LaCie admits hack went unnoticed for a year

Hacker
LaCie didn't see the hacker signs

Hard drive maker LaCie has admitted that it was the victim of a hacking incident that went unnoticed for almost a year.

The Seagate-owned firm was notified by the FBI towards the end of March about an unauthorised access of personal customer information from its website.

LaCie believes that transactions made between March 27, 2013 and March 10, 2014 are affected, and information stolen could include names, addresses, email addresses, credit card numbers and expiration dates, and login and password credentials.

While LaCie did not specify how the attack occurred, security blogger Brian Krebs suggested that vulnerabilities in Adobe ColdFusion were exploited.

LaCie said it has temporarily disabled the shop on its website while it moves to a more secure payment service. It also hired a forensic investigation firm to explore the issue and help improve its security.

'Embarrassing'

The hack is made worse because LaCie also offers a series of security-focused hard drive products for business use. While the products have not been affected, the company's lack of awareness about its own online security will create customer doubts.

"Customers should also be asking the company tough questions about why it didn't spot the intrusion earlier, and whether it had put enough resources into properly penetration testing its site to find and resolve weaknesses," said Graham Cluley, an independent security consultant, on his blog.

Cluley labelled the incident "deeply embarrassing," and recommended that LaCie customers keep an eye on their credit card bills for unusual activity, as well as ensuring their LaCie password is not in use anywhere else.

He warned other companies not to become "smug" or complacent about their own security.

Via BBC

TOPICS
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand