Yesterday, Great Western Railway sent a number of password reset email notifications to its customers, in response to it becoming aware of “unauthorised attempts to gain access to a small number of GWR.com accounts over the past week”. GWR customers have shared screen grabs of the email notification on Twitter.
GWR has since confirmed in interview that circa 1,000 accounts were affected.
Rashmi Knowles, EMEA Field CTO at RSA Security and expert in data protection and end-user security, implores customers to take heed of the advice from companies like GWR and reset their passwords – commented below.
Rashmi Knowles, Field CTO, EMEA at RSA Security:
“This is why everyone should practice good cyber hygiene. If you know that one of your accounts has been compromised, and use the same username and password elsewhere, then update your other accounts immediately. More generally, with consumer breaches of this kind on the rise, you should never be using the same passwords for business and personal use. Targeting consumers is often a gateway into their place of work for hackers. By having separate passwords, you can minimise the chances of your employers being affected. Finally, users should opt in to two-factor authentication, where possible. For example, often you will see your bank asking for a fingerprint, voice scan or secondary password because we regularly see passwords failing to protect us adequately. By adding an extra layer of defence you can make things much harder for the bad guys.”
The opinions expressed in this post belongs to the individual contributors and do not necessarily reflect the views of Information Security Buzz.