Web.com discloses major data breach

(Image credit: Shutterstock)

Web.com has announced that it as well as Register.com and Network Solutions all suffered a data breach in August.

A disclosure notice that was published across all three sites, revealed that on October 16, the company had “determined that a third-party gained unauthorized access to a limited number of our computer systems in late August 2019, and as a result, account information may have been accessed”.

According to Web.com, contact details including user's names, addresses, phone numbers, email addresses and which web hosting products they had purchased were all acquired by hackers as a result of the data breach.

While customer passwords have been reset as an added precautionary measure, a spokesperson for Web.com explained to Brian Krebs that it encrypts all user passwords and that the company believes no passwords were obtained by the attackers, saying:

“We encrypt account passwords and do not believe this information is vulnerable as a specific result of this incident. As an added precautionary measure, customers will be required to reset passwords the next time they log in to their accounts. As with any online service or platform, it is also good security practice to change passwords often and use a unique password for each service.”

Data breach

Thankfully no credit card data was compromised during the incident which Web.com has already reported to federal authorities.

The web host confirmed in its disclosure notice that all of its customers' credit card numbers are stored in a Payment Card Industry (PCI) compliant encryption standard and that there was no sign that the attackers were able to access users' credit card information. However, Web.com is encouraging customers to monitor their credit card accounts and notify their providers if they do find any suspicious charges.

Security awareness advocate at KnowBe4, Javvad Malik warned that the attackers behind the Web.com data breach may try to use the customer information they acquired to launch phishing attacks, saying:

“Without more details on the incident, it is difficult to establish the objectives of the attackers. It could be possible that this was an opportunistic attack to steal credentials or personal information. It's important for companies of all sizes and verticals to invest in security, especially where customer data is involved, not just payment information. 

"Customers who are affected should change their passwords, and also check their accounts to ensure no changes have been made to any of their details or sites. They should also be extra vigilant against any potential phishing emails that criminals may send using the information stolen from these breaches.”

Via Forbes

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras