Carphone Warehouse fined after failures put customer and employee data at risk
ico.org.uk
ico.org.uk
One day, out of the blue I answered the number and there was someone on the other end of the line. I then went through a difficult conversation where I attempted to get out of them why they were phoning me. I found out, (1) the company was called something ridiculous like the "phone delivery depot for your provider" and they were trying to sell mobile phone contracts by using that name when answering calls "Hi this is the 'hone delivery depot for your provider'", I kid you not. He even claimed to be from my mobile provider at one point (no he wasn't, I'd already checked that when I attempted to get them to block the calls.) (2) the guy on the other end of the phone knew quite a bit about me, so had access to data from a third party. (3) it was a total phishing exercise and they were trying to get fees for reselling the customers new fixed term contracts to them after they had become rolling monthlies.
After laying in to him I finally got the route of the data. "We get a lot of our leads from Carphone Warehouse." BING!! The moral of this story is, always read the fine print. I probably in haste missed a tick box or ticked the wrong box - or the girl serving me "helpfully" did it for me on their computer system without asking. Carphone Warehouse are a scummy company, with bad practices, and best advice is to avoid at all costs!
http://www.tpsonline.org.uk/tps/index.html
Takes 5 minutes.
GP already was.
If you've inadvertently agreed to marketing by overlooking some opt-out section of a contract then that counts as consent and TPS means nothing:
https://ico.org.uk/for-organisations/guide-to-pecr/electroni...
The problem was, I needed to answer my phone as I was working away from home at the time. Any of the calls could have been a valid call about my real life. I often got calls from people not in my contact list.. from random clients, my kids' schools, data centres or related to work.
Apparently it has been reported multiple times, but the company doesn't have a well defined presence in UK, so they dodge any persecution.
Once they identified the vulnerability to exploit, it seems they used genuine credentials to then place webshells on the server which gave them persistence - a low-level reverse shell if you will, allowing them to traverse the file system, execute commands as if they had genuine access. Next up, a quick grep for plaintext credentials that they can then pivot with. There are still questions around how those credentials were obtained, but they'd don't specifically call them out as being default.
The report then jumps to the person accessing databases (including payment card info.. whoops) - the question here is why did a Wordpress instance have access to such data? I can't imagine it would have needed it, so I suspect that they either had one huge DB server containing the backend for this WordPress instance, plus their customer data & payment info databases/tables. Or, the malicious actor traversed the internal network, using the WordPress as a pivot point.
Last point worth calling out, is that they are unsure how much of the data was actually exfiltrated - "[...] the transaction/payment card information referred to above was located and accessed: it cannot be ascertained whether or not some or all of that information was indeed exported, but that is a very realistic possibility." This is a common problem with breaches, and an area what active monitoring can help. By planting unique details/tokens into the database (users, payment information etc.), you can start scanning for them on the clear and dark web. As and when they appear, you can confirm if the data was exfiltrated (and with many honeypots, pinpoint time of the breach). This is one of the many reasons I put BreachInsider[0] together.
I jump through hoops to get a £7 train ticket paid.
If they let a £10 train ticket slide for each employee it would be more than this fine.
There have been cases where spam companies have done 100m SMS/phone calls and got a £100K fine (which they can just prepack away). It's probably a tenth of their telecom cost per call. Just a cost of doing business.
In this case, it's a company that's not actively trying to be malicious, but rather due to [cost-saving/incompetence] has underfunded IT security to an excessive degree. For them, and others like them, to change their ways it's a lot less self evident that the fine needs to be huge. The fine (and accompanying reputational damage) just needs to be enough to make them, and similar companies, take IT security seriously.
Very different situations, really.
£400k is nothing.
While I agree with many others that this is a small fee all things considered, it does put other companies on notice: secure your shit or you'll be held liable (to some degree at least).
400k is not even a slap on the wrist. I'm disappointed.
On the one hand, it's good to see an organisation receiving a real financial penalty after a serious breach, and apparently there were many serious failings in security on the part of Carphone Warehouse.
On the other hand, reading the Commissioner's views in the notice, there is a disturbing amount of commentary about measures not in place at Carphone Warehouse that asserts apparently without evidence that such measures are widely accepted security standards, either acknowledges that these measures may not have made any difference to this kind of attack anyway or implies again apparently without evidence that they would, and then considers the lack of each such measure to be a contravention in its own right.
I'm not sure this is a good thing, because if we took the principles indicated by those views and applied them more generally, I'm not sure many if any organisations would meet the required standards here.
For example, how many organisations that use WordPress to run their web sites have measures in place to detect unauthorised use of legitimately issued WordPress credentials? What would that even look like?
How many small organisations have a dedicated WAF box installed, or the money to run regular independent pentesting or hire suitably qualified in-house staff to do it? (Obviously we're not talking about a small organisation in the case at hand, so maybe the ICO would apply a more liberal standard in other situations.)
There is a reference to transaction data being encrypted but the encryption key being present in plain text in the application source code. Well, OK, but that key has to be present somewhere accessible on the system or you can't access the data at all even for legitimate purposes. If you've got an attacker who apparently already has access to both your database and your runtime system, I'm not sure what alternative they would have preferred to see that would have mitigated the damage materially here. Does it really matter whether the attacker looks at source code or somewhere else like environment strings, if the end result is the same either way?
Compared to obviously terrible practices like not updating externally accessible software for many years so the live version has multiple known vulnerabilities or storing full credit card data including things like CVCs for all historical transactions, some of the issues raised here seem both much more dangerous and much more practically mitigable than others.
Install the free Wordfence plugin and you'll get an e-mail whenever someone logs in using an admin account.
I limit SSH access to my ISPs net blocks, that's just a hobbyists personal computer on which I have no legal obligation to protect the data.
Otherwise it reads -- to me, a layman in these things -- like the standard pontification you get out of a prosecutor when they're showing off to the press.
But it doesn't have to be in available code without even obfuscation. As a non-programmer I'd expect bare minimum to XOR it.
Perhaps they should have read SO, https://stackoverflow.com/questions/764012/how-do-you-hide-s....
Please excuse my ignorance.
https://www.linkedin.com/pulse/day-31-write-every-carphone-w...
Each dynamic function remotely hosted by 3rd-party who knows security.