News: 1683586890

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Western Digital: Customer info stolen in that IT attack

(2023/05/09)


Customer information was stolen from the IT systems of Western Digital in the March security breach we've previously reported, forcing the storage manufacturer to shut down its online store until at least next week.

Western Digital (WD) [1]disclosed the intrusion in early April, saying that in late March its engineers discovered someone had broken into "a number" of the biz's systems. In a brief statement at the time, officials said they had disconnected their systems and services from the public internet and were working to restore regular operations.

WD also said it was working with outside forensic experts to probe and repair the damage, though offered little other info.

[2]

In an [3]update late last week, WD admitted the intruders grabbed a copy of the database powering Western Digital's online store. That trove included a range of personal information of the store's customers – including names, billing and shipping addresses, email addresses, and telephone numbers.

[4]

[5]

Other data stolen included – in "encrypted" form – hashed and salted passwords and partial credit card numbers.

In a brief [6]letter to customers also sent late last week, WD reiterated the data that was stolen, and said it had [7]temporarily suspended access to online store accounts.

[8]Western Digital open to spinning out flash, hard disk businesses

[9]After quietly switching to slower NAND in an NVMe SSD, Western Digital promises to be a bit louder next time

[10]Western Digital shingled out in lawsuit for sneaking RAID-unfriendly tech into drives for RAID arrays

[11]Elliott Management to WDC board: Spin out or sell flash biz

The company's online store features a small banner that reads: "We'll be back soon. We are unable to process orders at this time." And where a button marked "Buy Now" would usually appear, it's been replaced by one marked "Find A Reseller."

The disk slinger's plan is to restore access to accounts the week of May 15. The My Cloud service – which was shut down as part of the proactive measures taken after the security breach and includes such stuff as My Cloud Home, My Cloud Home Duo, My Cloud OS5, and SanDisk ibi – was restored April 13.

[12]

WD also outlined steps customers can take to protect themselves against fraud and other abuse of their personal information, and advised now is the time for heightened awareness of crooks using the intrusion to lure victims to phishing pages.

What wasn't included in the letter was any mention of the usual credit monitoring after a privacy blunder. The Register has contacted WD for more information and will update the story if the business responds.

Who is behind this?

There also is the issue of the stolen information being released publicly by the miscreants who acquired it. The crooks claiming to have orchestrated the theft boasted at one point they had stolen 10TB of data from Western Digital, including WD's code-signing certificate. The crew said they wanted an eight-figure ransom payment.

In late April, the BlackCat ransomware group – also known as ALPHV – [13]posted to its website purported screenshots of data stolen from WD. It also reportedly [14]interrupted a video-conference call among Western Digital's security incident response team, taunting the group, and even going as far as sharing a screenshot of the meeting, according to cyber researcher Dominic Alvieri.

Some WD users voiced their frustrations over the breach, and what they said was the vendor's tardy communication.

[15]

"Took them long enough to say something," one netizen wrote on [16]Reddit , noting that on another subreddit channel, "people have been talking about their site doing weird shit for what seems like months. Removing the ability to buy drives and stuff like that."

Another user said that "we need laws that heavily hurt companies that suffer 'customer data breaches', and hurt them even more if they are found to try and cover them up. We need to incentivize these companies to stop holding customer data."

Others took a more measured view.

"To be fair all the things they listed seem pretty essential if you're selling physical goods to people," one person wrote. "Are they just supposed to not have a record of where things got sent to or something? I'm all for data privacy, but I really don't think this is a case that deserves heavy penalties.

"The fact is that sometimes shit happens – you can do everything right and still have things go wrong. I don't think it's fair to penalize companies for this sort of thing unless it's clear that they were capable of avoiding it or reducing the impact but chose not to." ®

Get our [17]Tech Resources



[1] https://www.theregister.com/2023/04/03/western_digital_confirms_security_incident/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZFnFZIWdgGLLBAL5pUBcwwAAAJU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.westerndigital.com/company/newsroom/press-releases/2023/2023-05-05-western-digital-provides-update-on-network-security-incident

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFnFZIWdgGLLBAL5pUBcwwAAAJU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFnFZIWdgGLLBAL5pUBcwwAAAJU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.hotukdeals.com/discussions/western-digital-data-breach-4131297

[7] https://blocksandfiles.com/2023/05/08/western-digitals-online-store-still-closed-six-weeks-after-cyber-attack/

[8] https://www.theregister.com/2022/06/08/western_digital_flash_hdd_spinouts/

[9] https://www.theregister.com/2021/08/27/western_digital_components/

[10] https://www.theregister.com/2020/05/29/wd_class_action_lawsuit/

[11] https://www.theregister.com/2022/05/03/elliott_management_to_wdc_board/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFnFZIWdgGLLBAL5pUBcwwAAAJU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://twitter.com/AlvieriD/status/1652084141125431300

[14] https://twitter.com/AlvieriD/status/1652173436888784896?cxt=HHwWgIC90Ze_2e0tAAAA

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFnFZIWdgGLLBAL5pUBcwwAAAJU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://www.reddit.com/r/LinusTechTips/comments/13a5t94/western_digital_had_a_data_breach/

[17] https://whitepapers.theregister.com/



Other data exposed include – in "encrypted" form – hashed and salted passwords

Howard Sway

Right, so you encrypted your users passwords so that they couldn't be misused after a data breach. But it never occurred to you to encrypt their names, addresses, telephone numbers, email, because you didn't realise that these are also commonly used for phishing attacks when they get stolen.

20 years I've been informing companies of this problem, and imploring them to encrypt a lot more of the personal data they hold. And still I encounter the shrug of the shoulders and get told that they don't think it's that important and will make more work for them. Still, this story is one more example to add to my file of reasons why they're wrong.

Re: Other data exposed include – in "encrypted" form – hashed and salted passwords

Kevin McMurtrie

Counterpoint: Encrypting frequently used data can make the decryption keys more widely available for theft.

That's why you need to put a lot of effort into general security practices.

TrevorH

I got the email from them telling me of this breach and, usefully, it contains only a JPEG of the grovelling apology from some WD bigwig. That JPEG has no explanatory text to go with it and like many I have images deliberately turned off in my email client so all I got on two email clients (gmail on Android 13 and Thunderbird on a desktop) was a blank email from them containing, apparently, nothing at all. Very useful. It was only because I wondered why WD would be sending me a blank email that I bothered to dig through the headers and work out that it was actually from them. I then had to hack through the HTML email source code to extract the JPEG URL so I could read it....

Not a great way to communicate

L'hazard ne favorise que l'esprit prepare.
-- L. Pasteur