Wawa的数据泄露

Reset the days without a major data breach back to zero.

在不断发展的网络安全世界中, it doesn’t look like the phrase above will ever surpass the 30-day mark. 好像一个月一次, 要么是大型零售商, financial institution or service provider is affected by some sort of data breach. 现在瓦瓦, a popular east coast chain of gas and convenience stores, has taken the spotlight after a breach related to financial data was discovered to be occurring within the organization from as early as March 4. The retailer joins the long list of entities affected by 数据泄露 in the past year: Marriott, Whitepages, 脸谱网, 美国第一金融公司., American Medical Collection Association, Capital One and Adobe.

Details are still unclear on how an attacker was able to operate inconspicuously within Wawa’s environment for more than eight months, but one fact seems to be known: this breach most likely affected all retail/gas locations under Wawa’s purview. 另外, it’s been confirmed from an anonymous source that an external firm was called on to assist Wawa in rectifying the data breach, 但该公司的名字尚未公布.

在施耐德唐斯,我们的 网络安全 team assists a multitude of clients in matters related to 数据泄露, PCI遵从性 安全意识. 只要有漏洞上了头条, 我们想提醒我们的读者, clients and potential clients that there is a long list of items to focus on when it comes to payment card security. 正如我们在整个行业所看到的那样, sensitive cardholder data can be stored – and therefore stolen – from many places, 有些比其他的更明显:

  1. Compromised card readers and other supporting infrastructure (e.g.(RAM刮削器)
  2. Paper stored in a filing cabinet (the old fashioned way)
  3. Cardholder data stored in a payment system database
  4. Camera footage recording entry of authentication data
  5. Secret tap into the store’s wireless or wired network
  6. 客服呼叫中心录音

Based on the limited information we know about the Wawa breach, 项目项1, 3 and 5 were the most likely avenues in which the attacker was able to compromise such a large amount of data. The only good news that come out of this story is that Wawa was able to rectify the issue related to this breach within two days once it was identified. The bad news is, the hackers went unidentified in their systems for over eight months.

这是我们能期待的最好的消息了, 虽然, is no more news from the data breach front as we get through the holiday season. 与此同时, we encourage all readers to monitor their payment statements over the coming months if they’ve purchased anything from Wawa in the last year.

来源:

http://www.cnet.com/news/biggest-data-breaches-of-2019-same-mistakes-different-year/

你们已经听到了我们的想法,我们也想听听你们的想法

The Schneider Downs 我们对 blog exists to create a dialogue on issues that are important to organizations and individuals. 虽然我们喜欢分享我们的想法和见解, we’re especially interested in what you may have to say. If you have a question or a comment about this article – or any article from the 我们对 blog – we hope you’ll share it with us. After all, a dialogue is an exchange of ideas, and we’d like to hear from you. 电邮至 (电子邮件保护).

Material discussed is meant for informational purposes only, 而且这不能被理解为投资, 税, 或法律建议. 请注意,个别情况可能有所不同. 因此, this information should be relied upon when coordinated with individual professional advice.

©2024施耐德唐斯. 版权所有. All content on this site is property of Schneider Downs unless otherwise noted and should not be used without 书面许可.

我们对
8审查用户访问时的关键考虑事项
Allegheny County Marriage License Data Leak May Affect Recent Newlyweds
$1 Billion a Day: Unpacking the 金融 Aftershock of the Change 医疗保健 Cyber-Attack
Get the Low Down Before You Download: Exploring the Temu App’s Security Risks
Six-Figure Ransomware Attack Hits Washington County, PA
浪漫骗局:保护你的心和钱包
Register to receive our weekly newsletter with our 最近的 columns and insights.
有问题吗?? 问我们!

我们很乐意听到你的消息. Drop us a note, and we’ll respond to you as quickly as possible.

问我们
bet9平台游戏

This site uses cookies to ensure that we give you the best user experience. Cookies assist in navigation, analyzing traffic and in our marketing efforts as described in our 隐私政策.

×