Security incident exposed personal information of 5 million users

Synopsis

In May 2020, the company disclosed a 'data security incident' where unauthorized actors obtained customer information from their user account database. The disclosure came after the discovery of their database being advertised on a dark web marketplace (being sold for $2,500).

The exposed information included customers’ names, login credentials to their accounts (email address and password), telephone number, billing address and shipping address(es). For less than 1 percent of affected customers, date of birth, is believed to have been impacted. The company stated that unauthorized actors may have determined plain text passwords for some accounts and confirmed that they do not store customers’ full payment or credit card information so that was not exposed in the event.

Analyst

Courtenay Brammar

Experienced global enterprise risk and governance professional. Previously Vice President at Morgan Stanley, Deloitte Risk Advisory practitioner and PRMIA steering committee member in both London and New York.

Additional services

We offer a range of cost-effective, fixed-price training programmes and consultant services derived from the unique insights gained from all our case study data.

If you'd rather we did the heavy lifting in developing a cyber incident response plan or lessons learnt training for your organisation underpined by our unique insight into the challenges faced and strategies implemented by organisations countering today's cyber security threats then please contact us here.

Companies

  • Minted

We've done the analysis so you can make the decisions

$489.99
When purchasing a minimum of 5 Case Studies
$699.99 if buying less than 5.

  • Detailed cause & effect analysis
  • Lessons learnt catalogued
  • Preventive controls extracted
Add to Cart
Heads up! Want to try before you buy? You can download our FREE demo case study here