Security incident exposed personal information of 5 million users

Synopsis

In May 2020, the company disclosed a 'data security incident' where unauthorized actors obtained customer information from their user account database. The disclosure came after the discovery of their database being advertised on a dark web marketplace (being sold for $2,500).

The exposed information included customers’ names, login credentials to their accounts (email address and password), telephone number, billing address and shipping address(es). For less than 1 percent of affected customers, date of birth, is believed to have been impacted. The company stated that unauthorized actors may have determined plain text passwords for some accounts and confirmed that they do not store customers’ full payment or credit card information so that was not exposed in the event.

Book a consultation

Want to discuss this case? You can purchase a 30 minute conference call with our analysts to discuss this case and the implications it has for your organisation. Just select the time and date that works for you:

Companies

  • Minted

We've done the analysis so you can make the decisions

$489.99
When purchasing a minimum of 5 Case Studies
$699.99 if buying less than 5.

  • Detailed cause & effect analysis
  • Lessons learnt catalogued
  • Preventive controls extracted
Add to Cart
Heads up! Want to try before you buy? You can download our FREE demo case study here