Dell resets customer passwords following cyber attack

The company has just issued a statement with more detail regarding the incident

Dell has confirmed that it detected and stopped unauthorised activity on its network which attempted to extract data from customers including names, email addresses and hashed passwords.

The situation resulted in Dell carrying out a forced password reset for customers. But Dell did this on 14 November some five days after discovering the hack attempt on 9 November, meaning customers were potentially left in the dark about the risk posed to their personal data. 

However, the tech giant was keen to assure its customers that following an internal investigation, no information was extracted. That said, it did add that it might be possible that some information had been removed from Dell's servers.

Dell confidently says that no credit card or other sensitive information was extracted from the network, nor did it impact any of its products or services.

"Upon detection of the attempted extraction, Dell immediately implemented countermeasures and initiated an investigation," Dell said in its statement. "Dell also retained a digital forensics firm to conduct an independent investigation and has engaged law enforcement."

Advertisement
Advertisement - Article continues below

"In this age of highly sophisticated information security threats, Dell is committed to doing all it can to protect customers' information," Dell added. "This includes encouraging customers to change passwords for other accounts if they use the same password for their Dell.com account. Dell will continue to invest in its information technology networks and security to detect and prevent the risk of unauthorised activity."

IT Pro has approached Dell for comment over a Reuters report alleging that the company failed to tell customers of what happened when it forced the password resets but had not received comment at the time of publication. 

This is particularly significant because, following GDPR, firms are facing stricter regulations regarding data breaches. Companies are required to tell its customers quickly and accurately about the details of any data breach which would affect them, or risk fines that could rise into the millions.

Featured Resources

The essential guide to cloud-based backup and disaster recovery

Support business continuity by building a holistic emergency plan

Download now

Trends in modern data protection

A comprehensive view of the data protection landscape

Download now

How do vulnerabilities get into software?

90% of security incidents result from exploits against defects in software

Download now

Delivering the future of work - now

The CIO’s guide to building the unified digital workspace for today’s hybrid and multi-cloud strategies.

Download now
Advertisement

Recommended

Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/hardware/354232/raspberry-pi-4-owners-complain-of-broken-wi-fi-when-using-hdmi
Hardware

Raspberry Pi 4 owners complain of broken Wi-Fi when using HDMI

29 Nov 2019
Visit/cloud/amazon-web-services-aws/354223/what-to-expect-from-aws-reinvent-2019
Amazon Web Services (AWS)

What to expect from AWS Re:Invent 2019

29 Nov 2019
Visit/mobile/google-android/354189/samsung-galaxy-a90-5g-review-simply-the-best-value-5g-phone
Google Android

Samsung Galaxy A90 5G review: Simply the best value 5G phone

22 Nov 2019