Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Acer Suffers By Data Breach
News & Analysis

Acer Suffers By Data Breach

ISBuzz TeamBy ISBuzz TeamJune 20, 2016Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Following the news that Acer has suffered a data breach on its e-commerce site due to the unauthorized access of a third-party. Acer is not saying how many users were affected by the intrusion but revealed that data such as names, addresses, payment card numbers, card expiration dates and three-digit security codes (CVV numbers) may have been compromised. IT security experts from AlienVault, ESET and Cryptzone commented below.

Javvad Malik, Security Advocate at AlienVault:

Javvad Malik“Breaches as a result of third parties are not something new. The nature of business today is that organisations rely on many partners and suppliers to provide services to their customers. However, this supply chain needs to be managed and secured appropriately.

Attackers will choose the path of least resistance to get into a company – and if it is well-secured, then this path will usually be through a third party that has legitimate access.

Having an appropriate supplier security assurance framework in place that sets the requirements for a third party and also the ongoing controls is essential. For this, though, no one size will fit all. The level of rigor needed will change depending on whether a third party has direct access to data on-premise, how the data is shared between organisations, what data the third party processes, etc.

There are other legal considerations – for example, is the company allowed to conduct security testing against a partners IT infrastructure? Can it monitor third party communications?

One of the fundamental security controls to have in place where a third party is connecting to corporate systems is to have solid monitoring controls in place that can notify when a connection is made, the duration, and the activity that was carried out. Added benefits would be some form of behavioral monitoring that can assess whether a third party has suddenly changed their activity, for example, by communicating over uncommon ports, transferring large amounts of data, or traversing the internal network.

Until companies can get proper visibility and understanding into what actions are being undertaken on their systems and by who, these types of breaches from external and internal parties will continue.”

Mark James, Security Specialist at ESET:

mark-james“With so many data breaches happening these days some recent and some from a while ago, it really is getting to the point where if you’re lucky enough to NOT have at least some of your data bouncing around the internet then you’re in the minority.

We entrust all levels of data both personal and public to organisations but have NO control over how they protect it. When it does get compromised we have to rely on those companies to inform us, hopefully quickly and giving us all the relevant information but there’s always a compromise from their point of view. It’s also important to ensure they have all the facts and sometimes this may take time, finding out how it happened, how to stop it happening again and then informing the affected parties is not going to happen in a few days. Then it’s our job to try and mitigate any damage, change passwords, cancel payment options or even cancel cards if enough data is at risk. You also need to consider any other logins that may be sharing passwords although I am sure nobody reuses passwords…

Using a password manager is a great way to generate complex and unique passwords you personally don’t have to remember and also, where possible, try and utilise two-factor authentication.

You need to ensure you keep an eye on your finances, be on the lookout for small insignificant payments or amounts you’re not sure about. Don’t be concerned about flagging payments that you don’t remember, it’s better to be over cautious rather than under cautious after all it’s your hard earned money that’s at stake here.”

Leo Taddeo, CSO and Former Special Agent at NYC’s FBI Cybercrime Division: 

LeoTaddeo“Acer claims the breach was the result of a problem with one of its third party payment processing systems.  No matter how the breach occurred, Acer is ultimately responsible for maintaining the security and confidentiality of its customer information. The risks posed by third parties are clear: all of the IT vulnerabilities of your third party partners become your vulnerabilities when they connect to your network.  The best defenses against these risks are proper segmentation, strong authentication, robust logging and monitoring, and limiting access to only the network segments that are required by the third party.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}