If you were a customer of Get Fresh Auto in Detroit, you may want to read a report by Randy Wimbley for Fox2. Contacted after a watchdog found customer information just dumped on a debris-littered street, the used car dealership’s owner’s responses to the reporter’s questions about how the papers wound up there reminded me of Sgt. Schultz in Hogan’s Heroes. “As soon…
Category: Business Sector
Changing other people’s flight bookings is too easy
Lucian Constantin reports: The travel booking systems used by millions of people every day are woefully insecure and lack modern authentication methods. This allows attackers to easily modify other people’s reservations, cancel their flights and even use the refunds to book tickets for themselves, according a team of researchers who analyzed this online ecosystem. Karsten…
UK: Derbyshire computer hacker who broke into a company’s emails is now helping it get secure
Kit Sandeman reports that a 24-year-old man from London who was arrested after targeting an unnamed organization in Derbyshire has been given a “restorative justice” option: The man admitted accessing email accounts by using information found on social media sites such as LinkedIn and Facebook to identify targets, and bypass their security questions. This then…
2016 goes out with a hack as thedarkoverlord dumps more data
At 00:00 UTC, TheDarkOverlord issued a “press release.” Depending on where you reside, it made for a bad end to 2016, which was already a pretty terrible year for breaches, or a rotten start to 2017. Several days ago, DataBreaches.net reported on several hacks TheDarkOverlord (TDO) had announced. As expected, TDO has now dumped more data from…
Sg: Cellar Door, Web host fined over data protection breach after customer data appeared on Pastebin
K.C. Vijayan reports: The Cellar Door, a well-known local seller of gourmet products, has been fined $5,000 for failing to protect the personal data of some of its customers and users from being posted on another website without authorisation. Its website host, Global Interactive Works (GIW), was fined $3,000 by the Personal Data Protection Commission…
KeepKey notifies customers of security incident, offers 30 BTC reward for tips leading to attacker’s arrest
KeepKey, a hardware bitcoin wallet, has disclosed how a brief compromise of the company phone and email enabled the attacker to reset some account passwords. Here’s how KeepKey responded to the attack and the attacker: A Message from the Founder About Email Breach Our guiding principle at KeepKey is building open and transparent products for our most…