In April 2018, the overseas-train-travel company disclosed it had suffered a three-month data breach from November 2017 to mid-February 2018.
The data breach was caused by hackers installing skimming software on the company's website. The hackers were believed to have captured customers’ name, gender, address, telephone number, email address, username, password as well as credit card numbers, expiration dates and CVV codes.
Given the type of information the hackers stole about the customers which left them particularly exposed to identity theft and financial fraud made the company's 10 week delay between event discovery and event notification particularly disappointing.
If you'd rather we did the heavy lifting in developing a cyber incident response plan or lessons learnt training for your organisation underpined by our unique insight into the challenges faced and strategies implemented by organisations countering today's cyber security threats then please contact us here.