Europe's largest caravan club admits wide array of personal data potentially accessed
- Reference: 1707741910
- News link: https://www.theregister.co.uk/2024/02/12/europes_largest_caravan_and_rv/
- Source link:
According to an update shared with members late last week and now published on its website, the CAMC listed all the different types of data that might have been accessed, and all the data that definitely wasn't, but remained firmly on the fence as to whether any theft actually took place.
"The cyber security team conducting the forensic investigation cannot confirm that any member data has been accessed, stolen, or is being used in an unauthorized manner," said Nick Lomas, director general at the CAMC.
[1]
"In the spirit of transparency, we want to make you aware that the following data was held on the servers that were potentially accessed."
[2]
[3]
CAMC, which has more than a million members, offers a variety of insurance policies through its website, and those who purchase different types of coverage may be affected to different degrees.
If members took out policies for Mayday breakdown insurance between 2018 and 2024, the extent of the potential data compromise includes names, addresses, vehicle registration numbers, policy numbers, policy start and end dates, and membership numbers.
[4]
For caravan insurance policies between 2018 and 2024, members may have had their names, policy numbers, policy prices, and policy start and end dates accessed.
Members who made claims on their Red Pennant emergency assistance – breakdown cover for European trips – between 2018 and 2024 may have had a wealth of data accessed. This includes:
Names
Addresses
Dates of birth
Mobile phone number
Email addresses
Policy numbers
Membership numbers
Vehicle registration numbers
Caravan vehicle identification number
Information about claims made
CAMC said this information was gathered to handle claims and the amount of data collected for each claim may be different for each customer.
The organization has asked members not to make contact regarding any possible personal data security matters as it will be contacting affected members directly, should the data be eventually found to be compromised.
"Our aim is not to alarm members unnecessarily, but we believe we have a responsibility as a members' club to share details about the incident," said Lomas.
[5]
In an [6]FAQ section on its website, CAMC confirmed payment details, campsite booking details, and passwords are unaffected but "as a precautionary measure," members are advised to update their passwords anyway.
[7]Mon Dieu! Nearly half the French population have data nabbed in massive breach
[8]Meet VexTrio, a network of 70K hijacked websites crooks use to sling malware, fraud
[9]Uncle Sam sweetens the pot with $15M bounty on Hive ransomware gang members
[10]Major IT outage at Europe's largest caravan and RV club makes for not-so-happy campers
Members are warned to be extra watchful against phishing attacks via email or text messages, and to avoid clicking any suspicious links.
"This type of incident is a reminder that we must all remain vigilant to any unusual or spurious requests for personal details," said Lomas.
"Data security is of paramount importance to the Club, our members, guests, and suppliers. We have taken further actions under the instruction of our cybersecurity experts to enhance the Club's cybersecurity to help prevent this type of incident from happening again."
Lomas also said that the organization will no longer post updates to its social media channels about the incident, per the recommendations of the contracted third-party investigators.
"It's important that we don't raise awareness of details of the incident to the cybercriminals and our cybersecurity experts have advised us not to share any further details to do with the incident on social media. We would advise you to follow the same guidance."
Any further updates will be published on its website and communicated directly to members.
"I would like to offer my sincere apologies for any inconvenience this has caused, and thank you for your continuing patience as we return to normality," Lomas concluded.
Incident recap
Reg readers were the first to know about [11]the issues at the CAMC after multiple members got in touch asking us to investigate.
Members were pleading with the club for days to gain assurances that their data was safe. CAMC's comms team limited contact to social media replies that offered little insight into what was going on behind the scenes of an outage that saw its website and app pulled offline for weeks.
[12]
Screenshots of the website and mobile app of the Caravan and Motorhome Club, both displaying the different outage messages
The online issues began on January 20 and according to recent social media posts, full website and app access was only restored on February 6.
The official line at the beginning was that investigators had been drafted in and there was no evidence to suggest member data was compromised, a stance that has since shifted to open up the possibility of data access. CAMC, however, reported itself to the UK's data watchdog, the Information Commissioner's Office, from the outset.
Despite the wording of the CAMC's disclosure sounding an awful lot like [13]ransomware , and the fact LockBit claimed the attack on its leak blog, the organization has never confirmed that the incident involved ransomware.
Without verifying the data, [14]LockBit does have 9.47 GB worth of files allegedly belonging to the CAMC available for download on its website.
If ransomware was involved in the attack, the publication of files would generally suggest that the organization didn't pay whatever ransom was set by the criminals. ®
Get our [15]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZcpOtekNA7D89yBABjukfAAAAMg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZcpOtekNA7D89yBABjukfAAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZcpOtekNA7D89yBABjukfAAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZcpOtekNA7D89yBABjukfAAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZcpOtekNA7D89yBABjukfAAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.caravanclub.co.uk/whats-on/caravan-club-news/latest-information-regarding-the-cyber-security-incident/
[7] https://www.theregister.com/2024/02/12/infosec_news_roundup/
[8] https://www.theregister.com/2024/02/10/malicious_traffic_broker_vextrio/
[9] https://www.theregister.com/2024/02/09/hive_leaders_bounty/
[10] https://www.theregister.com/2024/01/24/major_it_outage_at_caravan/
[11] https://www.theregister.com/2024/01/24/major_it_outage_at_caravan/
[12] https://regmedia.co.uk/2024/01/24/camc_outages_screenshots.jpg
[13] https://www.theregister.com/2024/01/18/ransomware_attacks_hospitalize_security_pros/
[14] https://www.theregister.com/2023/11/17/lockbit_cracks_whip_on_affiliates/
[15] https://whitepapers.theregister.com/
"The official line at the beginning was that investigators had been drafted in and there was no evidence to suggest member data was compromised, a stance that has since shifted to open up the possibility of data access. CAMC, however, reported itself to the UK's data watchdog, the Information Commissioner's Office, from the outset."
In so many of these cases a lack of honesty & transparency from the outset.
If in doubt, communications assume the worst case data leak scenario & warn customers ASAP
.. If it turns out the actual result was "better" than worse case scenario, then regard that as a bonus.
The BS of "minor incident". gradually unfolding over time to statements along the lines of "Ooh, crown jewels nabbed" gets tedious & irritates customers.
I'm not one of the El Reg readers affected by this, just sick and tired of seeing the same old PR drivel, when customers would be better served by honesty, even if its just "we don't know how bad it is, so assume the worst until we know otherwise"
"I'm not one of the El Reg readers affected by this"
I am, and the CAMC has been shambolic at handling this. The first we knew was the website going down (500), then they put up a holding page. It was ~6 days before they issued their first statement. They claimed they were told not to go public with an announcement, presumably in the hope that their 1M+ members (including myself) simply wouldn't notice.
In January. When most people have a new holiday year. And are starting to book holidays. Like we were trying to.
On the upside
Thousands of hacked companies can now breathe a bit easier as their exfiltrated data is now stuck in a long line of traffic to the dark web behind all this stuff.
Re: On the upside
Yes, but it will have impact as now people will know who owns one..
:)
More of the same...
""I would like to offer my sincere apologies for any inconvenience this has caused, and thank you for your continuing patience as we return to normality,"
That's what they say every bank holiday,
CAMC ... offers a variety of insurance policies
Hope they remembered to cover themselves against IT risks.
The problem is, even if you have the best security systems on earth, there can still be flaws in the system that expose your data to a skilful hacker (or even a trojan written by a skilful hacker). Even if there aren't, all they need is an operator with a weak password or that falls for a phishing attempt. If that operator is an admin, then that is better for them.
The problem is that ideally, all companies handling any kind of data they don't want in the open, should have secure and up to date tech (this includes all software and devices that the data might be stored on, accessed by or travel through) that is thoroughly locked down, and regularly security tested. All staff that have any access to the data should receive proper training on keeping that data securie, including anti phishing training, and should be regularly (and anonymously) tested.
I should note that even the most skeptical, security minded people *can* be fooled into falling for scams.
That's the ideal world, from a security point of view. We work in the real world. What is ideal is often costly and inconvenient, so tends to get forgotten.
"Data security is of paramount importance to the Club, our members, guests, and suppliers. We have taken further actions under the instruction of our cybersecurity experts to enhance the Club's cybersecurity to help prevent this type of incident from happening again."
Yeah, yeah.
If the first sentence were true, you'd have done the things in the second sentence before it happened, not after.