TechCrunch News 2024年11月12日
Amazon confirms employee data stolen after hacker claims MOVEit breach
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

亚马逊确认,其员工数据在第三方供应商遭遇“安全事件”后遭到泄露。泄露的信息包括员工的工作联系方式,如工作邮箱、办公电话和办公地点等。据称,此次泄露事件与去年MOVEit Transfer软件的大规模漏洞利用有关,黑客声称已经获取了超过280万条数据,并计划陆续公开更多数据。亚马逊表示,其自身系统安全并未受到影响,泄露数据不包含敏感信息,如社保号码或财务信息。第三方供应商已修复安全漏洞。此次事件凸显了供应链安全的重要性,以及数据泄露对企业和员工带来的潜在风险。

🤔亚马逊确认员工工作联系信息(工作邮箱、办公电话、办公地点等)在第三方物业管理供应商的安全事件中泄露。

⚠️泄露事件疑似与2023年MOVEit Transfer软件的零日漏洞利用有关,黑客声称已获取超过280万条数据。

🛡️亚马逊表示其自身系统安全未受影响,泄露数据不包含敏感信息,如社保号码或财务信息。

🔧第三方供应商已修复导致数据泄露的安全漏洞。

🚨此次事件再次提醒企业关注供应链安全,以及数据泄露带来的潜在风险。

Amazon has confirmed that employee data was compromised after a “security event” at a third-party vendor.

In a statement given to TechCrunch on Monday, Amazon spokesperson Adam Montgomery confirmed that employee information had been involved in a data breach.

“Amazon and AWS systems remain secure, and we have not experienced a security event. We were notified about a security event at one of our property management vendors that impacted several of its customers including Amazon. The only Amazon information involved was employee work contact information, for example work email addresses, desk phone numbers, and building locations,” Montgomery said.

Amazon declined to say how many employees were impacted by the breach. It noted that the unnamed third-party vendor doesn’t have access to sensitive data such as Social Security numbers or financial information and said the vendor had fixed the security vulnerability responsible for the data breach.

The confirmation comes after a threat actor claimed to have published data stolen from Amazon on notorious hacking site BreachForums. The individual claims to have more than 2.8 million lines of data, which they say was stolen during last year’s mass-exploitation of MOVEit Transfer.

The threat actor, operating under the alias “Nam3L3ss” claims to have published data allegedly stolen from 25 major organizations, cybersecurity firm Hudson Rock reports.  

“What you have seen so far is less than .001% of the data I have,” the threat actor claims. “I have 1,000 releases coming never seen before.”

TechCrunch has contacted the other organizations listed by the threat actor but has not yet received any further responses. 

The MOVEit breach, which saw attackers exploit a zero-day vulnerability in Progress Software’s file-transfer software, was the biggest hack of 2023. 

These hacks, which were claimed by the notorious Clop ransomware and extortion gang, impacted more than 1,000 organisations, including the Oregon Department of Transportation (3.5 million records stolen), the Colorado Department of Health Care Policy and Financing (four million) and U.S. government services contracting giant Maximus (11 million).

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

亚马逊 数据泄露 MOVEit 第三方供应商 网络安全
相关文章