{"id":11922,"date":"2018-04-03T14:10:03","date_gmt":"2018-04-03T22:10:03","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2018\/04\/03\/news-5691\/"},"modified":"2018-04-03T14:10:03","modified_gmt":"2018-04-03T22:10:03","slug":"news-5691","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/04\/03\/news-5691\/","title":{"rendered":"Panerabread.com breach could have impacted millions"},"content":{"rendered":"<p><strong>Credit to Author: Wendy Zamora| Date: Tue, 03 Apr 2018 20:53:29 +0000<\/strong><\/p>\n<p>Customers who signed up for a Panerabread.com account in order to order fast-casual baked goods may want to guard their dough. Security researcher <a href=\"https:\/\/krebsonsecurity.com\/2018\/04\/panerabread-com-leaks-millions-of-customer-records\/\" target=\"_blank\" rel=\"noopener\">Brian Krebs reported yesterday<\/a> that the website for the bakery chain leaked millions of customer records, including names, emails, physical addresses, birthdays, and the last four digits of customers&#8217; credit card numbers.<\/p>\n<p><span style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen-Sans, Ubuntu, Cantarell, 'Helvetica Neue', sans-serif;\">Until Monday, millions of customer data points were accessible on the site as plain text\u2014an oversight that Krebs maintains left data exposed for at least eight months. While Panera was contacted by security researcher Dylan Houlihan back in August 2017 about the leak, it appears <a href=\"https:\/\/medium.com\/@djhoulihan\/no-panera-bread-doesnt-take-security-seriously-bf078027f815\" target=\"_blank\" rel=\"noopener\">they did not take action to fix it<\/a>, despite reassurances they were working on a resolution.<\/span><\/p>\n<p><span style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen-Sans, Ubuntu, Cantarell, 'Helvetica Neue', sans-serif;\">Once Krebs notified Panera about the breach, the company took its website offline for a brief period of time. When the site came back online, the customer data was no longer available. <\/span><\/p>\n<p><span style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen-Sans, Ubuntu, Cantarell, 'Helvetica Neue', sans-serif;\">Panera issued statements to the press that they moved to fix the breach hours after Krebs reached out to them, though they didn&#8217;t address the eight-month gap in action from their first notification. In addition, they stated that only 10,000 customer records were exposed, though researcher <a href=\"https:\/\/twitter.com\/holdsecurity\" target=\"_blank\" rel=\"noopener\">HoldSecurity<\/a>\u00a0claims it&#8217;s more like 37 million.<\/span><\/p>\n<p>While this story is still developing, we urge our readers to take necessary precautions to protect their data. An <a href=\"https:\/\/blog.malwarebytes.com\/101\/2018\/03\/the-data-breach-epidemic-no-info-is-safe\/\" target=\"_blank\" rel=\"noopener\">unprecedented season of breaches in 2017<\/a> gave way to more breach discoveries in early 2018, with companies such as <a href=\"http:\/\/whnt.com\/2018\/03\/31\/over-half-a-million-payment-cards-vulnerable-in-orbitz-data-breach\/\">Orbitz<\/a>, <a href=\"https:\/\/www.cnbc.com\/2018\/04\/02\/what-to-do-after-the-lord-taylor-saks-fifth-avenue-data-breach.html\" target=\"_blank\" rel=\"noopener\">Lord &amp; Taylor\/Saks Fifth Avenue<\/a>, and <a href=\"http:\/\/www.itpro.co.uk\/data-breaches\/30870\/150m-myfitnesspal-users-hit-by-data-breach\" target=\"_blank\" rel=\"noopener\">MyFitnessPal<\/a> collectively exposing more than 155 million users.<\/p>\n<p>Recognize that while the flood of data breaches in itself is alarming, we still haven&#8217;t seen the full potential for the consequences of giving such valuable data freely to the black market. As <a href=\"https:\/\/blog.malwarebytes.com\/101\/2017\/02\/tips-to-stay-secure-during-tax-season\/\" target=\"_blank\" rel=\"noopener\">tax season comes to a close<\/a>, for example, we may be poised for a deluge of fraudulent claims and identity theft as criminals try to cash in on their data. Because of this, we suggest taking similar steps as after the <a href=\"https:\/\/blog.malwarebytes.com\/101\/2017\/09\/equifax-aftermath-how-to-protect-against-identity-theft\/\" target=\"_blank\" rel=\"noopener\">Equifax breach<\/a>, which includes monitoring credit reports, staying on high alert for email, phone, or text scams, and enabling alerts on your accounts.<\/p>\n<p>The more we see infringements of the size and proportion of the Panerabread.com breach, the more we caution users to just assume their data has been compromised. Right now, the best we can do\u2014until companies buckle down harder on security and privacy protocols\u2014is to caution everyone to protect their data from being used to harm them.<\/p>\n<p>Stay safe, everyone.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/panerabread-com-breach-could-have-impacted-millions\/\">Panerabread.com breach could have impacted millions<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/panerabread-com-breach-could-have-impacted-millions\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Wendy Zamora| Date: Tue, 03 Apr 2018 20:53:29 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/panerabread-com-breach-could-have-impacted-millions\/' title='Panerabread.com breach could have impacted millions'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/04\/oldschool_biz.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>The Panerabread.com breach might have exposed 37 million customers&#8217; data online. What should you do to make sure your security isn&#8217;t compromised? <\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/hacking\/\" rel=\"category tag\">Hacking<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/brian-krebs\/\" rel=\"tag\">Brian Krebs<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-breach\/\" rel=\"tag\">data breach<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/identity-theft\/\" rel=\"tag\">identity theft<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/krebsonsecurity\/\" rel=\"tag\">KrebsOnSecurity<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/lord-taylor\/\" rel=\"tag\">Lord &amp; Taylor<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/myfitnesspal\/\" rel=\"tag\">MyFitnessPal<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/orbitz\/\" rel=\"tag\">Orbitz<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/panera\/\" rel=\"tag\">Panera<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/panerabread-com\/\" rel=\"tag\">Panerabread.com<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/privacy\/\" rel=\"tag\">privacy<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/saks-fifth-avenue\/\" rel=\"tag\">Saks Fifth Avenue<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/panerabread-com-breach-could-have-impacted-millions\/' title='Panerabread.com breach could have impacted millions'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/04\/panerabread-com-breach-could-have-impacted-millions\/\">Panerabread.com breach could have impacted millions<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[18006,4503,11172,3919,3921,17621,18007,18008,18009,18010,18011,5897,18012],"class_list":["post-11922","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-brian-krebs","tag-cybercrime","tag-data-breach","tag-hacking","tag-identity-theft","tag-krebsonsecurity","tag-lord-taylor","tag-myfitnesspal","tag-orbitz","tag-panera","tag-panerabread-com","tag-privacy","tag-saks-fifth-avenue"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11922","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=11922"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11922\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=11922"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=11922"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=11922"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}