Tom Spring writes: Box.com has changed the way it handles publicly shared accounts and folders after a researcher found confidential documents and data belonging to Box.com users via Google, Bing and other search engines. While Box.com maintains this is a case of its customers unintentionally over-sharing, it says it has “fixed” the issue. The problem…
Category: Business Sector
Customer records from used car dealership found dumped in Detroit’s Brightmoor area
If you were a customer of Get Fresh Auto in Detroit, you may want to read a report by Randy Wimbley for Fox2. Contacted after a watchdog found customer information just dumped on a debris-littered street, the used car dealership’s owner’s responses to the reporter’s questions about how the papers wound up there reminded me of Sgt. Schultz in Hogan’s Heroes. “As soon…
Changing other people’s flight bookings is too easy
Lucian Constantin reports: The travel booking systems used by millions of people every day are woefully insecure and lack modern authentication methods. This allows attackers to easily modify other people’s reservations, cancel their flights and even use the refunds to book tickets for themselves, according a team of researchers who analyzed this online ecosystem. Karsten…
UK: Derbyshire computer hacker who broke into a company’s emails is now helping it get secure
Kit Sandeman reports that a 24-year-old man from London who was arrested after targeting an unnamed organization in Derbyshire has been given a “restorative justice” option: The man admitted accessing email accounts by using information found on social media sites such as LinkedIn and Facebook to identify targets, and bypass their security questions. This then…
2016 goes out with a hack as thedarkoverlord dumps more data
At 00:00 UTC, TheDarkOverlord issued a “press release.” Depending on where you reside, it made for a bad end to 2016, which was already a pretty terrible year for breaches, or a rotten start to 2017. Several days ago, DataBreaches.net reported on several hacks TheDarkOverlord (TDO) had announced. As expected, TDO has now dumped more data from…
Sg: Cellar Door, Web host fined over data protection breach after customer data appeared on Pastebin
K.C. Vijayan reports: The Cellar Door, a well-known local seller of gourmet products, has been fined $5,000 for failing to protect the personal data of some of its customers and users from being posted on another website without authorisation. Its website host, Global Interactive Works (GIW), was fined $3,000 by the Personal Data Protection Commission…