American fast food restaurant chain Five Guys announced a data breach in a recent letter from COO Sam Chamberlain to customers.
according to lettera security incident occurred in September 2022, exposing sensitive customer data by an unauthorized third party with access to a file server.
The stolen data includes personally identifiable information (PII) of employees such as names, social security numbers, and driver’s license numbers.
“This is yet another incident in which an attacker successfully penetrated an organization’s network, and the victim whose data was stolen was not notified until months later, allowing the attacker to use that information to gain credibility.” It gave them plenty of time to commit fraud and identity fraud,” said Julia O’. Tools, CEO MyCena Security Solution.
Additionally, according to Founder and CTO Casey Ellis: bug cloudit is likely that Five Guys’ recruiting system, where candidates upload their resumes, was compromised.
“Having this kind of system available on the Internet makes sense given the recruitment and job-seeking process, but if it is more accessible to the general public, potential attackers will also take advantage of it. It makes it easier,” Ellis said. Information security.
“Common web coding flaws such as indirect object references (IDOR), authentication flaws, and even injection flaws can allow this kind of attack outcome without the need for lateral movement. “
John Bambanek, Chief Threat Hunter Netenrichadded that the most direct use of this data is to recognize that there are a small number of people at the lower end of the economy looking for work.
“I expect these people to be sent scams and mule-recruiting decoys in the near future,” added Bambenek. “Given the industry, I don’t see a viable attack vector for Five Guys itself unless part of their resume is a ‘back office’ type of staff.”
In the letter, the company said it arranged for affected customers to receive free credit monitoring and identity protection services through IDX as compensation.
“These identity protection services include one year of credit and CyberScan monitoring, a $1 million insurance reimbursement policy, and a fully managed identity theft recovery service,” the company wrote. .
The data breach, which has just been disclosed, came weeks before the exfiltration of KFC and McDonald’s customers. Targeted via phishing campaigns Last October, it crossed Saudi Arabia, the UAE and Singapore.