Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - More then 650,000 Customers Data has been Breach
News & Analysis

More then 650,000 Customers Data has been Breach

ISBuzz TeamBy ISBuzz TeamDecember 8, 2015Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Data has been Breach
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

It has been reported that pub chain JD Wetherspoon has been hit by a data breach that has affected more than 650,000 customers. While JD Wetherspoon has not confirmed the details of the breach, it suggests that an ‘old database’ used by the company’s previous website was attacked and personal information, such as customer names and email addresses, has been compromised.

JD Wetherspoon CEO John Hutson said in a statement released to the market today: “Unfortunately, hacking is becoming more and more sophisticated and widespread. We are determined to respond to this by increasing our efforts and investment in security and will be doing everything possible to prevent a recurrence.” Security experts from WhiteHat Security, Thales e-Security, Veracode and Rapid7 have the following comments on this breach.

[su_note note_color=”#ffffcc” text_color=”#00000″]Simon Keates, Consultant in Mobile Security at Thales e-Security :

“Although it is reported that “very limited” credit and debit card information was accessed in the Wetherspoons breach, it is of no less significant concern that personal details including names and email addresses may have been stolen. In fact, theft of card details is relatively easy to ‘deal with’ – they can be blocked and replaced. It’s the other – seemingly innocuous – information that can post a bigger problem. Details such as your mother’s maiden name, your date of birth, and where you live can be pieced together relatively easily by would-be criminals and used as bait for targeting phishing attacks and identity theft to access more sensitive information. Armed with this information, hackers can continue to commit behavioural attacks well beyond the initial breach. In today’s data-flooded world, security is increasingly becoming a big data problem – accessing personal details is just one more step in building a large database to mine information. Businesses need to change the way they think about data protection, extending their encryption policies to cover all personally identifiable information, so it is ‘detoxified’ should it fall into the wrong hands. Without this, there’s a real danger that attackers will know much more about you than your favourite beer..”[/su_note]

[su_note note_color=”#ffffcc” text_color=”#00000″]Paul Farrington, Senior Solution Architect at Veracode :

Just as you can’t lock a door you don’t know is there, this breach has demonstrated how important it is for companies to have full visibility into their web perimeter. The Wetherspoons breach seems to have occurred due to the company failing to decommission old web applications, illustrating how companies that don’t take steps to determine the full scope of their IT environment leave themselves open to be exploited through unpatched vulnerabilities in these forgotten apps.

When working with companies to reduce application-layer risk, Veracode typically finds 40 percent more websites than they originally believed they had (more than more than 350,000 sites in the past two years alone). To dramatically reduce their risk, it is essential that organisations identify all the web and mobile applications on their IT environment, and work to secure those which are needed and decommission those which no longer serve a purpose.

There remains a perception that it’s only other companies that get hacked. The reality is that every company is being scanned each day by different threat actors. We hear about the high profile attacks such as the recent Talk Talk incident and now this attack, yet this in a strange sense creates a false sense of security because they appear to happen days or weeks apart. The reality is that so many attacks either remain undisclosed or undetected.

CIOs have an opportunity to save money and reduce their attack surface by rediscovering their web perimeter. Automation makes this easy to do. A typical virtual machine used to host a website from a leading cloud provider, costs around £1.7K per annum. Turn-off just a few handfuls of these unloved servers with potential vulnerabilities – over time the firm might easily save more than £100K annually.[/su_note]

[su_note note_color=”#ffffcc” text_color=”#00000″]Johnathan Kuskos, Manager, Threat Research Centre at WhiteHat Security :

“To say that “…hacking is becoming more and more sophisticated and widespread” is the modern age “my dog ate my homework” excuse for a data breach. Until we see what the attack actually was, I’d hardly call it sophisticated right from the start. If it ends up being the result of SQLi, which is my bet since JD Wetherspoon call the database “old”, there’s not much sophisticated about it. SQLi was a Top 10 OWASP vulnerability in 2007, that’s nearly 9 years ago.”[/su_note]

[su_note note_color=”#ffffcc” text_color=”#00000″]Tod Beardsley – Security Engineering Manager, Rapid7 :

“So far, the scope of the Wetherspoon breach seems relatively limited, with just a small portion of those breached having financial details exposed. This is especially true when compared with some other recent hacks, including TalkTalk, LANDESK, and VTech, even though the volume is being reported as significantly larger.

For most of those impacted, the details compromised included names, phone numbers, email addresses, and birthdates – and early reports put the number of customers breached upward of half a million.

While data dumps like these can be useful for organised phishing campaigns, there are plenty more comprehensive sources for mass marketing data like this. Ultimately, the Wetherspoon breach is a reminder to people to be careful about who they share their personally identifiable information (PII) with, even when a company makes a PII promise, and to stay vigilant about monitoring credit card statements for unusual activity.”[/su_note]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The next phase of endpoint security starts with simplicity

June 24, 20266 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}