Autodoc hacked
Posted: Fri Sep 09, 2022 11:12 pm
I know a few people use Autodoc on here for car parts. They've been hacked.
Initial comms:
"No other data is affected, in particular no access data, passwords, credit card data, bank data, credit balances, or order
details."
Now: "According to our investigations, we cannot completely rule out the possibility that the perpetrators got hold of encrypted data, behind which customer passwords are also hidden"
So basically, I speculate that they did poor data segregation, someone phished a customer services person and their customer passwords were pivotable from that.
And - speculation again - they probably weren't well encrypted very well and they think they can be decrypted. If they were confident in their encryption, they'd have said so. Good encryption will be realistically uncrackable for a solid decade from today, etc.
Search your email for AutoDoc, if you have an account, change your password, and the usual change it on other places it was shared with because I knw you do that.
Also, you might not have got an email about this. My pal Charles did. The initial comms were over two weeks ago. The most recent one (where passwords are mentioned as being at risk) is from last night.
I didn't get any emails about this....
....at all....
Initial comms:
"No other data is affected, in particular no access data, passwords, credit card data, bank data, credit balances, or order
details."
Now: "According to our investigations, we cannot completely rule out the possibility that the perpetrators got hold of encrypted data, behind which customer passwords are also hidden"
So basically, I speculate that they did poor data segregation, someone phished a customer services person and their customer passwords were pivotable from that.
And - speculation again - they probably weren't well encrypted very well and they think they can be decrypted. If they were confident in their encryption, they'd have said so. Good encryption will be realistically uncrackable for a solid decade from today, etc.
Search your email for AutoDoc, if you have an account, change your password, and the usual change it on other places it was shared with because I knw you do that.
Also, you might not have got an email about this. My pal Charles did. The initial comms were over two weeks ago. The most recent one (where passwords are mentioned as being at risk) is from last night.
I didn't get any emails about this....
....at all....