IOTW: Acer suffers second massive data breach in seven months

Taiwanese hardware supplier hit by attack on local after-sales service system in India having refused to pay ransom demands following previous attack in March

Add bookmark
Acer suffers massive data breach again

Acer, the world’s sixth-largest PC seller, has suffered yet another data breach. The Taiwan-based firm lost 60GB of client, distributor and retailer information, as well as log-in details, financial and audit data – all gleaned via an unknown attack type claimed by hacker group Desorden.

The hardware supplier suffered a previous attack back in March, when ransomware group REvil attempted to charge Acer US$50mn for the release of sensitive data. Acer reportedly refused to pay the demand, which has had unintended consequences for it in this week’s breach

The facts

On 13 October, a user on a popular hacker forum posted the below screenshot, claiming credit for the 60GB attack, referencing the March breach and offering both video evidence of the haul, as well as releasing the records of 10,000 Acer clients.

The attack was made at local level in India, and seems to have only impacted Indian clients, retailers and distributors – although it remains unknown what financial and audit information was accessed, which is a possible big blow for the manufacturer.

Acer confirmed the successful attack the next day, with the full statement reading: “We have recently detected an isolated attack on our local after-sales service system in India. Upon detection, we immediately initiated our security protocols and conducted a full scan of our systems. We are notifying all potentially affected customers in India. The incident has been reported to local law enforcement and the Indian Computer Emergency Response Team and has no material impact to our operations and business continuity.”

Lessons learned

The fact that Acer refused to comply with the REvil’s ransom (which reportedly went up to $100m following the company’s refusal) will undoubtedly be the reason that Desorden has already released some of the data.

Both Privacy Affairs and Bleeping Computer have confirmed that the data appears to be authentic, and that it includes the email addresses, phone numbers and names of several million Acer clients. While the company says this attack will not have a material impact on operations and business continuity, having two breaches in less than a year will certainly not encourage continued customer loyalty, impacting sales conversion for new customers. Both large and small businesses will have been affected, and for SMEs, the potential impact – which could include future identity theft – is large enough to give pause for thought when it comes to renewing contracts.

Further, Acer’s security protocols should already have been in place, and a full system scan, even of localized systems, should be de rigueur for a company which, after being attacked a mere seven months ago, should have known better.

Quick tips

  • As usual, when an attack like this occurs in your industry or with a competitor, it is best to assume your company is equally vulnerable. Make sure your local servers and systems are all as tight as one another and conduct thorough scans regularly.
  • Consider the main type of breaches and make sure that any sim tests or pen tests include them.
  • Consider cloud-based data storage, particularly CASB, which focuses on data protection.

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":0,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":null,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[{"id":"6165542d312025359d0ef3d8","name":"IOTW: Anonymous hacker posts salaries of \u2018Twitchers\u2019 to 4chan","description":"4chan user posts Twitch users' earnings data for the past few years in effort to \u201cdisrupt\u201d online video streaming space","file":null,"url":"\/attacks\/articles\/iotw-anonymous-hacker-posts-salaries-of-twitchers-to-4chan"},{"id":"615729073120256a7c3787a6","name":"IOTW: Giant Pay\u2019s devastating ransomware attack affects lorry drivers and more","description":"HGV drivers have been left to chase back payments, expenses and salaries as Giant Group enforces a full proactive blackout following ransomware attack","file":null,"url":"\/attacks\/articles\/iotw-giant-pays-devastating-ransomware-attack-affects-lorry-drivers-and-more"},{"id":"6143403fd1d92e28ef2a8294","name":"IOTW: T-Mobile under investigation following fourth data infringement in three years","description":"Telecoms giant faces slew of lawsuits after hacker was spotted attempting to sell stolen data online","file":null,"url":"\/attacks\/articles\/t-mobile-under-investigation-following-fourth-data-infringement-in-three-years"}],"featured_content_portal_embedded":null}" >