Image via Augustine Bin Jumat/Shutterstock

According to a leading cybersecurity firm, more than three million records of customers of international cosmetics and beauty products retailer Sephora are reportedly up for sale on the Dark Web.
Singapore-based cybersecurity outfit Group-IB said in a media release on Thursday (1 Aug) that its cyber intelligence analysts located “two databases with customer data on underground forums that are likely to be related to Sephora”.
These databases are believed to contain records from February and March this year, which corresponds with the recent Sephora data breach that affected the personal data of its online customers in Singapore, Malaysia, Indonesia, Thailand, the Philippines, Hong Kong, New Zealand, and Australia.
CEO and founder of Group-IB Ilya Sachkov said in the media release that the first database was advertised on two Dark Web forums on 16 and 17 July, respectively.
According to the seller, the database “consists of 500,000 records including the usernames and hashed passwords from Sephora.co.id (Indonesia) and Sephora.co.th (Thailand)”.
“The listing’s author notes that the data comes from February 2019,” he added.
Meanwhile, the second database surfaced on an underground forum on 28 July, a day before the news of the breach was made known by Sephora.
“As its name implies “Sephora 2019/03 – Shopping – [3.2 million]”, the database contains 3.2 million records, and was leaked in March 2019,” said Mr Sachkov.
With its high-tech tools, Group-IB’s cyber intelligence team “infiltrated sources in closed hacking communities” and initiated contact with the seller, who then supplied the sample of the data being sold.
Mr Sachkov noted that the sample revealed that the database contains all sorts of personal data such as login, encrypted password, date of registration and last activity, IP of registration, last IP, gender, name, surname, ethnicity, eye color, skin tone, skin type, hair color, hair concerns, makeup essentials, and skincare routines.
He then pointed out that the set of data was priced at USD 1,900 (S$2,613).
Even though the records do not include any payment information or decrypted passwords, such detailed information about the customers can be used to carry out social engineering or targeted phishing attacks that is why the scale of the breach shouldn’t be underestimated,” he stated.
“As a precaution, we advise all customers who had accounts at Sephora to change their password, especially if they use the same login/password pair across multiple services, such as email and social media accounts, to avoid them being compromised,” he added.
TOC has reached out to Sephora earlier today for its comments on Group-IB’s findings. We have yet to receive a response, but will provide an update upon receiving a reply.

Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments
You May Also Like

PSP’s Dr Tan Cheng Bock calls for televised debate with Chan Chun Sing on competency of alternative parties in handling COVID-19

The Progress Singapore Party (PSP) secretary-general Dr Tan Cheng Bock on Sunday…

【选举】戳破“反对党当非选区议员”迷思 陈立峰:反而稳固执政党“超级多数”优势

工人党后港单选区候选人陈立峰,反驳原律政部高级政务部长英兰妮“反对党当非选区议员”的论述,点出非选区议员的局限,致使反对党议员无法深耕选区,且只会巩固行动党“超级多数”议席的优势。 早前,英兰妮指出,非选区议员有12人,选民无须担心国会里会没有多元的声音。 但陈立峰戳破迷思,指非选区议员有局限,敦促人民不应轻易落入对非选区议员的圈套。 尽管非选区议员仍能在国会对各种议题提出异议,但他直言,非选区议员的身份,使得在野党难以在选区深耕。例如,他不被允许在凤山单选区举办活动,但在工人党的选区内,败北的人民行动党却比工人党候选人获得更多便利。 如果人民持续相信设立非选区议员的目的,反而会成为在野党无法深耕在选区内,因为他们不被允许这么做。与此同时,反而会增加人民行动党极多数(super majority)的问题。 “再者如果有一天人民行动党失败、或做得非常差,到时是否有其他政党能接管?这种情形会是国人想要的吗?”

海鲜盒内藏玄机! 马国罗厘过关遇截查 发现大量漏税烟

海鲜盒内藏玄机!一辆载送海鲜的罗厘在经过大士关卡时,遭拦截检查,移民与关卡局人员在海鲜保丽龙盒内起获大量漏税烟。 移民与关卡局今日(26日)于脸书上发文,指在上周五(22日)起获漏税烟。 当时执法人员在大士关卡拦截一辆马国注册的罗厘,内有海鲜并使用保丽龙盒子装。然而在盒内却暗藏玄机,发现了1千530条以及560包漏税烟。 当局也晒出相关照片,从照片可见盒内上层是一些散落的鲜虾作掩饰,然而鲜虾下却有一层塑料,塑料内就是漏税烟。 这起案件已转交给关税局作进一步调查。 当局也表示,类似的手法已非首例,因此引起当局的关注。当局续指,将会持续对乘客、货物、车辆进行例行检查,确保我国的安全。