News: 1661531608

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Now Oktapus gets access to some DoorDash customer info via phishing attack

(2022/08/26)


DoorDash has confirmed that "a small percentage" of its customers and delivery drivers' information, including names, email and delivery addresses, phone numbers, and order and partial credit card details, were exposed as part of a broad phishing campaign dubbed Oktapus.

It appear someone was able to phish the login details of a vendor who works with DoorDash; these credentials were then used, or could have been used, by miscreants to access internal personal data on drivers and customers of the food-ordering giant.

"We can confirm the incident is connected to a wider, sophisticated phishing campaign that has targeted several other companies," a company spokesperson told The Register . "The advanced tactics used in this incident are identical to the tactics used against several other companies."

[1]

As soon as it became aware of the intrusion, DoorDash [2]said it disabled the vendor's access to its IT environment and "contained the incident."

[3]

[4]

"For a smaller set of consumers, basic order information and partial payment card information (the card type and last four digits of the card number) was also accessed," beyond the basic lifted data, we are told.

Meanwhile, for Dashers — the app's delivery drivers — stolen information was mostly limited to names, phone numbers and email address. However, "information affected for each impacted individual may vary," the company said.

[5]

The lifted personal information hasn't been "misused for fraud or identity theft at this time," DoorDash noted, adding that the miscreants weren't privy to customers' or employees "sensitive information."

"Based on our investigation to date, the information accessed by the unauthorized party did not include passwords, full payment card numbers, bank account numbers, or Social Security or Social Insurance numbers," it said.

Yesterday, security firm Group-IB released [6]details about an attack that targeted employees of Okta customers to steal their work login credentials and multi-factor authentication (MFA) codes. It named the phishing campaign Oktapus, and said in addition to [7]Twilio , the attackers hit more than 130 other organizations.

[8]

The phishing trip, which began in March, snaffled at least 9,930 user credentials and 5,440 multi-factor authentication codes. Criminals then used the stolen info to carry out several supply-chain attacks and access corporate data, emails and internal documents.

[9]Twilio, Cloudflare just two of 135 orgs targeted by Oktapus phishing campaign

[10]Digital Ocean dumps Mailchimp after attack leaked customer email addresses

[11]1,900 Signal users exposed: Twilio attacker 'explicitly' looked for certain numbers

[12]Crooks target top execs on Office 365 with MFA-bypass scheme

DoorDash said it notified affected users and "relevant authorities," and is working with a "leading cybersecurity firm" to assist in the investigation. It also implemented measures to further protect its systems and improve vendors' security posture.

When asked about what specific actions it took to boost security, the company declined to comment.

"What we can say is we take the safety of our platform extremely seriously and have already taken immediate action to further safeguard our systems, as well as the systems of our vendors," a spokesperson said. ®

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YwlCdwbTBDhx9Fn4djTGNAAAAII&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://doordash.news/get-the-facts/how-were-responding-to-a-third-party-vendor-phishing-incident/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YwlCdwbTBDhx9Fn4djTGNAAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YwlCdwbTBDhx9Fn4djTGNAAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YwlCdwbTBDhx9Fn4djTGNAAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/08/25/twilio_cloudflare_oktapus_phishing/

[7] https://www.theregister.com/2022/08/08/twilio_phishing_attack/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YwlCdwbTBDhx9Fn4djTGNAAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2022/08/25/twilio_cloudflare_oktapus_phishing/

[10] https://www.theregister.com/2022/08/16/digital_ocean_dumps_mailchimp/

[11] https://www.theregister.com/2022/08/16/twilio_breach_fallout_signal_user/

[12] https://www.theregister.com/2022/08/25/microsoft_365_bec/

[13] https://whitepapers.theregister.com/



Blah, blah, blah

IGotOut

"What we can say is we take the safety of our platform extremely seriously... "

Clearly you dont

Cloudflare were targeted and they didn't fall for it, which shows your procedures were inadequate. So fuck off with your bullshit lies and ACTUALLY take it seriously.

From the article

Lis

company spokesperson told The Register. "The advanced tactics used in this incident are identical to the tactics used against several other companies.

So I have to ask, if they knew that, then why didn’t they lean from it? Yes I know. Stupid fucking question.

Though maybe we should give them some slack being that it was a “sophisticated” attack /s.

Arseholes.

As a kid with landlines

chivo243

I once got a phone call from a friend, cool, but then he proceeded to ask me if? I was at home... ?? My response was 'what number did you dial?'

Wait, you have my username, and probably password, but you want to know it?

If you don't know where you are, you're lost!

What ever happened to happily ever after?