Remove Authentication Remove Data breaches Remove Information Security Remove Social Engineering
article thumbnail

Cisco Duo warns telephony supplier data breach exposed MFA SMS logs

Security Affairs

Cisco Duo warns that a data breach involving one of its telephony suppliers exposed multifactor authentication (MFA) messages sent by the company via SMS and VOIP to its customers. ” reads the data breach notification send to the impacted individuals. date and time of the message, type of message, etc.).”

article thumbnail

Okta discloses a new data breach after a third-party vendor was hacked

Security Affairs

Okta warns approximately 5,000 employees that their personal information was compromised due to a third-party vendor data breach. “On October 12, 2023, Rightway informed Okta that an unauthorized actor gained access to an eligibility census file maintained by Rightway in its provision of services to Okta.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

CafePress faces $500,000 fine for data breach cover up

Malwarebytes

As well as over 180,000 unencrypted Social Security Numbers (SSNs), along with tens of thousands of partial payment card numbers (last 4 digits) and expiration dates. A treasure trove for social engineers. Informing customers. CafePress has already settled with seven US states as a result of this data breach.

article thumbnail

Twilio discloses data breach that impacted customers and employees

Security Affairs

Communications company Twilio discloses a data breach after threat actors have stolen employee credentials in an SMS phishing attack. Communications company Twilio discloses a data breach, threat actors had access to the data of some of its customers. SecurityAffairs – hacking, data breach).

article thumbnail

MongoDB investigates a cyberattack, customer data exposed

Security Affairs

.” At this time, we are not aware of any exposure to the data that customers store in MongoDB Atlas.” ” The US firm urges customers to be vigilant for social engineering and phishing attacks. However, the company states that the activity is not related to the security incident.

article thumbnail

Threat actors breached Okta support system and stole customers’ data

Security Affairs

Okta says that threat actors broke into its support case management system and stole authentication data, including cookies and session tokens, that can be abused in future attacks to impersonate valide users. HAR files can also contain sensitive data, including authentication information.

article thumbnail

Okta customer support system breach impacted 134 customers

Security Affairs

In October, the Cloud identity and access management solutions provider said that threat actors broke into its support case management system and stole authentication data, including cookies and session tokens, that can be abused in future attacks to impersonate valid users.