News: 1701717310

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Hershey phishes! - Crooks snarf chocolate lovers' creds

(2023/12/04)


There's no sugarcoating this news: The Hershey Company has disclosed cyber crooks gobbled up 2,214 people's financial information following a phishing campaign that netted the chocolate maker's data.

According to a [1]security notification filed with the Maine Attorney General's office, the phishing emails landed in employees' inboxes in early September. From that point on, it sounds like accessing private data was as easy as stealing candy from a baby.

The other Chocolate Factory did not immediately respond to The Register 's questions.

[2]

In a letter sent to affected individuals, Hershey says it recently wrapped up its investigation, and says the thief "may have had access to certain personal information," but adds (not-so-reassuringly) that there is "no evidence that any information was acquired or misused."

[3]PDF



[4]

[5]

This data included first and last names, health and medical information, health insurance information, digital signatures, dates of birth, addresses and contact information, driver's license numbers, credit card numbers with passcodes or security codes, and credentials for online accounts and financial accounts including routing numbers.

Basically, the crooks accessed anything they need for all types of evil deeds with old-fashioned financial theft likely topping the list..

[6]

"Upon learning of the incident, Hershey worked to block the unauthorized user's access and confirm that the affected Hershey accounts were no longer in use by the unauthorized user," according to the breach notification letters.

[7]New Relic's cyber-something revealed as attack on staging systems, some users

[8]Scores of US credit unions offline after ransomware infects backend cloud outfit

[9]Apple slaps patch on WebKit holes in iPhones and Macs amid fears of active attacks

[10]Black Basta ransomware operation nets over $100M from victims in less than two years

Hershey also says it worked with "multiple third parties" to clean up the sticky mess, including a forensic provider.

"We also have taken steps to enhance our data security measures to prevent the occurrence of a similar event in the future, including forced password changes and additional detection safeguards to our corporate email environment," the letter adds.

And, while the candy maker has "no reason to believe" that the data thieves have misused the stolen data, Hershey is offering affected individuals the traditional two free years of Experian IdentityWorks. Unfortunately, the company didn't sweeten the deal by throwing in some complimentary chocolate.

Hershey joins the ranks of high-profile intrusions that occurred in early September, and include Las Vegas casino giants [11]Caesars Entertainment and MGM Resorts , both of whom suffered network intrusions and extortion demands around this same time.

[12]

Criminals haven't shown any signs of slowing down as the end of the year approaches, with organizations ranging from web tracking and analytics firm [13]New Relic , to [14]60 US credit unions , and the [15]British Library reporting problems in the last few weeks. ®

Get our [16]Tech Resources



[1] https://apps.web.maine.gov/online/aeviewer/ME/40/0bde9ba2-ba66-4741-9b54-208987b13c24.shtml

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZW5aGWRUWITe0I6mJQELZQAAANA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://regmedia.co.uk/2023/12/04/hershey_data_breach_notification.pdf

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZW5aGWRUWITe0I6mJQELZQAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZW5aGWRUWITe0I6mJQELZQAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZW5aGWRUWITe0I6mJQELZQAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/12/04/new_relic_security_incident/

[8] https://www.theregister.com/2023/12/02/ransomware_infection_credit_unions/

[9] https://www.theregister.com/2023/12/01/iphones_macs_patch/

[10] https://www.theregister.com/2023/11/30/black_basta_ransomware_operation_extorts/

[11] https://www.theregister.com/2023/11/17/fbi_scattered_spider_action/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZW5aGWRUWITe0I6mJQELZQAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2023/12/04/new_relic_security_incident/

[14] https://www.theregister.com/2023/12/02/ransomware_infection_credit_unions/

[15] https://www.theregister.com/2023/11/29/british_library_begins_contacting_customers/

[16] https://whitepapers.theregister.com/



Martin-73

To be fair, chocolate lovers wouldn't be on Hershey's database...

cornetman

When we originally came to Canada 16 years ago, it was just before Christmas and we got stocked up in the supermarket with chocs and stuff (including this stuff called "root beer" which I quickly realised was not the Canadian name for ginger beer and turned out to be Germoline in liquid form :( )

One of the things we got to try were "Hershey's Kisses" Honestly, after trying one, I thought that they had been tampered with, it was so disgusting, tasting like vomit. We ended up throwing them out.

Never again have I bought anything from Hershey's.

sweh

I moved to NYC 22 years ago, and wandering around I found some Cadbury's Fruit and Nut. Since I was a little home sick I bought it. And after tasting a few chunks was almost sick. Checking the label I saw "Made under license by Hershey".

That put me off Hershey chocolate!

JimboSmith

If you can get it try their Extra Dark with Cranberries, Blueberries and Almonds which is so much better and far less vomit inducing/tasting than their usual stuff which I don’t like either.

https://www.amazon.com/Hersheys-Chocolate-Cranberries-Blueberries-3-52-Ounce/dp/B000IXSLMI/ref=cm_cr_arp_d_pb_opt?ie=UTF8

Canadian name for ginger beer and turned out to be Germoline in liquid form

The Oncoming Scorn

I am so stealing that description (Been here 14 years myself).

Blame the oompa loompas

Rikki Tikki

I'll bet they feel right Charlies for giving the hackers a golden ticket

Ol'Peculier

Remember when the comedian Dave Gorman did the thing where he did Google searches that returned zero results? Here's another one: "Hershey" "chocolate lovers".

Nestle?

Anonymous Coward

"Stealing Kit Kat maker's data?"

If Hershey made them the way they make their own branded chocolate, I wouldn't touch them with a barge pole.

Oh well, just to be safe, I'll have to import a pack of Kvikk Lunsj when I visit Norway next year....

Standards are slippin now El Reg focuses on readers outside Europe

Anonymous Coward

A few years ago this article would have consistently mentioned Hershey "chocolate" instead of Hershey chocolate.

I had colleagues who would come back with Hershey Kissses whenever they had been across the pond and I was always surprised they got them through customs. Perhaps they declared them as dog food?

dafuq

captain veg

Who hands over PII to a lowest common denominator chocolate manufacturer?

Really, I despair.

-A.

Re: dafuq

sten2012

Is this employee data or what?

Why health, for example? If it's customers:

A) why would anyone choose to supply it?

B) under what premise was it collected?

C)why would they possibly want to collect it? They know the answer already, and collecting it is just removing any deniability for "they knowingly sold unhealthy food" lawsuits in future.

Please keep your hands off the secretary's reproducing equipment.