Overnight, news broke that Delta Airlines, Sears, Kmart and more were affected by a data breach at software service provider [24]7.ai. Despite the incident starting on Sept. 26, 2017 and being resolved by Oct. 12, Sears has said it was only notified of the incident a few weeks ago.
The incident led to unauthorised access to the credit card information of under 100,000 of its customers. Delta Airlines is currently uncertain if its information was accessed and compromised. Luke Brown, VP EMEA at WinMagic commented below.
“Fortunately, the impact on Sears and Delta Air customers of this particular data breach appears to be minimal. But any company that allows unauthorised access to its customers’ credit card data has some pretty serious security challenges. We don’t know the details of this particular incident, but one thing is clear – the data accessed by these hackers can’t have been encrypted. If was, they couldn’t have read it. In the movies, they say something is encrypted and somebody can hack it in 5 minutes. That is not true. If something is encrypted with a strong password, nobody is going to unlock it. Companies can implement all the security bells and whistles they want to protect their perimeter, but if they leave the crown jewels – i.e. data – unprotected, they’re leaving themselves wide open for a breach.”
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.