Cloud

6/29/2018
10:29 AM
50%
50%

Adidas US Website Hit by Data Breach

The athletic apparel firm was hacked and data on potentially 'millions' of customers now at risk.

Adidas is the latest retailer to get hit with a data breach: the athletic apparel firm said it's alerting some customers that their data may have been exposed due to a newly discovered hack of its US website.

"On June 26, Adidas became aware that an unauthorized party claims to have acquired limited data associated with certain Adidas consumers," the company said in a statement on its website. Customer contact information, usernames, and encrypted passwords were exposed in the data breach.

According to some press reports, an Adidas spokesperson said the attack could have affected "millions" of customers. Adidas did not elaborate on the number of victims in its statement.

"Adidas has no reason to believe that any credit card or fitness information of those consumers was impacted," the company said, and it's currently working with security firms and law enforcement in an investigation into the attack. 

Read more here. 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
7/3/2018 | 6:08:27 AM
Re: Adidas has no reason to believe that any credit card or fitness information of those consumers was impacted
@Ryan: Not every breach has to involve payment information.


Even without the encrypted passwords, we are absolutely talking about PII: usernames + contact information. And very little contact info indeed is needed to perpetuate notable harm.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
6/29/2018 | 2:07:53 PM
Adidas has no reason to believe that any credit card or fitness information of those consumers was impacted
When this is the case I believe the event to be an incident but not a breach. Release an email to the affected that you will be forcing a password change. Unless you can confirm that sensitive data sets were acquired I don't think there is any reason to declare a breach and it is more difficult to back track than it is to escalate severity once more data is found.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
6/29/2018 | 2:03:05 PM
More to come....hopefully
When these go public there is many times a lack of detail until the Incident Report is released. These are the logistics I typically concern myself with. 
Crowdsourced vs. Traditional Pen Testing
Alex Haynes, Chief Information Security Officer, CDL,  3/19/2019
BEC Scammer Pleads Guilty
Dark Reading Staff 3/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Insider Threat Prevention activated!
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-7238
PUBLISHED: 2019-03-21
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
CVE-2017-16253
PUBLISHED: 2019-03-21
An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012 for the cc channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriti...
CVE-2017-16254
PUBLISHED: 2019-03-21
An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can send an authenticated HTTP re...
CVE-2017-16255
PUBLISHED: 2019-03-21
An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can send an authenticated HTTP re...
CVE-2018-3968
PUBLISHED: 2019-03-21
An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy i...