Tag: leak

  • Apple’s Key Supplier Tata Boosts Security Measures Amid Dark Web Data Leak Investigation

    Apple’s Key Supplier Tata Boosts Security Measures Amid Dark Web Data Leak Investigation

    Tata Electronics, a primary supplier for tech giant Apple in India, has increased its internal security measures following a potential leak of confidential client files on the dark web, according to a source from Tata and two industry representatives.

    In response to the incident, Tata has engaged an international consultant to perform a forensic audit. The company has also reported the incident to the Indian government and its customer base. The source from Tata chose to remain anonymous due to the sensitive nature of the situation.

    The cybercrime group known as World Leaks claimed responsibility for uploading over 200,000 files onto the dark web. These files allegedly include design documents for components used by both Apple and Tesla, another of Tata’s clients. The authenticity of the data remains unverified.

    Tata acknowledged the occurrence of a “cybersecurity incident” but assured that its operations were not affected, without providing further details.

    In addition to Apple and Tesla, the leaked data is believed to include at least 16 files and folders from Taiwan Semiconductor Manufacturing Co (TSMC) and 23 from Qualcomm. Both companies supply parts for iPhones.

    Increased Security Measures

    Following the breach, Tata Electronics strengthened security protocols across all its facilities and offices. Remote access to sensitive internal tools, such as those used for placing purchase orders, was limited to a select group of employees. Prior to the incident, these tools were more accessible. The updated protocols apply across Tata Electronics and are not limited to specific factories.

    The investigation into the breach continues, with Apple’s security team reportedly collaborating closely with Tata. The security enhancements include stricter regulations for accessing Tata’s official network from outside the company’s premises.

    Implications for Tata and its Clients

    Tata Electronics, led by former Intel and Applied Materials executive Randhir Thakur, is a critical part of Apple’s strategy to expand iPhone production outside China. However, the breach poses a significant setback to Apple’s supply chain. Tata is also facing scrutiny over alleged farmland contamination near one of its iPhone parts plants in India.

    World Leaks claimed to have published more than 204,341 files containing Tata Electronics data, amounting to over 630.4 gigabytes. The exposed documents include purported “product reliability test” details of a TSMC component and mechanical specifications for a power management integrated circuit from Qualcomm.

    Despite the challenges, India is expected to manufacture 26% of the world’s iPhones by 2026, a significant increase from the 6% it produced four years ago, as reported by research firm Counterpoint.

    Questions & Answers

    How has Tata Electronics responded to the data breach?
    Tata Electronics has increased internal security measures, limited remote access to sensitive systems, and engaged an international consultant for a forensic audit.

    What does the leaked data purportedly contain?
    The data allegedly contains design documents from Apple and Tesla, and files from Taiwan Semiconductor Manufacturing Co and Qualcomm.

    What are the potential impacts of the breach on Tata and its clients?
    The breach could interrupt Apple’s supply chain and increase scrutiny on Tata, which is already facing allegations of farmland contamination in India.

  • Spanish Retail Giant Mango Suffers Data Breach: Customer Marketing Data Compromised

    Spanish Retail Giant Mango Suffers Data Breach: Customer Marketing Data Compromised

    Mango, a global fashion retail corporation based in Spain, has recently announced a data breach. An external marketing service provider affiliated with the retailer experienced an unauthorized intrusion, compromising customer data.

    Details of the Data Breach

    On October 15, Mango informed its customers via email about the data breach incident. The breach compromised certain customer information used for marketing purposes. This included data such as first names, countries, postal codes, email addresses, and phone numbers.

    The company was quick to reassure customers that the breach did not involve financial information, passwords, or other identification details.

    Mango’s Response to the Breach

    Mango emphasized the continued security of its infrastructure and internal corporate systems. It also confirmed that the company’s operations are continuing uninterrupted.

    Upon learning about the breach, Mango immediately implemented all its security protocols. The company has also reported the issue to the Data Protection Agency and the Authorities, in accordance with current regulations and their internal protocol.

    As a precaution, Mango sent out a notice to its customers about the breach. It advised customers to be vigilant for suspicious emails or phone calls asking for personal information or prompting them to take unusual actions.

    Contacting Mango

    Clients who have any concerns about the breach can reach Mango’s customer service at personaldata@mango.com. Alternatively, they can make a direct phone call to +34 93 860 24 24.

    In closing, Mango expressed regret for the incident. The company conveyed their sincere apologies for any inconvenience caused by the situation.

    Questions & Answers

    What kind of customer data did the breach compromise?
    The breach compromised data used for marketing purposes, including customers’ first names, countries, postal codes, email addresses, and phone numbers.

    Did the breach involve any financial or identification information?
    No, the breach did not involve any financial information, passwords, or other identification details.

    What steps has Mango taken in response to the breach?
    Mango has implemented all its security protocols and reported the issue to the Data Protection Agency and the Authorities. The company has also advised customers to be alert for suspicious emails or phone calls.

  • UBS Faces Major Darknet Data Breach Exposing Personal Details of 130,000 Employees

    UBS Faces Major Darknet Data Breach Exposing Personal Details of 130,000 Employees

    A significant cybersecurity breach has rattled UBS, as sensitive data concerning 130,000 of its employees has surfaced on the darknet following a hacker attack on its procurement service provider. But UBS isn’t the only one feeling the heat from this incident.

    Chain IQ: The Breach Exposed

    The breach traces back to Chain IQ, a procurement service provider and former UBS spinoff, which has also served other prominent clients such as Pictet, Manor, and Implenia. The troubling news was first reported by the Swiss daily Le Temps, shedding light on a severe data theft that occurred in June.

    Among the leaked information are names, email addresses, landline numbers, and, in some instances, mobile numbers—one of which belongs to UBS CEO Sergio Ermotti. Other details include job levels, languages spoken, and office locations within the bank.

    Service Provider in the Spotlight

    Chain IQ, headquartered in Baar with additional offices in Geneva and Zurich, has established itself firmly in the procurement sector, delivering services that cover human resources, IT systems, waste management, and more.

    The Victorious Hacker’s List

    The data leak is not just a concern for UBS. Chain IQ’s client list is also up for grabs on the darknet; a troubling revelation. The firm has previously engaged with over 400 partners, and now exposed are the details of contracts, service types, and the internal contacts for each partner. Noteworthy clients include Pictet, insurance giants like Swiss Life and Axa, and global entities such as FedEx and IBM.

    UBS’s relationship with Chain IQ includes support in managing supply chain due diligence and company credit card administration. The leaked dataset spans 137,192 rows, each representing an employee.

    Darknet Deals and Criminal Risks

    Concerns escalate as reports confirm that the leaked file has been sold multiple times on the darknet. Such information poses a risk of being exploited for criminal activities, including identity theft and fraud.

    In response, Chain IQ is treating this situation with the utmost seriousness. The company has activated its security protocols, assembled a dedicated team of internal and external experts, and contacted the Zug cantonal police. They also aim for transparency, having informed all stakeholders promptly.

    A UBS spokesperson confirmed their awareness of the cyberattack on Chain IQ, assuring that they are monitoring the developments closely.

    Pictet’s Invoice Data Under Scrutiny

    In an additional twist, the leaked data allegedly includes information from Pictet, detailing “tens of thousands of invoices.” While the invoices themselves are not part of the leak, the records describe various expenditures by companies and employees, including groceries, dining, travel, and security services.

    A representative from Pictet stated that the compromised data does not include sensitive employee information or customer data, but mostly concerns invoice details from select suppliers. Precautionary measures are being implemented to mitigate further risks.

    As the world turns more digital, will we see a rise in such cyber capers, or can the industry step up its defenses to combat these digital bandits?

    Questions & Answers

    What type of data was leaked in the UBS incident? The data includes names, email addresses, phone numbers, and job-related details for 130,000 UBS employees.

    Which companies are involved in the breach? Chain IQ, former UBS spinoff, is the main service provider affected, alongside other clients like Pictet and Manor.

    What actions are being taken in response to the breach? Chain IQ has activated security protocols, mobilized a dedicated response team, and contacted law enforcement while keeping stakeholders informed.

  • Facebook in legal battle with Australia over alleged user data breach

    Facebook in legal battle with Australia over alleged user data breach

    Last year, Facebook received a penalty of $5 billion by the American Federal Trade Commission for sharing personal information via a survey product called “This Is Your Digital Life”, which disclosed users’ Facebook data to a political consultant Cambridge Analytica. Now, an Australian privacy regulator is filing a lawsuit against the tech giant over the same survey, which this time is said to have shared the data of more than 300,000 Australians.

    The lawsuit is filed in regards to 311,127 users’ personal data being unlawfully shared, with the users not being aware of their data’s disclosure. According to Reuters, the lawsuit didn’t request any specific amount in damages, however, each breach of the privacy law can amount to around $1.1 million penalties at most. So in total, if each of the 311,127 instances is taken into consideration, the penalty facing Facebook could be up to a maximum $348 billion.

    The disclosed personal information could be used for monetization and political purposes and is considered a serious interference with the privacy of Australian individuals. However, Facebook did not provide any comment on the issue.

    Overall, until now, allegedly Facebook has unwillingly shared information of over 87 billion users via the aforementioned survey tool. According to the Australian lawsuit, Facebook was not aware of what data it shared with the program, but this is still considered a failure to protect user data.

  • Uniqlo shoppers Details Leaked Online

    Uniqlo shoppers Details Leaked Online

    Uniqlo parent Fast Retailing announced hackers may have gained access to personal information of 461,091 accounts registered on the company’s Japanese shopping websites.

    The retailer said in a statement Monday the hackers may have accessed customers’ personal information, purchase history and partial credit card numbers of some of the users of its Uniqlo Japan and GU Japan online stores from April 23 to May 10 by means of list type account hacking.

    List type account hacking is when user IDs and passwords are potentially leaked from other services or sites.

    The company said it is still investigating the breach and added the number of incidents and circumstances may change during the course of the investigation.

    In the meantime, the Japanese retailer advised its online store’s customers, the number of which the company has not disclosed, to use unique passwords and to avoid using passwords used from other websites to lower the chances of hackers accessing their accounts.

    “Fast Retailing sincerely apologizes for the trouble and concern this has caused to its customers and all others involved,” the company said.

    “Going forward, the company will further strengthen its security measures and take steps to ensure safety, in order to prevent similar incidents in the future.”

    The retailer said information that was potentially accessed includes:

    • Customer name (last name and first name)
    • The customer address (postal code, address, and apartment number)
    • Customer phone number, mobile phone number, email address, gender, date of birth, purchase history, and clothing measurements
    • Receiver name (last name and first name), address, and phone number
    • Customer partial credit card information (cardholder name, expiration date, and a portion of credit card number). The credit card numbers potentially accessed are hidden, other than the first four and last four digits. In addition, the CVV number (credit card security code) is not displayed or stored.

    In its announcement, Fast Retailing said it has identified the origin of the communication from which the unauthorized logins were attempted and has blocked access. The company added it is strengthening monitoring of other access points.

    The Japanese retailer said it has already disabled the passwords for the 461,091 user IDs that were compromised and is sending individual e-mails to each person affected, requesting that they reset their password.

    Fast Retailing has also filed a report of damages regarding the unauthorized logins with the Tokyo Metropolitan Police.

    Online sales made up 9.9 percent of Uniqlo sales in Japan and 20 percent in China in the company’s first-half report. The company said overall online sales rose 30.3 percent in that report.

  • Motorola One Vision leak reveals new color option

    Motorola One Vision leak reveals new color option

    We’ve known for a while that Motorola is gearing to release another Android One phone under the name Motorola One Vision. Today, another leak gives us a glimpse at a new color option, which the One Vision will be available in at launch.

    As per earlier leaks, the Motorola One Vision will sport a sizable 6.2-inch display with a 21:9 aspect ratio and a small punch-hole selfie camera in the upper left corner. Around the back, the renders reveal, a dual-camera setup with a 48-megapixel sensor will be taking care of video and stills. There’s no word yet on what function the second camera will serve, though it could very well be used for depth sensing.

    Under the hood, the One Vision is set to be Motorola’s first smartphone that employs a Samsung processor. Specifically, the Exynos 9610, which was recently used in the Galaxy A50, and is about on par with the Snapdragon 660, performance-wise. The Samsung CPU is said to be accompanied by 3 or 4 GB of RAM and a 3,500 mAh battery.

    The newly-leaked renders also reveal a blue color option for the Motorola One Vision, in addition to the brown shade, which was shown in earlier leaks. The phone is slated to make its official debut at an event held in São Paulo, Brazil on May 15th.

  • Next Generation Mercedes-Benz S-Class Interior Leaked

    Next Generation Mercedes-Benz S-Class Interior Leaked

    Mercedes-Benz is readying the next generation of its flagship S-Class sedan and while we’ve seen test mules in the past, a leaked image of the interior have now made its online. The next generation Mercedes-Benz S-Class due to make its debut sometime in 2020 and going by the leaked image, the car appears future ready. Confirmed by earlier spy shots, the W223 S-Class replaced the dual infotainment screen with single unit for the instrument console and a massive vertically-stacked display for all other controls. The Tesla like touchscreen system replaces a tonne of switches on dashboard that gets a clutter-free appearance with sleek looking air-con vents and a new steering wheel. The leaked image also reveals the dual-tone treatment to the cabin in pristine while and black shades.

    The new generation Mercedes-Benz S-Class will be based on the automaker’s MRA platform and will come with a range of six and eight cylinder petrol and diesel engines. There will also be an electrified version called – the EQ S – and will be based on the company’s new Modular Electric Architecture (MEA). The new electrified version is expected to sport a range of 500 km on a single charge, as the automaker’s new top-of-the-line electric saloon. Not to forget, there will be the Affalterbach versions too with the AMG-tuned S-Class drawing power from the 4.0-litre V8 bi-turbo motor that is likely to go hybrid.

    In addition, the new Mercedes-Benz S-Class is expected to be offered in only the long-wheelbase guise globally. That said, do expect the Pullman and Maybach versions to follow suit packing in tech and comfort over the current W222 S-Class. It needs to be seen if Mercedes will continue with the Coupe and Convertible versions on the next generation. With respect to new tech, expect improved autonomous driving capability possibly up to Level 3; a new and updated version of the Airmatic suspension and more segment-first creature comforts on the offering.

    In terms of design, the new S-Class is likely to get an evolutionary styling along lines of the new A-Class, CLS and the likes. The current version is one of the most gorgeous looking saloons out there, which really sets the benchmark for the new version. It is also likely to serve as the design inspiration for the next C-Class and E-Class models, when its time for their respective new life cycles.

    More details on the new S-Class will be available in the months to come. A global debut will happen next year while sales globally should commence by 2021 or 2022, depending on the market. The W222 S-Class is assembled in India, and given the sheer demand for the flagship Mercedes, expect the new model to be locally assembled as well.

  • Some Nokia phones were spotted sending user data to China

    Some Nokia phones were spotted sending user data to China

    HMD Global has managed the Nokia smartphone brand impressively well since it took over in December 2016, but now the Finnish company has found itself in hot water. In a report published earlier today, Norway’s public broadcaster NRK claims to have found proof that certain Nokia smartphone have been transmitting unencrypted user information to China. Allegedly, on-device data such as GPS location, the device serial number, and even the user’s phone number were being transmitted back to a Chinese server.

    The server in question was under the domain “vnet.cn,” which is reportedly managed by state-owned carrier China Telecom. From the look of things, every time the Nokia 7 Plus units were powered on, data would immediately be transferred over to the server. Similarly, simply turning on the display or unlocking the device would trigger the same process.
    Fortunately for consumers, this issue was present only a “single batch” of Nokia 7 Plus units. Presumably, the smartphones were initially intended for the Chinese market but ultimately made it into the hands of European consumers. Moreover, since the issue has been raised, HMD Global has removed the infringing files from the devices.
  • Kathmandu suffers a data breach, customers potentially exposed

    Kathmandu suffers a data breach, customers potentially exposed

    An unidentified third-party has breached Kathmandu’s website and potentially accessed customers’ personal information and payment details, the outdoor retailer revealed on Wednesday.

    The business was alerted to the breach, which took place between January 8 and February 12, 2019, through bank fraud monitoring.

    A Kathmandu spokesperson told that the business is currently investigating how many customers are affected by the breach, but that it remains an ongoing process.

    “Whilst the independent forensic investigation is ongoing, we are notifying customers and relevant authorities as soon as practicable,” Kathmandu chief executive Xavier Simonet said.

    “As a company, Kathmandu takes the privacy of customer data extremely seriously and we unreservedly apologise to any customers who many have been impacted.”

    The business has enlisted the help of external IT and cyber security experts to assist in investigating the circumstances, and to confirm which customers have been impacted.

    While the financial impact of the incident is still unclear, the dual-listed retailer saw its stock price fall to $2.31 per share after the announcement, though rebounded to $2.37 by the end of trade.

  • Apple iPhone 6S to be revealed next week

    Apple iPhone 6S to be revealed next week

    It seems like just yesterday Apple unveiled the iPhone 6 and 6 Plus. Now, the industry has shifted focus from the iPhone 6 models to the inevitable sequels. If history is any indication, the consumers will soon follow. We expect the masses to clamor for the latest from Cupertino.

    According to Dutch site Techtastic, the iPhone 6S and 6S Plus pricing will be about the same as last year’s iPhones. Based on the site’s sources, it seems that Apple will continue to sell iPhones with 16, 64, and 128GB of storage.

    Seeing as these European prices match last year’s prices, it seems likely that the American price will not change, either. Techtastic also estimates that the new iPhones will go on sale on September 25. Of course, since Apple staggers release dates around the world, it’s possible the U.S. sale date could be the previous Friday, September 18. These are just rumors, so we’ll keep you posted on the final prices once Apple announces them.

    Seeing as these European prices match last year’s prices, it seems likely that the American price will not change, either. Techtastic also estimates that the new iPhones will go on sale on September 25. Of course, since Apple staggers release dates around the world, it’s possible the U.S. sale date could be the previous Friday, September 18. These are just rumors.

    On August 27, Apple confirmed that it will hold an event on September 9 at 10 a.m. PST in San Francisco’s Bill Graham Civic Auditorium. Obviously, it’s widely expected that the iPhone 6S and 6S Plus will launch at the event, though Apple could introduce some other products as well. The only teaser on the invite is the tagline, “Hey Siri, give us a hint!” The Siri reference could be referring to iOS 9’s new Proactive predictive feature, HomeKit controls, or both.

    Previous rumors mostly agreed that a September 9 launch date was planned. Multiple sources referred to a September 9 event, and now 9to5Mac has found some evidence that supports the launch date and hints at a possible in-store sale date for the iPhone 6S and 6S Plus. The publication’s sources state that BestBuy and Apple have agreed to sell Apple Care warranties at the retail store on September 14.