Gulp! Pepsi hack sees personal information stolen by data-stealing malware

Late last year, malicious hackers compromised the systems of Pepsi Bottling Ventures, the largest privately owned Pepsi Cola beverage bottler in the United States, and installed malware.

For nearly a month, malware quietly exfiltrated personally identifiable information (PII) from corporate networks.

Pepsi Bottling Ventures first learned of the compromised network on January 10, 2023, but it took another nine days for the organization to completely lock the attacker out of their systems.

As beeping computer Notifications sent to affected individuals reportedly confirm a range of concerning information was stolen.

  • full name
  • Home Address
  • financial account information (including passwords, PINs and access numbers);
  • State and federal ID numbers and driver’s license numbers
  • Identification
  • Social Security Number (SSN)
  • passport information
  • digital signature
  • Welfare/employment information (health insurance card/medical history)

It is clear that cybercriminals can use information stolen from corporate networks to launch phishing attacks and attempt to steal identity.

What is not clear from the notice is how many people could be affected by a data breach and whether business partners or customers would be affected. From the information shared so far, it is certain that the stolen information is related to Pepsi employees.

Affected individuals will be provided with one year of free identity monitoring. Pepsi also recommends that users change their login credentials and make sure they aren’t using the same password elsewhere on the internet.

The company said it notified law enforcement of the attack, reset company passwords, and took additional measures to protect its network.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *