Acer confirms Philippines employee data leaked on hacking forum

20 tháng 3, 2024

Acer Philippines confirmed that employee data was stolen in an attack on a third-party vendor who manages the company's employee attendance data after a threat actor leaked the data on a hacking forum.


Acer is a Taiwanese maker of computer hardware and electronics, best known for its laptops that offer a good balance of performance, quality, and competitive pricing.


Earlier March 12, a threat actor known as 'ph1ns' published a link to download a stolen database containing Acer employee data for free on a hacking forum.




Threat actor's posts on BreachForums (BleepingComputer)




The attacker told BleepingComputer that no ransomware or encryption was involved and that it was a pure data theft attack.


They further confirmed to BleepingComputer that they were not attempting to extort the company. However, they did provide evidence that they wiped data on the breached servers before they lost access.


We reached out to Acer to verify the authenticity of the threat actors' claims, and an Acer spokesperson confirmed that the data is theirs but was not acquired directly from the company's systems.


"We are aware that one of our external vendors in the Philippines has suffered a data breach, and as a result, a limited set of employee data has been compromised," a spokesperson told BleepingComputer.


"While we are working with the vendor, cybersecurity experts and law enforcement, we would like to emphasize that no customer data has been affected and there is no evidence of any breach of Acer's systems."


Acer Philippines later issued a public statement on X offering similar assurances about the security of customer data and confirming that its systems remain uncompromised.



Acer's full statement




The computer maker has notified the National Privacy Commission (NPC) and the Cybercrime Investigation and Coordinating Center (CICC) in the Philippines, and an investigation of the incident is underway.


Acer's past lapses


Acer has had multiple security incidents in recent years. In February 2023, hackers breached a company server holding technical manuals, software tools, BIOS images, and replacement digital product keys (RDPK), among other things.


In October 2021, Acer admitted that its India-based after-sales service had been compromised, and millions of records containing customer data were stolen.


Finally, in March 2021, the computer maker was hit by a REvil ransomware attack that broke records for demanding a ransom payment of $50 million.



Source: BleepingComputer


Bạn cũng có thể quan tâm

4 tháng 6, 2024
Bộ định tuyến chơi game TP-Link Archer C5400X dễ mắc phải các lỗi bảo mật có thể cho phép kẻ tấn công từ xa, không được xác thực thực thi các lệnh trên thiết bị.
3 tháng 6, 2024
Ngày 27 tháng 5 Check Point đã cảnh báo rằng các tác nhân đe dọa đang nhắm mục tiêu vào các thiết bị VPN truy cập từ xa của Check Point trong một chiến dịch đang diễn ra nhằm xâm phạm mạng doanh nghiệp.
31 tháng 5, 2024
Công ty quản lý đơn thuốc Sav-Rx cảnh báo hơn 2,8 triệu cá nhân ở Hoa Kỳ việc họ đã bị vi phạm dữ liệu và dữ liệu cá nhân của họ đã bị đánh cắp trong một cuộc tấn công mạng năm 2023.
Thêm bài viết
Share by: