Attacks/Breaches

6/11/2018
11:20 AM
50%
50%

Dixons Carphone Hack Compromises 5.9M Payment Cards

The UK electronics retailer says the hack, which began last July, also involves 1.2M personal data records.

Dixons Carphone, a major UK electronics retailer, has alerted shoppers to a data breach involving 5.9 million payment cards and 1.2 million personal data records. There is no evidence any cards have been misused following the incident, which is under investigation, Dixons says.

The hacking attempt began last July, with attackers attempting to break into processing systems belonging to Currys PC World and Dixons Travel stores, the company says. Fortunately, the majority of compromised cards were equipped with chip-and-pin security, so only 105,000 cards without that level of protection were affected.  

Dixons says it only discovered the hack a week ago and that it's not linked to a security incident that occurred in 2015, which resulted in a £400,000 fine from the UK Information Commissioner's Office (ICO). Experts say this is a wake-up call for organizations to buckle down on security, especially with the European General Data Protection Regulation in effect.

"The Dixons Carphone breach highlights the need for organizations to maintain strong security practices," says Michael Magrath, director of global regulations and standards at OneSpan. "With shake-ups to data protection legislation such as the GDPR now being in force, businesses face huge fines for breaches and lax data security protocols."

Read more details here.

 

Top industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Click for more information

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
12 Free, Ready-to-Use Security Tools
Steve Zurier, Freelance Writer,  10/12/2018
Most IT Security Pros Want to Change Jobs
Dark Reading Staff 10/12/2018
6 Security Trends for 2018/2019
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/15/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10839
PUBLISHED: 2018-10-16
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
CVE-2018-13399
PUBLISHED: 2018-10-16
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
CVE-2018-18381
PUBLISHED: 2018-10-16
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type header during the uploading of image attachments.
CVE-2018-18382
PUBLISHED: 2018-10-16
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.