Tag: data breach

  • Oz Hair and Beauty Discloses Customer Data Breach Across Order Platform

    Oz Hair and Beauty Discloses Customer Data Breach Across Order Platform

    Oz Hair and Beauty has suffered a cyber incident on its online purchasing platform. The breach exposed the personal details and transaction histories of customers who placed orders before August.

    An unauthorised third party gained brief access to data managed through an external service provider. The Australian e-commerce merchant disclosed the incident to shoppers in a direct notification.

    Exposed records include full names, email addresses, mobile numbers, and purchase details showing total spend, currency, city, state, and postcode. Attackers did not obtain passwords, credit card numbers, payment details, or street addresses, the company stated.

    Third-Party Platform Compromise

    External technical specialists launched an investigation immediately after staff detected the intrusion. Early findings point to data held by a contractor rather than a direct breach of internal systems.

    Oz Hair and Beauty has not disclosed the total number of affected customer accounts. It reported the incident to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner while notifying affected buyers.

    Earlier this month, a separate cyber attack hit furniture retailer Nick Scali and forced core IT infrastructure offline across its regional business. Australian consumer brands face tightening scrutiny over vendor data storage as regulators press merchants to shorten retention schedules.

    Security Audit Underway

    The beauty retailer is now overhauling its data protection controls and third-party storage policies to prevent repeat exposures across its digital channels.

    Technical investigators are still determining the full timeline of the intrusion. The retailer has yet to submit its final incident report to federal privacy regulators.

  • Coupang Data Breach: Unmasked Details of 33 Million Customers Sparks Privacy Fears

    Coupang Data Breach: Unmasked Details of 33 Million Customers Sparks Privacy Fears

    Increased apprehension has gripped South Korea following a significant data leak at e-commerce giant, Coupang. Officials have indicated that this breach could have been overlooked for an extended period.

    Scale of Data Leakage

    Coupang, a United States-listed merchant, revealed on a recent Saturday that the private information of 33.7 million consumers, essentially its entire client base, had been jeopardized. The vulnerable data encompass names, contact numbers, email addresses, and delivery locations. The company reassured that financial information, credit card specifics, and login details remained untouched.

    Based on Coupang’s findings, unauthorized infiltration into the delivery-related private data seems to have been carried out via foreign servers from June 24 onwards.

    Investigation Update

    Individuals familiar with the situation have shared that the police have pinpointed at least one suspect. The person is allegedly a former Chinese worker of Coupang who has since dissociated from both the company and the nation. The authorities initiated an inquiry after receiving a complaint.

    Coupang confirmed detecting the data leak on November 18 and informed the regulators within the subsequent two days. The corporation initially stated that approximately 4,500 accounts had been impacted.

    Implications of the Breach

    The magnitude of the data exposure, which is now proven to be considerably more extensive and long-standing than initially conveyed, has unsettled consumers. They are apprehensive that their data might be exploited for fraudulent activities or phishing strategies. The event now surpasses the cyber breach at SK Telecom in April, which affected data from 23.2 million users and led to a record penalty of 134.8 billion won.

    The final repercussions could escalate as the investigation progresses. A similar recent incident involving Lotte Card initially denied leakage of financial data following a breach in September. The company had to backtrack two weeks later and admit that credit card numbers and other critical data had indeed been laid bare.

    Questions & Answers

    What type of data has been compromised in the breach at Coupang?
    Names, phone numbers, email addresses, and delivery locations of customers have been exposed.

    Who has been identified as a possible suspect in this data breach incident?
    The police have identified a former Chinese worker of Coupang as a possible suspect.

    What are the possible implications of the data breach at Coupang?
    This breach has unsettled consumers who fear their personal data might be exploited for fraudulent purposes or phishing schemes. There is also a possibility of monetary penalties for the company.

  • Qantas Faces Cyberattack: Personal Data of Six Million Customers Breached in Major Security Incident

    Qantas Faces Cyberattack: Personal Data of Six Million Customers Breached in Major Security Incident

    In an alarming development, Australian airline Qantas has confirmed a significant data breach that has jeopardized the personal information of up to six million customers. This breach came to light following a cyberattack on a third-party customer service platform linked to a call center based in Manila, Philippines.

    A Shocking Vishing Attack

    The cyber intrusion, detected on June 30, involved a sophisticated form of voice phishing known as vishing, where malicious actors masquerade as trusted entities over phone calls to extract sensitive information from unsuspecting victims.

    Exposed Information and Assurances

    The compromised customer service platform housed a trove of personal data, including customers’ names, email addresses, phone numbers, birthdates, and frequent flyer numbers. However, Qantas has reassured customers that no financial information, credit card details, or passports were stored within the affected system. Additionally, the integrity of frequent flyer account credentials, passwords, and PINs remains intact.

    Robust Response and Investigation

    Operations and flight safety have not been compromised, as the airline emphasized. In response to this breach, Qantas has notified Australian intelligence agencies, including the Australian Cyber Security Centre, and law enforcement agencies such as the Australian Federal Police. The Office of the Australian Information Commissioner has also been apprised of the situation.

    To bolster customer assurance, the airline has initiated a comprehensive investigation and established a dedicated support line and website to keep affected customers updated. Those impacted will receive direct communication from the company.

    A Heartfelt Apology

    Qantas Group CEO Vanessa Hudson publicly addressed the situation, offering an apology to customers. “Our customers trust us with their personal information, and we take that responsibility seriously. We are contacting them directly and offering necessary support,” Hudson stated. It’s clear that trust, once broken, can be harder to mend than a wing on a seasoned aircraft.

    Questions & Answers

    What was the cause of the Qantas data breach?
    The breach stemmed from a cyberattack on a third-party customer service platform in the Philippines, involving a voice phishing scheme known as vishing.

    What type of personal information was compromised in the breach?
    The exposed information included customers’ names, emails, phone numbers, birthdates, and frequent flyer numbers, but no financial data or passwords were at risk.

    How is Qantas responding to the breach?
    Qantas has launched a full investigation and established a support line for customers while notifying relevant authorities and directly contacting affected individuals.

  • McDonald’s Korea fined for breach of customers’ personal data

    McDonald’s Korea fined for breach of customers’ personal data

    McDonald’s Korea was given a fine of 696 million won ($532,110) on Wednesday after the personal data of 4.87 million customers was leaked to hackers due to the firm’s lax data management.

    The Personal Information Protection Commission handed out the fine to the Korean branch of the American fast food chain, along with a financial penalty of about 10 million won for the data breach.

    According to the commission’s findings, McDonald’s Korea did not perform sufficient access control, leaving a backup file containing the personal data of its restaurant and McDelivery customers accessible via protocols for file sharing.

    As a result, the personal data of more than 4.87 million customers was hacked and leaked. McDonald’s Korea was also found to have not destroyed the personal data of 766,846 customers for whom the data retention period had expired, and belatedly notified authorities and customers of the data leakage.

  • Facebook in legal battle with Australia over alleged user data breach

    Facebook in legal battle with Australia over alleged user data breach

    Last year, Facebook received a penalty of $5 billion by the American Federal Trade Commission for sharing personal information via a survey product called “This Is Your Digital Life”, which disclosed users’ Facebook data to a political consultant Cambridge Analytica. Now, an Australian privacy regulator is filing a lawsuit against the tech giant over the same survey, which this time is said to have shared the data of more than 300,000 Australians.

    The lawsuit is filed in regards to 311,127 users’ personal data being unlawfully shared, with the users not being aware of their data’s disclosure. According to Reuters, the lawsuit didn’t request any specific amount in damages, however, each breach of the privacy law can amount to around $1.1 million penalties at most. So in total, if each of the 311,127 instances is taken into consideration, the penalty facing Facebook could be up to a maximum $348 billion.

    The disclosed personal information could be used for monetization and political purposes and is considered a serious interference with the privacy of Australian individuals. However, Facebook did not provide any comment on the issue.

    Overall, until now, allegedly Facebook has unwillingly shared information of over 87 billion users via the aforementioned survey tool. According to the Australian lawsuit, Facebook was not aware of what data it shared with the program, but this is still considered a failure to protect user data.

  • Forever 21 investigating POS security breach

    Forever 21 investigating POS security breach

    A Forever 21 data breach uncovered last November has prompted the fashion retailer to boost security at its checkout counters.

    In the security scare, hackers installed malware on point-of-sale machines at store checkouts in the US.

    A two-month long investigation has revealed that encryption technology on some POS devices at an unspecified number of stores was not always on and that malware had been installed by criminals looking to mine the system for customer payment data.

    The breaches occurred between April 3 and November 18 last year, lasting between a few days and in some cases the entire period, the company has admitted. Forever 21 stores use multiple POS devices and in most cases only one or a few of the POS devices in a store were affected.

    The malware searched for data on cards used for payments at the point-of-sale. In most cases, the data did not include the cardholder’s name, so was of no use to the hackers, but in a minority of instances, the cardholder’s name was found.

    Forever 21 said it has been working with its payment processors, hardware suppliers and independent consultants to improve the encryption systems on the POS devices in all Forever 21 stores.

    “We also continue to work with the payment card networks so that the banks that issue payment cards can be made aware of this incident,” the company said in a statement. “Lastly, we will continue to support law enforcement’s investigation of this incident.”

  • Massive data breach exposes all Philippines voters

    Massive data breach exposes all Philippines voters

    The Philippines’ 55 million voters are now susceptible to fraud and other risks after a massive data breach leaked the entire database of the Commission on Elections (Comelec), security firm Trend Micro has warned.

    The defacement of the Comelec website by a hacker group called Anonymous Philippines happened at near midnight on March 27. In a message to the government, the group said they want the poll body to implement tighter security measures on the precinct count optical scan (PCOS) machines to be used in the May 9 polls.

    “But what happens when the electoral process is mired with questions and controversies? Can the government still guarantee that the sovereignty of the people is upheld?” the hackers posted in the defaced Comelec website.

    A report said a second hacker group called LulzSec Pilipinas posted within day an online link to the Comelec’s whole database. The following day, the group also reportedly updated the post to add three mirror links to an index of files that could be downloaded.

    Trend Micro said the leak may turn out as the biggest government-related data breach in history, surpassing the Office of Personnel Management (OPM) hack in 2015 that leaked personally identifiable information (PII), including fingerprints and social security numbers (SSN) of 20 million US citizens.

    While the Comelec has given assurances to the public the day after the hacks that the no sensitive information was compromised and the country’s second automated polls will be secure, the securty firm believes otherwise.

    “Based on our investigation, the data dumps include 1.3 million records of overseas Filipino voters, which included passport numbers and expiry dates. What is alarming is that this crucial data is just in plain text and accessible to everyone,” the security firm said in a blog post.

    “Interestingly, we also found a whopping 15.8 million record of fingerprints and a list of people running for office since the 2010 elections,’” it added.

    “Among the data leaked were files on all candidates running on the election with the filename VOTESOBTAINED. Based on the filename, it reflects the number of votes obtained by the candidate. Currently, all VOTESOBTAINED file are set to have NULL as figure.”

    Regardless whether the hacking could affect the elections, the security firm said there is still the issue of all voter information that was leaked.