Question

security incidents select a recent security incident that had their data stolen by an outside attack,...

security incidents

select a recent security incident that had their data stolen by an outside attack, insider threat, or some other mechanism.  There are multiple examples that can be used, i.e., Target, Capital One, Home Depot, OPM, etc.  v

0 0
Add a comment Improve this question Transcribed image text
Answer #1

Uniqlo Suffers Credential Stuffing Cyber Attack:

Fast Retailing is the company behind multiple Japanese retail brands including Uniqlo, which is confirmed in an official statement, is the latest victim to a credential stuffing attack. The company said that from April 23 to May 10, 2019, there was fraudulent login to 461,091 accounts [so far as it is still under investigation.

According to the statement, “We deeply apologize to our customers and stakeholders for any inconvenience or concern. We will strive to further enhance security and ensure safety so that similar events do not occur.”

Attack Details Known So Far:

The number of customer accounts for which unauthorized login has been confirmed: UNIQLO official online store-Gyu registered 461,091 items.

The personal information of customers who may have been browsed:

  • Customer's name (first name, last name, phonetic)
  • Customer's address (zip code, city, county, street address, room number)
  • Phone number, mobile phone number, e-mail address, gender, date of birth, purchase history, name and size registered in My Size
  • Shipping name (first name, last name, address), phone number
  • Part of credit card information (cardholder, expiration date, part of credit card number). Credit card numbers are hidden except for the first four digits and the last four digits. CVV numbers (credit card security codes) are not displayed or stored, so there is no possibility of leakage.

Once the company identified the communication origin where unauthorized login was attempted, it blocked access and strengthened monitoring on other accesses. For the 461,091 user IDs where personal information may have been viewed, the password has been invalidated on May 13, and e-mails were sent asking customers to reset passwords. In addition, the case was reported to the Tokyo Metropolitan Police Department.

Fast Retailing urges its customers using its online store site to cooperate by:

  1. Setting a password different from other company's services.
  2. Do not use passwords that third parties can easily guess.

“We recognize that the protection of customer information is our top priority, and we sincerely accept the occurrence of this situation and maintain an environment where customers can shop more safely and securely, such as strengthening monitoring of unauthorized logins,” the company said.

While the number of Fast Retailing online customers is not public, "Internet sales made up 10% of domestic sales in the first half of the company’s current fiscal year," as Bloomberg initially reported.

How To Prevent Credential Stuffing

Since the beginning of 2019, there have already been a handful of successful credential stuffing attacks which managed to infiltrate the computing systems of TurboTax, Dunkin' Donuts, Basecamp, and Dailymotion, as reported by bleeping computer. It said that cybercriminals behind credential stuffing campaigns have designed them to be completely automated, making use of large collections of stolen credentials bought from underground markets to be able to take over customer accounts.

According to Akamai Research, it recorded nearly 30 billion credential stuffing attacks in 2018. Some tips for businesses to avoid credential stuffing attacks include:

-Partner with a solid solutions provider to help detect and stop credential stuffing attacks.

-Ensure a defensive solution is tailored to the businesses, as criminals will adjust their attacks accordingly to evade out-of-the-box configurations.

-Users need to be educated about credential stuffing attacks, phishing and other risks that put their account information in jeopardy.

-Brands should stress the importance of unique passwords and password managers to customers and highlight the value of multi-factor authentication.

Add a comment
Know the answer?
Add Answer to:
security incidents select a recent security incident that had their data stolen by an outside attack,...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • Select a recent, within ten years, cybersecurity case in which security broke down, or were security...

    Select a recent, within ten years, cybersecurity case in which security broke down, or were security was breached.   Target, Equifax, Home Depot, Sony, the OPM are common topics, and one may chose one of these, but I would prefer if one found a less common, but equally challenging case to evaluate.

  • There have been some major data breaches in recent years - including Equifax, Capital One, Target,...

    There have been some major data breaches in recent years - including Equifax, Capital One, Target, Home Depot, Facebook etc [You can find a complete list here: All of these breaches increase the likelihood of you or your friends becoming a victim of identity theft. Detail what actions you have taken or will take to protect yourself from this risk. Further, describe what you would advise a friend or client to do if their identity has been stolen.

  • CASE STUDY U.S. Office of Personnel Management Data Breach: No Routine Hack The U.S. Office of...

    CASE STUDY U.S. Office of Personnel Management Data Breach: No Routine Hack The U.S. Office of Personnel Management (OPM) is conducted, may have been extracted. Government offi responsible for recruiting and retaining a world-class cials say that the exposure of security clearance irn workforce to serve the American people and is also mation could pose a problem for years responsible for background investigations on pro- spective employees and security clearances. In June the OPM system, and its records were protected...

  • Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around...

    Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...

  • A new version of the operating system is being planned for installation into your department’s production...

    A new version of the operating system is being planned for installation into your department’s production environment. What sort of testing would you recommend is done before your department goes live with the new version? Identify each type of testing and describe what is tested. Explain the rationale for performing each type of testing. [ your answer goes here ] Would the amount of testing and types of testing to be done be different if you were installing a security...

  • Project 7-1: Classify Patient Incidents According to Policy This primary source of information on patient safety...

    Project 7-1: Classify Patient Incidents According to Policy This primary source of information on patient safety will be used to analyze the incidents according to level of severity. The following policies define the three categories of severity Policy on Level I Event: An incident that resulted in patient death or serious short or long-term (6 weeks or more) disability or harm Policy on Level II Event: An incident that resulted in minimal short-term patient disability or harm Policy on Level...

  • MGMT SS STATS, an umbrella body that facilitates and serves various Social Security Organizations...

    MGMT SS STATS, an umbrella body that facilitates and serves various Social Security Organizations/Departments within the Caribbean territories, stood poised to meet the needs of its stakeholders by launching an online database, located at www.SSDCI.gov. The database will provide members and the public with access to the full set of services that can (also) be initiated face to face; and it will provide managed, private, secure access to a repository of public and/or personal information. For example, insured persons accumulate...

  • The discussion: 150 -200 words. Auditing We know that computer security audits are important in business....

    The discussion: 150 -200 words. Auditing We know that computer security audits are important in business. However, let’s think about the types of audits that need to be performed and the frequency of these audits. Create a timeline that occurs during the fiscal year of audits that should occur and “who” should conduct the audits? Are they internal individuals, system administrators, internal accountants, external accountants, or others? Let me start you: (my timeline is wrong but you should use some...

  • TRUE/FALSE QUESTIONS:  Foundations of Information Security and Assurance 1. There is a problem anticipating and testing for...

    TRUE/FALSE QUESTIONS:  Foundations of Information Security and Assurance 1. There is a problem anticipating and testing for all potential types of non-standard inputs that might be exploited by an attacker to subvert a program. 2. Without suitable synchronization of accesses it is possible that values may be corrupted, or changes lost, due to over-lapping access, use, and replacement of shared values. 3. The biggest change of the nature in Windows XP SP2 was to change all anonymous remote procedure call (RPC)...

  • THE CASE Sameer Arkell and Marcy Haddow had worked for Crowdsite, an international computer repair service,...

    THE CASE Sameer Arkell and Marcy Haddow had worked for Crowdsite, an international computer repair service, for ten years. It therefore came as a surprise when they both received lay-off notices on a Friday afternoon early January 2015. Both were given severance packages that matched their seniority so they decided that this might be the catalyst to launch their own business repairing computers and related equipment for businesses in their community. Both were single and had no children, so no...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT