Sunday, January 26, 2025
Homecyber securityMOVEit Hack : Over 185,000 AutoZone Users Personal Data Hacked

MOVEit Hack : Over 185,000 AutoZone Users Personal Data Hacked

Published on

SIEM as a Service

Follow Us on Google News

AutoZone Inc., a US retailer of automotive parts and accessories, warned customers that their data had been compromised as a result of the Clop MOVEit file transfer attacks.

Personal information, such as the names and social security numbers of 185,000 individuals, was impacted due to the extensive MOVEit hacking campaign.

Founded in 1979, AutoZone, Inc. is the largest retailer in the United States, with 7,140 locations around the country as well as in Mexico, Puerto Rico, Brazil, and the US Virgin Islands.

Overview of the Data Breach

According to the company’s breach notification, more precisely, AutoZone discovered that certain data had been exfiltrated as a result of the MOVEit application’s vulnerability being exploited on or around August 15, 2023.

An unauthorized third party had taken advantage of a MOVEit vulnerability and was able to exfiltrate some data from a system that AutoZone maintains and uses to support the MOVEit application.

Document
Free Webinar

Live API Attack Simulation Webinar

In the upcoming webinar, Karthik Krishnamoorthy, CTO and Vivek Gopalan, VP of Products at Indusface demonstrate how APIs could be hacked. The session will cover: an exploit of OWASP API Top 10 vulnerability, a brute force account take-over (ATO) attack on API, a DDoS attack on an API, how a WAAP could bolster security over an API gateway

The vulnerability in the MOVEit Transfer program affected over two thousand companies worldwide, as has been widely publicized.

AutoZone took action to evaluate and fix the issue as soon as they learned about the incident. In particular, the company launched an inquiry and hired independent specialists.

“We  began an investigation to understand the scope and impact. We also took measures to address the vulnerability, including temporarily disabling the MOVEit application, rebuilding the affected system, and patching the vulnerability. We have no evidence at this time that the incident is ongoing”, reads the notification.

The MOVEit software vulnerability, identified as CVE-2023-34362, was exploited by the Cl0p ransomware group to steal data from numerous enterprises that were utilizing the program for file transfers.

The vulnerability impacted the US Department of Energy, Siemens Energy, Schneider Electric, Shell, hundreds of US schools, and the state of Maine.

Hence, the business advised customers to be on the lookout for identity theft and fraud. Additionally, avoid opening attachments or clicking links in shady emails, and exercise caution when you receive unsolicited communications requesting personal information from you or directing you to a website that provides.

Experience how StorageGuard eliminates the security blind spots in your storage systems by trying a 14-day free trial.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Subaru’s STARLINK Connected Car’s Vulnerability Let Attackers Gain Restricted Access

In a groundbreaking discovery on November 20, 2024, cybersecurity researchers Shubham Shah and a...

Android Kiosk Tablets Vulnerability Let Attackers Control AC & Lights

A security flaw found in Android-based kiosk tablets at luxury hotels has exposed a...

CISA Releases Six ICS Advisories Details Security Issues

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued six Industrial Control Systems (ICS)...

Juniper Routers Exploited via Magic Packet Vulnerability to Deploy Custom Backdoor

A sophisticated cyber campaign dubbed "J-magic" has been discovered targeting enterprise-grade Juniper routers with...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Subaru’s STARLINK Connected Car’s Vulnerability Let Attackers Gain Restricted Access

In a groundbreaking discovery on November 20, 2024, cybersecurity researchers Shubham Shah and a...

Android Kiosk Tablets Vulnerability Let Attackers Control AC & Lights

A security flaw found in Android-based kiosk tablets at luxury hotels has exposed a...

CISA Releases Six ICS Advisories Details Security Issues

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued six Industrial Control Systems (ICS)...