Dell resets customer passwords following cyber attack

The company has just issued a statement with more detail regarding the incident

Dell has confirmed that it detected and stopped unauthorised activity on its network which attempted to extract data from customers including names, email addresses and hashed passwords.

The situation resulted in Dell carrying out a forced password reset for customers. But Dell did this on 14 November some five days after discovering the hack attempt on 9 November, meaning customers were potentially left in the dark about the risk posed to their personal data. 

However, the tech giant was keen to assure its customers that following an internal investigation, no information was extracted. That said, it did add that it might be possible that some information had been removed from Dell's servers.

Dell confidently says that no credit card or other sensitive information was extracted from the network, nor did it impact any of its products or services.

"Upon detection of the attempted extraction, Dell immediately implemented countermeasures and initiated an investigation," Dell said in its statement. "Dell also retained a digital forensics firm to conduct an independent investigation and has engaged law enforcement."

"In this age of highly sophisticated information security threats, Dell is committed to doing all it can to protect customers' information," Dell added. "This includes encouraging customers to change passwords for other accounts if they use the same password for their Dell.com account. Dell will continue to invest in its information technology networks and security to detect and prevent the risk of unauthorised activity."

IT Pro has approached Dell for comment over a Reuters report alleging that the company failed to tell customers of what happened when it forced the password resets but had not received comment at the time of publication. 

This is particularly significant because, following GDPR, firms are facing stricter regulations regarding data breaches. Companies are required to tell its customers quickly and accurately about the details of any data breach which would affect them, or risk fines that could rise into the millions.

Featured Resources

Humility in AI: Building trustworthy and ethical AI systems

How humble AI can help safeguard your business

Download now

Future of video conferencing

Optimising video conferencing features to achieve business goals

Download now

Leadership compass: Privileged Access Management

Securing privileged accounts in a high-risk environment

Download now

Why you need to include the cloud in your disaster recovery plan

Preserving data for business success

Download now

Recommended

What is shoulder surfing?
Security

What is shoulder surfing?

2 Dec 2020
Security benefits of open virtualised RAN
Whitepaper

Security benefits of open virtualised RAN

2 Dec 2020
Bitdefender debuts cloud-based endpoint detection and response solution
endpoint security

Bitdefender debuts cloud-based endpoint detection and response solution

2 Dec 2020
Google brings enterprise-grade Android security to SMBs
Google Android

Google brings enterprise-grade Android security to SMBs

2 Dec 2020

Most Popular

350,000 Spotify users hacked in credential stuffing attack
Security

350,000 Spotify users hacked in credential stuffing attack

24 Nov 2020
46 million Animal Jam accounts leaked after comms software breach
Security

46 million Animal Jam accounts leaked after comms software breach

13 Nov 2020
Samsung Galaxy Note might be discontinued in 2021
Mobile Phones

Samsung Galaxy Note might be discontinued in 2021

1 Dec 2020