{"id":14485,"date":"2019-02-01T11:10:03","date_gmt":"2019-02-01T19:10:03","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2019\/02\/01\/news-8237\/"},"modified":"2019-02-01T11:10:03","modified_gmt":"2019-02-01T19:10:03","slug":"news-8237","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/02\/01\/news-8237\/","title":{"rendered":"Houzz data breach: Why informing your customers is the right call"},"content":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Fri, 01 Feb 2019 18:00:39 +0000<\/strong><\/p>\n<p>Houzz is an online platform dedicated to home renovation and design. Today (February 1, 2019), they notified their customers about a data breach that reportedly happened in December 2018.<\/p>\n<p>Data breaches unfortunately have become a common event. In fact, we dubbed <a href=\"https:\/\/blog.malwarebytes.com\/101\/2018\/12\/2018-the-year-of-the-data-breach-tsunami\/\">2018 the year of the data breach tsunami<\/a>. Also Houzz is not a giant corporation with millions of customers. So why are we writing about this, you may ask? Mainly because we feel there are some giant corporations out there who can learn from this event as an example on how to handle a data breach properly.<\/p>\n<h3>Turnaround<\/h3>\n<p>Discovering and informing your customers about a breach that happened less than two months ago is a lot better than what we have seen recently. They did not wait until the investigation on how the breach happened was finished. As soon as they knew what was stolen, they decided to inform those concerned. Of course it is imperative that you get this information into your customers&#8217; hands as soon as possible. Which is probably why the investigation is being conducted by a leading forensics firm. Law enforcement has been notified as well.<\/p>\n<h3>Informing customers<\/h3>\n<p>Houzz informed their customers directly by email, as well as on their website, about the breach. They said:<\/p>\n<blockquote>\n<p>Houzz recently learned that a file containing some of our user data was obtained by an unauthorized third party.<\/p>\n<\/blockquote>\n<p>The mail starts with this disclosure, goes on to explain what happened, and which information was stolen. It also contains a link to their <a href=\"https:\/\/help.houzz.com\/s\/article\/security-update?language=en_US\">website, where you can find more information<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/mail.png\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"27069\" data-permalink=\"https:\/\/blog.malwarebytes.com\/security-world\/business-security-world\/2019\/02\/houzz-data-breach-why-informing-your-customers-is-the-right-call\/attachment\/mail-3\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/mail.png\" data-orig-size=\"802,637\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"mail\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/mail-300x238.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/mail-600x477.png\" class=\"aligncenter size-large wp-image-27069\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/mail-600x477.png\" alt=\"Houzz mail customers\" width=\"600\" height=\"477\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/mail-600x477.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/mail-300x238.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/mail.png 802w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>The information given is concise and precise\u2014not just some general remark that no financial information was stolen, which thankfully wasn\u2019t indeed. Houzz included a list of information that was stolen.<\/p>\n<blockquote>\n<p>The following types of information could have been impacted by this incident:<\/p>\n<ul>\n<li>Certain publicly visible information from a user\u2019s Houzz profile only if the user made this information publicly available (e.g., first name, last name, city, state, country, profile description)<\/li>\n<li>Certain internal identifiers and fields that have no discernible meaning to anyone outside of Houzz (e.g. country of site used, whether a user has a profile image)<\/li>\n<li>Certain internal account information (e.g., user ID, prior Houzz usernames, one-way encrypted passwords salted uniquely per user, IP address, and city and ZIP code inferred from IP address) and certain publicly available account information (e.g., current Houzz username and if a user logs into Houzz through Facebook, the user\u2019s public Facebook ID)<\/li>\n<\/ul>\n<p>Importantly, this incident does not involve Social Security numbers or payment card, bank account, or other financial information.<\/p>\n<\/blockquote>\n<p>On the website, customers can find detailed information on how to change their password. And, like we have done in the past, they advise their customers to use a unique password for each service,\u00a0<a href=\"https:\/\/blog.malwarebytes.com\/101\/2017\/05\/dont-need-27-different-passwords\/\">which does not need to be as big a hassle<\/a> as you might expect.<\/p>\n<h3>Improvements<\/h3>\n<p>Houzz announced security improvements without going into detail. While customers might find this vague, it makes sense to withhold the specifics, as the investigation is ongoing, and they wouldn&#8217;t want to make\u00a0<a href=\"https:\/\/blog.malwarebytes.com\/glossary\/threat-actor\/\">threat actors<\/a> any wiser. Seeing that they were already using one-way encrypted passwords salted uniquely per user was certainly encouraging.<\/p>\n<h3>Dealing with data breaches<\/h3>\n<p>Data breaches happen all the time. It happens to the best of companies. It\u2019s the way those organizations deal with them that can save face. What other businesses can take away from this example:<\/p>\n<ul>\n<li>Inform customers as soon as it makes sense and be precise about the stolen information.<\/li>\n<li>Approach your customers directly. Don\u2019t let them read about it in the papers or social media.<\/li>\n<li>Engage law enforcement and a firm specialized in forensic investigations.<\/li>\n<li>Learn from what went wrong and improve on that.<\/li>\n<\/ul>\n<p>Stay safe, everyone!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/security-world\/business-security-world\/2019\/02\/houzz-data-breach-why-informing-your-customers-is-the-right-call\/\">Houzz data breach: Why informing your customers is the right call<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/security-world\/business-security-world\/2019\/02\/houzz-data-breach-why-informing-your-customers-is-the-right-call\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Fri, 01 Feb 2019 18:00:39 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/security-world\/business-security-world\/2019\/02\/houzz-data-breach-why-informing-your-customers-is-the-right-call\/' title='Houzz data breach: Why informing your customers is the right call'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/furniture_broken.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Online renovation and design platform Houzz suffered a data breach\u2014not good. Their subsequent response, however, was exemplary. Here&#8217;s how other businesses can learn from their example.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/security-world\/business-security-world\/\" rel=\"category tag\">Business<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/security-world\/\" rel=\"category tag\">Security world<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/breach\/\" rel=\"tag\">breach<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-breach\/\" rel=\"tag\">data breach<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/data-privacy\/\" rel=\"tag\">Data privacy<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/forensics\/\" rel=\"tag\">forensics<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/gdpr\/\" rel=\"tag\">gdpr<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/houzz\/\" rel=\"tag\">houzz<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/security-world\/business-security-world\/2019\/02\/houzz-data-breach-why-informing-your-customers-is-the-right-call\/' title='Houzz data breach: Why informing your customers is the right call'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/security-world\/business-security-world\/2019\/02\/houzz-data-breach-why-informing-your-customers-is-the-right-call\/\">Houzz data breach: Why informing your customers is the right call<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[11510,1001,11172,11063,12749,12116,19908,10497],"class_list":["post-14485","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-breach","tag-business","tag-data-breach","tag-data-privacy","tag-forensics","tag-gdpr","tag-houzz","tag-security-world"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14485","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14485"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14485\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14485"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14485"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14485"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}