Gabia Discloses Personal Information Leak of 2,998 Customers;
IT DAILY ·
✦ AI Summary
Gabia confirmed and disclosed that customer personal information had been leaked through unauthorized access by an external attacker.
The leak affected 2,998 people, and the leaked items were 4 types of data: customers' names, IDs, email addresses and mobile phone numbers.
Gabia said it confirmed the intrusion, which occurred around 11:45 a.m. on September 21, on the 23rd, and that no password leak had been confirmed.
Gabia said it confirmed that customer personal information had been leaked through unauthorized access by an external attacker and disclosed the incident through a notice on its website and an advisory. It said the leak was confirmed on the 23rd and involved 2,998 people.
According to the leak Gabia confirmed, an external attacker made unauthorized access on the 21st, and the incident occurred around 11:45 a.m. on September 21. The leaked items were customers' names, IDs, email addresses and mobile phone numbers, for a total of 4 types of data. So far, no password leak has been confirmed.
The cause of the incident was found to be insufficient verification of external requests for some functions of the web service. The vulnerability was an input validation flaw, and the attacker exploited it to access the internal system. In the process, personal information was transmitted outside.
Gabia said it first became aware of signs of intrusion around 1:05 p.m. on September 21. It took about 1 hour and 20 minutes from the incident to the first detection. Gabia then began reporting the incident and launched a full investigation.
Immediately after recognizing the incident, Gabia blocked the external access path used in the attack and promptly suspended the related accounts. It also preserved evidence logs, strengthened access controls for the system and addressed the vulnerability that caused the incident. In addition, it is conducting a companywide inspection for the same type of vulnerability across all systems.
Gabia reported the intrusion incident to the Korea Internet & Security Agency (KISA) and notified the Personal Information Protection Commission of the leak. It is also conducting a detailed root-cause analysis with the relevant agencies and carrying out a joint investigation into whether there was any additional damage.
Gabia said there has been no password leak. However, it noted the possibility of secondary misuse, such as brute-force attacks on accounts at other sites based on the leaked IDs. Accordingly, it urged customers to change their passwords and asked them to beware of phishing and smishing impersonating Gabia and relevant authorities.
Gabia said it is taking the incident seriously as a company that must protect customer information safely. It added that all employees deeply feel their responsibility and said it will fundamentally review its security system. It also said it would do everything possible to prevent a recurrence.
Source: IT DAILY · Kwon Young-seok
Original: https://www.itdaily.kr/news/articleView.html?idxno=241837
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.