Tag Archive for: datastealing

Gulp! Pepsi hack sees personal information stolen by data-stealing malware


Towards the end of last year, malicious hackers broke into the systems of Pepsi Bottling Ventures, the largest privately-owned bottler of Pepsi-Cola beverages in the USA, and installed malware.

For almost the month the malware secretly exfiltrated personally identifiable information (PII) from the company’s network.

The first Pepsi Bottling Ventures knew about the unauthorized access to its network was on January 10 2023, but it took a further nine days until the organisation completely shut the attackers out of its systems.

As Bleeping Computer reports, a notification letter sent to affected individuals confirms that a worrying array of information was stolen:

  • Full name
  • Home address
  • Financial account information (including passwords, PINs, and access numbers)
  • State and Federal government-issued ID numbers and driving license numbers
  • ID cards
  • Social Security Numbers (SSNs)
  • Passport information
  • Digital signatures
  • Information related to benefits and employment (health insurance claims and medical history)

Clearly the potential exists for cybercriminals to exploit the information stolen from the company’s network to launch phishing attacks and attempt to commit identity theft.

What isn’t clear from the notification letter is how many people may be affected by the data breach, and whether any business partners or customers are impacted. It certainly appears, from the information shared so far, that the information stolen relates to Pepsi employees.

Affected individuals are being offered free identity monitoring for one year.  Pepsi is also recommending that users change their login credentials, and ensure that they are not using the same password anywhere else on the internet.

The company says that it has informed law enforcement agencies of the attack, reset company passwords, and put in place additional measures to secure its network.

Source…

EwDoor Malware Infects AT&T Users: How to Detect Data-Stealing Virus, Remove from Your Phone


EWDoor malware infected the networking equipment of AT&T, which protects and manages communications of the mobile carrier.

The said AT&T malware affected more than 5,700 subscibers.

EWDoor Malware Affects AT&T Subscribers

Chinese cybersecurity company, Qihoo 360, found out that thousands of networking equipment belonging to AT&T subscribers in the United States have been compromised with newly acquired malware, per Ars Technica.

Gizmodo reported that the AT&T malware acts as a backdoor, allowing an attacker to get into networks, steal data and engage in other activities.

Moreover, the said attacked device is named EdgeMarc Enterprise Session Border Controller. This tool is used by small and medium companies to protect and manage phone calls, video conferencing and other real-time communications.

In addition to this, session border controllers, the link connecting businesses and their Internet service providers, have access to a wide range of bandwidth and may obtain sensitive personal information, making it perfect for distributed denial of service (DDoS) attacks and data gathering.

Since the AT&T malware acts as a backdoor, it was named EWDoor by Qihoo 360, which is a word play of the “backdoor,” referring to the fact that it affects Edgewater devices.

In addition to this, EWDoor malware can update on its own, do port scanning, organize files, DDoS attack, reverse shell, and unprecedented command execution.

For those who do not know what DDoS is, Kaspersky stated that it is a method of attack that takes advantage of internet resource capacity limitations.

The DDoS attack will make several demands towards the targeted online resource. Aside from this, it also aims to surpass the website’s capabilities, accommodate numerous request and prevent it from working properly.

Read Also: Apple Hack for Students, Teachers: How to Get $400 Discount on Your Mac, iPad Purchase

On the other hand, Qihoo 360 researchers identified the EWDoor malware after infiltrating a previously undisclosed botnet, revealing that it had affected at least 5,700 AT&T subscribers in the United States.

They also claimed to have discovered more than 100,000 devices using the same TLS certificate as…

Source…

Android security: This fake message about a missed delivery leads to data-stealing malware – ZDNet

Android security: This fake message about a missed delivery leads to data-stealing malware  ZDNet
“android security news” – read more

Critical Android Data-Stealing Security Threat Confirmed For Almost All Android Versions – Forbes

Critical Android Data-Stealing Security Threat Confirmed For Almost All Android Versions  Forbes
“android security news” – read more