In May 2020, the company disclosed a 'data security incident' where unauthorized actors obtained customer information from their user account database. The disclosure came after the discovery of their database being advertised on a dark web marketplace (being sold for $2,500).
The exposed information included customers’ names, login credentials to their accounts (email address and password), telephone number, billing address and shipping address(es). For less than 1 percent of affected customers, date of birth, is believed to have been impacted. The company stated that unauthorized actors may have determined plain text passwords for some accounts and confirmed that they do not store customers’ full payment or credit card information so that was not exposed in the event.
Want to discuss this case? We're offering a FREE 20 minute phone consultation to discuss this case and the implications it has for your organisation. Just select the time and date that works for you:
If you'd rather we did the heavy lifting in developing a cyber incident response plan or lessons learnt training for your organisation underpined by our unique insight into the challenges faced and strategies implemented by organisations countering today's cyber security threats then please contact us here.