We need a law mandating the company pays at least $1k per exposed record per customer or absolutely nothing will change. The current cost of “here’s a years worth of credit monitoring” doesn’t even amount to a slap on the wrist.
and I've never seen any confirmation elsewhere
Looks like CyberNews have edited the article with more info since first I saw it, it used to look quite suspicious and untrustworthy, it now has more info. Still doesn't say exactly what a record is, or how many uniques there are.
> We requested a security incident report from the ethical hackers as proof
So instead of paying him a fair bug bounty, they demand that he write a formal report for them and prove to them that there is even a problem.
Totally unhinged, but it gets worse:
> the response was a demand for money for the report, which confirmed our suspicion that this was a ransom-related incident.
Wow. So when the security researcher informs them that he would be happy to do some consulting work for them and informs them of his rates, they flip out and accuse his initial good samaritan decision to inform the company of the issue of being part of a plot by him to hold the company for ransom?
Whoever thought this is both totally delusional and a complete jerk. Truly, no good deed goes unpunished.
https://www.idmerit.com/blog/idmerits-data-breach-fail-safe-...
archived for posterity: https://archive.ph/MdSfO
This seems like a critical sentence. Is this database actually operated by IDMerit, or someone else? If so, who?
The system is broken. We shouldn't be so vulnerable because of foundational infrastructure.
The fact that they didn't vet their data providers then has to be considered a form of negligence. In the end, its the company I am handing over my details to to act responsibly, not their providers.
I hate this responsibility delegating when its not a good luck, and this will continue to get worse now as the entire internet will be ID gated soon. But don't worry, all the lapse in privacy and even security in the name of 'saving the kids'.
I saw a reddit thread about it earlier where someone said the apparent hacker refused to actually show any of the data and was asking for money. So probably just a scam rather than a real leak.