BreachesHIGH

Data Breach - Aura Exposes 900,000 Records After Phishing

🎯

Basically, Aura was hacked after an employee answered a fake phone call, exposing customer information.

Quick Summary

Aura has disclosed a data breach affecting 900,000 records due to a phishing attack. The exposed data includes names and email addresses of customers. While immediate actions were taken, affected individuals should remain vigilant against potential identity theft.

What Happened

Aura, a cybersecurity firm, recently revealed a significant data breach that compromised approximately 900,000 records. This incident was triggered by a targeted phone phishing attack aimed at one of its employees. The attackers gained access to the employee's account for about an hour before the breach was detected. Upon discovering the breach, Aura quickly terminated the compromised account and activated its incident response plan. They also engaged external cybersecurity experts and notified law enforcement to investigate the incident.

The breach primarily involved data from a marketing tool used by a company that Aura had acquired in 2021. This acquisition has now come under scrutiny due to the sensitive nature of the data involved. Aura's swift response highlights the importance of having a robust incident response plan in place to mitigate potential damage from such attacks.

Who's Affected

The breach impacts around 20,000 current customers and approximately 15,000 former customers. The exposed information includes names, email addresses, physical addresses, and phone numbers. However, Aura has confirmed that no Social Security numbers, passwords, or financial information were compromised during this incident. This is a crucial point, as it lowers the risk of identity theft for affected individuals.

Aura has begun notifying the impacted customers and is providing them with support. The company reassured customers that the compromised information was not stored in a manner that would significantly elevate their risk. This proactive communication is vital in maintaining customer trust following such incidents.

What Data Was Exposed

The data accessed in this breach consists mainly of names and email addresses. While the volume of records is substantial, the nature of the data is less sensitive than financial or personally identifiable information that could lead to identity theft. Aura has emphasized that sensitive customer data is encrypted and access to it is highly restricted, which likely prevented more severe consequences from the breach.

Despite the breach, Aura's systems are designed with multiple safeguards to limit exposure in case of a security incident. These organizational, technical, and physical safeguards were effective in this case, as they prevented access to more sensitive information. This incident serves as a reminder of the importance of data security measures, even when breaches occur.

What You Should Do

If you are a current or former customer of Aura, it is essential to stay vigilant. Monitor your email and physical mail for any communications from Aura regarding the breach. Although the company has stated that the risk of identity theft is low, it is wise to take precautionary measures such as changing passwords and enabling two-factor authentication on your accounts.

Additionally, consider checking your credit report regularly for any unusual activity. If you notice anything suspicious, report it immediately. Staying informed and proactive can help mitigate the impact of data breaches like this one. Remember, cybersecurity is a shared responsibility, and being aware of potential threats is the first step in protecting yourself.

🔒 Pro insight: The breach underscores the vulnerability of human factors in cybersecurity; organizations must enhance employee training against phishing attacks.

Original article from

SecurityWeek · Ionut Arghire

Read Full Article

Related Pings

HIGHBreaches

Marquis Data Breach - Affects 672,000 Individuals Revealed

Marquis has revealed a data breach affecting 672,000 individuals. Sensitive personal and financial information has been compromised, raising significant security concerns. Affected individuals should monitor their accounts closely.

SecurityWeek·
HIGHBreaches

Aura Data Breach - 900,000 Records Exposed in Attack

Aura has confirmed a data breach exposing 900,000 records due to a phishing attack. Affected individuals include active and former customers. The notorious hacking group ShinyHunters is believed to be behind the breach, raising concerns about data security.

Help Net Security·
HIGHBreaches

Data Breach - Major Verizon Retailer's Records Stolen

A major data breach has hit Russell Cellular, a Verizon retailer, with over 6.3 million customer records stolen. This breach poses significant risks to customers and employees alike. Immediate action is required to protect sensitive information.

SC Media·
HIGHBreaches

Data Breach - Aura Exposes 900,000 Marketing Contacts

Aura confirmed a data breach exposing 900,000 customer records. Names and emails were compromised, raising identity theft concerns. Aura is notifying affected individuals and working with experts.

BleepingComputer·
HIGHBreaches

Data Breach - Over 670,000 Affected by Marquis Software Attack

A massive data breach at Marquis Software has impacted over 670,000 individuals. Sensitive information, including Social Security numbers, has been exposed. This incident raises serious privacy concerns for numerous financial institutions involved. Stay alert for updates and protective measures.

The Record·
MEDIUMBreaches

Stryker - Restoring Ordering and Shipping Systems After Attack

Stryker is recovering from a cyberattack that disrupted its ordering and shipping systems. The company believes the threat is contained and is restoring operations. This incident highlights the importance of cybersecurity in healthcare.

Cybersecurity Dive·