{"id":18701,"date":"2022-04-07T05:10:05","date_gmt":"2022-04-07T13:10:05","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/04\/07\/news-12434\/"},"modified":"2022-04-07T05:10:05","modified_gmt":"2022-04-07T13:10:05","slug":"news-12434","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/04\/07\/news-12434\/","title":{"rendered":"Cash App breached by a former employee could affect millions"},"content":{"rendered":"<p><strong>Credit to Author: Jovi Umawing| Date: Thu, 07 Apr 2022 12:24:51 +0000<\/strong><\/p>\n<p>In December last year, the customer information of Cash App users was accessed by a former employee of Block, the company behind the popular mobile payment service app. This was revealed in <a href=\"https:\/\/www.sec.gov\/ix?doc=\/Archives\/edgar\/data\/0001512673\/000119312522095215\/d343042d8k.htm\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">a very recent filing<\/a> to the Securities and Exchange Commission (SEC), which shows that the former employee accessed and downloaded &#8220;certain reports&#8221; containing US customer information.<\/p>\n<p>The filing reads:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>&#8220;While this employee had regular access to these reports as part of their past job responsibilities, in this instance these reports were accessed without permission after their employment ended.&#8221; <\/p>\n<\/blockquote>\n<p>Cash App is currently in the process of reaching out to its 8.2 million US users about the breach. That includes current and former Cash App users.<\/p>\n<p>The compromised data contains full names and brokerage portfolio values. The filling explains the latter as &#8220;the unique identification number associated with customer&#8217;s stock activity on Cash App Investing&#8221;. <\/p>\n<p>The document also clarified that compromised data &#8220;did <span style=\"text-decoration: underline\">not<\/span> include usernames or passwords, Social Security numbers, date of birth, payment card information, addresses, bank account information, or any other personally identifiable information.&#8221; Security code, access code, or Cash App account passwords were also not part of the breached data.<\/p>\n<p>According to an email interview with Vice, a Cash App spokesperson said they have already taken remediating steps, and launched an investigation &#8220;with the help of a leading forensics firm&#8221;.<\/p>\n<p>We have yet to find out exactly how this former employee could still reach assets they should no longer be able to access after separating from their employer. Sadly, incidents like this happen all the time. <a href=\"https:\/\/smallbiztrends.com\/2021\/08\/employees-access-files-former-employer.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Multiple<\/a> <a href=\"https:\/\/mytechdecisions.com\/network-security\/more-than-a-third-of-former-employees-still-have-access-to-company-data\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">studies<\/a> have shown that many organizations&#8217; former employees, regardless of the nature of their termination, can still access not just corporate data but also platforms used by their former employers. Such incidents are not only classified as <a href=\"https:\/\/blog.malwarebytes.com\/101\/2018\/08\/the-enemy-is-us-a-look-at-insider-threats\/\">insider threat<\/a> incidents, but they are also good examples of many companies having <a href=\"https:\/\/www.forbes.com\/sites\/theyec\/2020\/08\/04\/the-cybersecurity-risks-of-improper-employee-offboarding\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">improper offboarding practices<\/a>.<\/p>\n<p>Cash App can only be used in the US and UK. No UK customers were affected by this breach.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/security-world\/2022\/04\/cash-app-breached-by-a-former-employee-could-affect-millions\/\">Cash App breached by a former employee could affect millions<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/security-world\/2022\/04\/cash-app-breached-by-a-former-employee-could-affect-millions\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Jovi Umawing| Date: Thu, 07 Apr 2022 12:24:51 +0000<\/strong><\/p>\n<p>Cash App is reaching out to its millions of US users regarding a breach of their data.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/security-world\/2022\/04\/cash-app-breached-by-a-former-employee-could-affect-millions\/\">Cash App breached by a former employee could affect millions<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[15174,25612,25613,14429,6280,10497,25614],"class_list":["post-18701","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-block","tag-cash-app","tag-improper-offboarding-practices","tag-insider-threat","tag-securities-and-exchange-commission","tag-security-world","tag-square"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18701","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18701"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18701\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18701"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18701"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18701"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}