• Zola wedding registry accounts hacked, company refuses to bring i

    From TechnologyDaily@1337:1/100 to All on Tue May 24 15:45:04 2022
    Zola wedding registry accounts hacked, company refuses to bring in 2FA

    Date:
    Tue, 24 May 2022 14:28:52 +0000

    Description:
    Zola credential stuffing attack worked and accessed some customer accounts, the company confirmed

    FULL STORY ======================================================================

    Cybercriminals were able to gain access to a number of user accounts at wedding planner website Zola, hijacking them to try and purchase gift vouchers, the company has confirmed.

    The news first popped up on social media as Zola users took to Twitter and Reddit to notify others of unauthorized account access, and multiple attempts at making purchases.

    Others found compromised Zola accounts for sale on the black market, but the company was quick to play down the seriousness of the news.

    Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022 . Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/10.99. Credential stuffing and weak passwords

    We understand the disruption and stress that this caused some of our couples, but we are happy to report that all attempted fraudulent cash fund transfer attempts were blocked, said Emily Forrest, Zola director of communications. Credit cards and bank info were never exposed and continue to be protected.

    Zolas infrastructure and endpoints were apparently not breached, with the criminals using a credential stuffing technique, in which the attackers try numerous username/password combinations, until one sticks. Credential
    stuffing usually works on victims who use the same username/password combination across a multitude of services.

    Forrest added that the company spotted a number of fraudulent gift card
    orders and that its currently addressing the issue, noting that less than
    0.1% of accounts were affected. Read more

    Prevent credential stuffing attacks through attack cost analysis


    New York warns over a million users of top websites may have had data
    stolen


    Microsoft Edge update will make sure you're never locked out of an account
    again

    However Zola did confirm it had reset all user passwords after learning of
    the breach. Mobile apps for both platforms were also disabled during the incident, but have since been reactivated.

    Despite the ability to link bank accounts with that on Zola, the latter does not provide any secondary authentication feature, such as an app for two-factor authentication ( 2FA ), security keys, and the like. That, TechCrunch argues, makes credential stuffing attacks easier to pull off.

    Security experts will usually recommend creating a strong, unique password
    for every service. While that may sound like a major nuisance, a good
    password manager can take away all of the annoyance of managing numerous unique passwords. Monitor all of the traffic on your network with the best firewalls around

    Via: The Verge



    ======================================================================
    Link to news story: https://www.techradar.com/news/zola-wedding-registry-accounts-hacked-company-r efuses-to-bring-in-2fa/


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)