Just in:
VinFast expands access to comprehensive aftersales network in France and Germany through agreement with Mobivia // Navigating Business Setup in Dubai: A Comprehensive Guide by Czar Bizserv // NEOM welcomes leading industry figures and investors to Hong Kong showcase as part of its ‘Discover NEOM’ China tour // Boeing Eyes 2030 Launch for Electric Flying Cars // AI Race Heats Up: Meta Unveils Powerful New Llama // Galaxy Macau Unveils the New Galaxy Kidz: An Edutainment Center for Play Time // Sharjah Charity International Extends Helping Hand to Flood Victims // Czar Workspace: a Modern Workspace Solutions in Dubai // UAE Delegation Engages in Arab Parliament Committee Discussions // DFA Hong Kong Young Design Talent Award 2024 // Saadiyat Grove Set for Smart Transformation Through Aldar-Siemens Alliance // Gunfire exchange near Manipur polling booth // Keung To Trams Return! “KeungShow HKFanClub” Sponsor Free Tram Rides for All on 30 April to Celebrate Keung To’s 25th Birthday // Congress Is Set To Perform Well In Lok Sabha Polls In Karnataka // Abu Dhabi Launches ‘Medeem’ Initiative to Promote Emirati Values in Marriage // VT Markets Releases Study on Upcoming Bitcoin Halving and Market Implications // Takeoff After Turbulence: Flydubai Restarts Operations at Dubai International Airport // Petrochemical Storm Clouds Gather Over Saudi Arabia // A Feast Without Footprint – Shiok Kitchen Catering Redefines Delicious Dining with Carbon Neutral Catering // Evolution and current state of global crypto adoption – Octa //

A database of thousands of credit cards was left exposed on the open internet

finding the credit card 604cs052313

New day, new leak.

ADVERTISEMENT

A US online pet store has exposed the details of more than 110,400 credit cards used to make purchases through its website, researchers have found.

In a stunning show of poor security, the Austin, TX-based company FuturePets.com exposed its entire customer database, including names, postal and email addresses, phone numbers, credit card information, and plain-text passwords.

Several customers that we reached out to confirmed some of their information when it was provided by ZDNet, but did not want to be named.

The database was exposed because of the company’s own insecure server and use of “rsync,” a common protocol used for synchronizing copies of files between two different computers, which wasn’t protected with a username or password.

Researchers at the Kromtech Security Research Center found the database in November. But after numerous efforts to contact the company by phone and email, the database was only secured this week.

It’s not clear who’s to blame for the breach. The pet store is understood to have been developed by DataWeb Inc., which has built dozens of other similar pet-related sites and owns PegasusCart, an e-commerce platform, used on all of DataWeb’s sites.

Kromtech researcher Bob Diachenko found that the leaked data wasn’t limited to just FuturePets.com, but also appeared to contain several folders, including one that shows several backup files and databases of transactions within the DataWeb network.

“They have everything in there — from ad campaigns to thousands of orders details, with full customer payment details exposed, with IP addresses tracked down for milliseconds,” said Diachenko, who also blogged about the discovery.

However, there’s no evidence to suggest that any PegasusCart data had been exposed.

Todd Nelson, co-founder of PegasusCart, said in an email that the owners of the site “explained that as of a year or so ago, their data was moved to an outside cloud based e-commerce platform.” (At the time of writing, FuturePets.com still used PegasusCart on its website.)

“If they were breached on their web server and any data were found, it would be very old and likely quite useless, but they jumped into action anyway,” he said.

“They have solicited a security firm to investigate the issue and plug any hole should one exist,” he added, but didn’t say if the company would inform its customers of a breach.

The upside to the story is that the exposure has stopped, but it’s not clear who else may have accessed the data — or if that data, such as credit card information, has been used.

Gone are the days where hackers will target en masse the larger companies, rare as those attacks are, because of the stringent security measures and systems in place. In other words, it’s harder than ever before to target the highest echelons of big business.

Instead, criminals out to make a few bucks are ever increasingly targeting smaller firms, who may not be as invested or knowledgeable in security.

According to Juniper Research, smaller companies usually have “less of a network to keep under control” than larger organizations, but “even small data breaches are likely to take a much larger toll on businesses with a smaller turnover.”

With a data exposure live on the internet for at least six months, there’s no telling where the data has gone. But what’s clear is that if a security researcher found it, it’s possible that others have, too.

(via PCMag)

ADVERTISEMENT

ADVERTISEMENT
Just in:
Sharjah Charity International Extends Helping Hand to Flood Victims // Navigating Business Setup in Dubai: A Comprehensive Guide by Czar Bizserv // UAE Delegation Engages in Arab Parliament Committee Discussions // A Feast Without Footprint – Shiok Kitchen Catering Redefines Delicious Dining with Carbon Neutral Catering // Evolution and current state of global crypto adoption – Octa // Czar Workspace: a Modern Workspace Solutions in Dubai // Abu Dhabi Launches ‘Medeem’ Initiative to Promote Emirati Values in Marriage // Gunfire exchange near Manipur polling booth // Petrochemical Storm Clouds Gather Over Saudi Arabia // Abu Dhabi Environment Agency Endorses ADNOC’s Decarbonization Push // Galaxy Macau Unveils the New Galaxy Kidz: An Edutainment Center for Play Time // Keung To Trams Return! “KeungShow HKFanClub” Sponsor Free Tram Rides for All on 30 April to Celebrate Keung To’s 25th Birthday // The International Exhibition of Inventions in Geneva Reveals More than 40 Scientific and Technological Innovation Achievements from Hong Kong // Boeing Eyes 2030 Launch for Electric Flying Cars // Global Cooperation Takes Center Stage at Dubai International Humanitarian Aid and Development Conference and Exhibition // Emirates Offer Support as Wildfires Ravage Greece // VinFast expands access to comprehensive aftersales network in France and Germany through agreement with Mobivia // UN Acknowledges Uneven Progress on Energy Goals During Sustainability Week // Saadiyat Grove Set for Smart Transformation Through Aldar-Siemens Alliance // DFA Hong Kong Young Design Talent Award 2024 //