Hack on ecommerce site StockX hits 6.8 million customers

The company initially told its customers that password resets were due to "system updates"

StockX

A cyber attack against the popular footwear trading platform StockX is thought to have exposed data belonging to 6.8 million of its customers, according to a recent report.

Customers were initially informed on Thursday that their passwords were reset due to 'system updates', only for the company to change its stance a day later, admitting that it was taking precautions against a suspected data breach.

Advertisement - Article continues below

On Friday the company alerted the press that the password reset was made out of "caution" after being "alerted to suspicious activity", following a report by TechCrunch.

The publication was approached by an anonymous data seller who claimed to have sensitive data belonging to millions of StockX's customers, and that it had been collected following a hack on the company's systems in May.

The data is said to include names, email addresses, hashed passwords and other profile information such as shoe size, preferred trading currency and type of device used to operate the account.

The anonymous source also said the stolen data was actively being sold on the dark web for $300 and there were already confirmed buyers at the time of publication.

"Though our investigation remains ongoing, forensic evidence to date suggests that an unknown third-party was able to gain access to certain customer data, including customer name, email address, shipping address, username, hashed passwords, and purchase history," a StockX spokesperson said in a statement on Saturday. "From our investigation to date, there is no evidence to suggest that customer financial or payment information has been impacted."

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"We want you to know that we took these steps proactively and immediately because we had just begun our investigation and did not yet know the nature, extent, or scope of suspicious activity to which we had been alerted," said StockX. "Though we had incomplete information, we felt a responsibility to act immediately to protect our customers while our investigation continued - and we took steps to do so."

The company, which was valued at $1 billion last month following a $110 million fundraiser, could be facing a significant GDPR fine for breach given that some of that exposed data belongs to EU residents. The penalty for GDPR violations of this kind can be up to 20 million or 4% of the company's annual global turnover, whichever is greater.

However, StockX is also facing criticism for short time it took to reverse its official stance on the password reset.

"Delays, or mixed messages, to sharing information can undermine customer confidence," said Javvad Malik, security awareness advocate at KnowBe4. "The recently levied GDPR fines show that regulators are putting an increased emphasis on customer privacy and personal information.

"Companies, like StockX, should take notice of these and look to improve their cyber security posture, not just from a compliance perspective, but from the point of view to have defensible technologies and processes in place and ensuring all staff are aware of their responsibilities," he added.

Featured Resources

Preparing for long-term remote working after COVID-19

Learn how to safely and securely enable your remote workforce

Download now

Cloud vs on-premise storage: What’s right for you?

Key considerations driving document storage decisions for businesses

Download now

Staying ahead of the game in the world of data

Create successful marketing campaigns by understanding your customers better

Download now

Transforming productivity

Solutions that facilitate work at full speed

Download now
Advertisement

Recommended

Visit/security/ransomware/356292/university-of-california-gets-fleeced-by-hackers-for-114-million
ransomware

University of California gets fleeced by hackers for $1.14 million

30 Jun 2020
Visit/security/cyber-security/356289/australia-announces-135b-investment-in-cybersecurity
cyber security

Australia announces $1.35 billion investment in cyber security

30 Jun 2020
Visit/cloud/cloud-security/356288/csa-and-issa-form-cybersecurity-partnership
cloud security

CSA and ISSA form cyber security partnership

30 Jun 2020
Visit/security/ethical-hacking/356252/poorly-secured-banking-apps-lead-to-cyber-threats
ethical hacking

Mobile banking apps are exposing user data to attackers

26 Jun 2020

Most Popular

Visit/mobile/google-android/356373/over-2-dozen-additional-android-apps-found-stealing-user-data
Google Android

Over two dozen Android apps found stealing user data

7 Jul 2020
Visit/laptops/29190/how-to-find-ram-speed-size-and-type
Laptops

How to find RAM speed, size and type

24 Jun 2020
Visit/cloud/356260/the-road-to-recovery
Sponsored

The road to recovery

30 Jun 2020