,” said Haris Izmee, president director of Microsoft Indonesia, in a statement last week.

    Last year, Indonesia saw over 205 million cyber-attacks, including the ransomware WannaCry that attacked the country’s major hospitals, according to the Ministry of Communication and Information Technology.

    In calculating the potential losses, the study took into account direct financial losses from the attacks themselves, the opportunity cost to the organization caused by the incident, such as loss of customers because of reputation loss. The study also estimated cyber-attacks induced costs on the broader economy, such as a decrease in consumer and business spending.

    A large organization — one that has more than 500 employees — can possibly incur an economic cost of $16.3 million due to cyber-attacks.

    Of this, only $1 million is likely to be a direct cost to the company itself. Around $5.7 million is predicted to come from indirect costs, and $9.6 million to come from the induced costs.

    Over 90 percent of cyber-attacks can be prevented with maintaining most basic best practices, such as strong passwords, use of multi-factor authentications for suspicious log-in attempts and keeping all software up to date, Microsoft said.

     

  • Stop DDoS from ruining your retail Brand’s sales momentum

    Stop DDoS from ruining your retail Brand’s sales momentum

    On 11 November 2017, Alibaba’s Singles’ Day sales hit a new record high with a 39% increase from last year’s sales. The company’s 2017 profits broke world records of Black Friday and Cyber Monday, marking this Asian sales day as one of the highest revenue sales in history.

    With increasing internet-user penetration, consumer behavior is quickly transitioning in Asia today. Shoppers make most of their retail purchases on-the-go, through mobile applications or via websites. In fact, 90% of this year’s Alibaba sales were made through mobile phones.

    Now more than ever, retail businesses in the Asia-Pacific region need to tap onto an omni-channel approach to be aligned with these changing customer demands. Based on the 2016 e-commerce study, Google and Temasek foresee Southeast Asia to be the next region to boom in this market. The predictions indicated that e-commerce will make up 6% of the region’s total retail sales by 2025.

    Beware of business bullies

    While these statistics show a positive growth for the region, businesses going digital must be aware of the lurking threat factors. The physical shoplifters that pained businesses – especially during big sales such as Great Singapore Sale and Black Friday – have now evolved to become cyber criminals. Unlike thieves, businesses are not physically able to discern these criminals, especially since they attack over the network.

    One of the most devastating kinds of cyberattack for e-commerce businesses today is Distributed Denial of Service (DDoS) which aims to bring down websites, therefore, disrupting online services and businesses. DDoS attacks occur when an unusual and unexpected spike in traffic and connection requests overwhelms a website, slows down the network, or in the worst-case scenario, shuts down the entire system.

    A reliable website that guarantees a good user experience is what defines a successful e-commerce business as it is the main platform for acquiring customers and generating revenues. The damage caused by a network failure or a complete site outage will directly and immediately impact business assets. For instance, Alibaba made US$7 billion within the first 30 minutes of the Singles’ Day sale3. Imagine if they had been hit by a DDoS attack; Alibaba would have lost US$233 million per second. Not only would this be a massive loss, the attack would have also caused long term damage to Alibaba’s brand image and customer loyalty. According to KPMG’s annual consumer survey, one fifth of consumers will turn away from a cyber-attacked company4.

    Don’t fall victim

    With the festive period approaching, online retailers can expect an approximately 20% increase in their web traffic5. To make the most out of this sale period, businesses need to ensure that they are ready to protect themselves against DDoS attacks. This includes re-evaluating their network security to assure they are taking the best protective measures.

    Monitor and Detect

    Businesses cannot fight what they do not know. Monitoring network traffic and flow data with DDoS detection alerts security pros to anomalies before they become full-blown catastrophes.

    One way to get a better understanding of what is happening on the network is baselining to know what the traffic looks like during peacetime. This allows organizations to take the appropriate wartime countermeasures when an attack happens. Effective DDoS detection needs to be able to discern the human traffic from the bots.

    Additionally, organizations need a detection solution that can scale given that attacks are increasingly getting larger in size. The best class solution should not only be able to process the data, but also be equipped with the ability to quickly make intelligent decisions with that data.

    Mitigate and Protect

    DDoS protection requires having the right mitigation in place. Businesses should look for a modern DDoS solution that empowers them to automate defenses – from reports to packet captures to mitigation. This can help security pros reduce stress and thwart attacks quickly.

    Communicate

    As with all security procedures, effective DDoS defense involves a human element, as well. It is imperative for businesses to have a communication plan in place in the event of an attack. This includes critical information such as who to notify during, and after an attack. For example, who should be the first to know if the site goes down due to a DDoS attack? Is that the same person notified if a DDoS attack shuts down the online retail site? Who else is notified if an attack happens? Having communications ironed out ahead of time can reduce time to remediation and lower stress levels.

    Make the most of this year’s sale season

    For businesses, these next few months are the time to peak your revenue and customer traffic. It may be a chance to raise brand awareness or even expand the business. Whichever the case, a DDoS attack can be a fatal roadblock to an organization’s goals. Reacting in an efficient manner is key. Online retailers need to ensure they have an emergency response plan that makes good use of anti-DDoS technologies for unforeseeable attacks. For a happy holiday for all, be on the lookout for any dangers and take the right cautionary actions to protect against any potential threats.