IOTW: Cyber incident halts Funky Pigeon online orders

UK retailer WHSmith confirms one of its subsidiaries has been subjected to a cyber security incident

Add bookmark
Cyber incident halts Funky Pigeon online orders

WHSmith subsidiary and online card retailer Funky Pigeon was forced to halt all online orders as it dealt with a cyber security incident which occurred on 14 April 2022.

Confirming the incident on 19 April WHSmith explained that Funky Pigeon temporarily suspended orders from its website and an investigation was being carried out regarding the detail of the incident with external, unspecified IT specialists.

Funky Pigeon confirmed it has isolated relevant systems and said its customer-facing website was not affected by the cyber security incident.

Customer data “not at risk”

The retailer said “no customer payment data, such as bank account or credit card details, has been placed at risk – all of this data is processed securely via accredited third parties and is securely encrypted”.

However, in a later email to customers on 20 April, Funky Pigeon said it was still investigating the extent to which any personal data, specifically names, addresses, e-mail addresses, telephone numbers and personalized card and gift designs had been accessed.

Become a Cyber Security Hub member and gain exclusive access to our upcoming digital events, industry reports and expert webinars

The company also does not believe that any customer account passwords have been placed at risk.

Outside of the statements issued, Funky Pidgeon has not revealed many details of the cyber incident.

Michael Stout, a UK-based contract CISO and cyber security consultant, said it looked to be a “straightforward data exfiltration attempt” where an attacker seeks to steal information from a system”.

“Whether this was a targeted or opportunistic attack remains unclear, and if it were successful, the stolen data would likely appear for sale on the Dark Web, used by organized crime, or by a state actor,” Stout explained.

“There is also the possibility that the hackers would attempt to ransom the information in exchange for not making the attack public.”

UK retailers being targeted

This is not the first time in recent weeks a UK-based retailer has been the target of a cyber-attack.
On 5 April 2022, discount retailer The Works confirmed it had been the victim of a cyber security incident involving unauthorized access to its computer systems.

“Online retailers continue to be targeted by hackers as they are public-facing and generally accessible worldwide. In addition, the nature of this type of attack can make it difficult to trace or prosecute,” said Stout .

The incident caused disruption to online orders and saw five physical stores close as a result of replenishment deliveries to the group’s stores being temporarily suspended. The company took its systems offline following the incident.

One commonality in both the Funky Pidgeon and The Works incidents is that both businesses took actions to take their systems offline while investigating the incident.

Stout remarked that this “indicated a concern with the overall security of their system design”.

“Offline, the investigators can complete a thorough system review, prevent further exploitation and preserve forensic evidence,” he added.

Getting mitigation tactics underway

To mitigate a data exfiltration attack there are a number of actions a system owner should follow which including keeping an up-to-date threat model and blacklisting IP addresses outside of their target market, Stout told CS Hub .

He pointed out that while blacklisting is not a security guarantee, it can reduce exposure to less sophisticated attacks.

“Ideally, at the earliest stage of system development, system designers working with information security professionals should create a threat model mapping the system design to technologies, vulnerabilities and threat actors,” Stout noted. “The threat model should be updated and reviewed with each system change and upon discovering new threats and vulnerabilities.”

“Having a threat model allows system owners to identify weak points in their systems, document areas of improvement, and in the case of a Funky Pigeon attack, understand where the attack took place and what aspects of the system were likely exploited by the cyber criminals,” he concluded.


Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":0,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":null,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[],"featured_content_portal_embedded":null}" >