fbpx
Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Penetration Testing

          Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Minted discloses data breach after 5M user records sold online

Minted discloses data breach after 5M user records sold online

Minted, a US-based marketplace for independent artists, has disclosed a data breach after a hacker sold a database containing 5 million user records on a dark web marketplace.

Minted is an online marketplace that allows independent artists to submit their art, which is then voted on by the Minted community. The winning submissions are then sold as art, home décor, and stationery to consumers.

Earlier this month, BleepingComputer reported that a hacking group named Shiny Hunters was selling the user records for eleven companies on a dark web marketplace. 

One of these databases allegedly contained 5 million users and mailing address records for Minted. This database was being sold for $2,500.

Dark web marketplace ad for Minted database

Based on samples of the database seen by BleepingComputer, the user records included a user’s email address and their blowfish hashed passwords.

Sample of the sold user database

The second database table contained mailing addresses and phone numbers of Minted users.

At the time of our reporting, BleepingComputer emailed Minted but never received a response.

Since our original reporting of these databases, Chatbook and Home Chef have also issued data breach notifications.

Minted issues data breach notification

Now, almost three weeks later, Minted has started to notify users that they were affected by a data breach after their systems were hacked.

According to Minted’s data breach notification, the attackers gained access to the company’s user database on May 6th, 2020.

“The information involved includes customers’ names and login credentials to their Minted accounts, consisting of their email address and password. The passwords were hashed and salted and not in plain text. Telephone number, billing address, shipping address(es), and, for fewer than one percent of affected customers, date of birth, also may have been impacted,” Minted states in their data breach notification.AD

Minted states that they do not believe credit card information, customer address book information, or photos or personalized information that customers added to Minted designs were accessed during the breach.

What Minted customers should do

While the passwords leaked in this data breach were encrypted, threat actors can use programs to dehash the password.

After a user’s password is cracked, threat actors would be able to use them in credential stuffing attacks at other sites.

Therefore, if you are a Minted customer, you should immediately change your password to a strong and unique one.

If that same password was used at another site, you should change it at any other site that also uses it.

When changing your passwords, be sure to use a unique and strong password at every site so that a data breach does not affect your account at other companies.

A password manager can make it much easier to use unique passwords at every site and is highly recommended.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us