vz-risk / VCDB

VERIS Community Database
Other
573 stars 180 forks source link

DataCamp notifies users of data breach #13134

Open swidup opened 5 years ago

swidup commented 5 years ago

https://support.datacamp.com/hc/en-us/articles/360017716074-DataCamp-Security-Update-Frequently-Asked-Questions

Dear Customer,

We are writing to let you know that we recently discovered that some user data was exposed as a result of criminal unauthorized access to one of our systems by a malicious third party. We are sorry for any concern or inconvenience this may cause. We are working rapidly to investigate the situation further and take appropriate steps to prevent such incidents in the future.

What Happened On Monday we discovered that some user data was exposed by a third party who gained criminal unauthorized access to one of our systems. We are still investigating the precise causes and are retaining a leading digital forensics and security firm to assist us in the work being conducted by our internal security team. We will be notifying data protection authorities.Our investigation is ongoing but we have already taken steps to contain the incident. Our efforts to protect our users and prevent this type of incident from happening in the future are our top priority.

What Kind of User Information Was Affected The following information may have been exposed:

Personal information Name Email address Optional information including location, company, biography, education, and picture

Account information Hashed passwords using bcrypt Creation date Last sign in date Sign in IP address

What We Are Doing While our investigation continues, we’re taking additional steps to improve our security:We’re in the process of notifying users whose data has been affected.Out of an abundance of caution, we are logging out all DataCamp users who may have been affected, and, if they use a password as their authentication method, we are invalidating their passwords. These users will receive a second email with a password reset link.

We believe we have identified the root cause and taken steps to address the issue, although our investigation is ongoing and we’ll continue to make security improvements.

You can find additional information, updates, and FAQs about this incident on our website.We will continue to work both internally and with our outside experts to gain a full understanding of what happened and take further action as needed.

Best,

The DataCamp TeamDataCamp Inc. 

| 350 Fifth Avenue | Suite 7730 | New York, NY 10118 | Unsubscribe |

swidup commented 5 years ago

https://www.databreaches.net/datacamp-notifies-users-of-hack-forces-password-reset/