Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Creative Software Maker Affinity Informs Customers of Forum Breach

UK-based creative software developer Affinity recently informed the 175,000 users of its forum of a data breach that occurred on April 6.

UK-based photo editing, graphic design and publishing software developer Affinity recently informed its forum members of a data breach that occurred on April 6.

The company said a hacker gained access to forum user data after compromising an administrator’s account. The attacker may have accessed information such as username, reputation, join date, post count, email addresses, and the last used IP address. 

While most of the compromised information is already public, the email address and IP are not, and this type of information can be useful to malicious actors for targeted phishing attacks. Affinity has warned forum users about the risk of phishing.

It’s unclear how many users had their data compromised, but the Affinity forum has nearly 175,000 members. 

Serif, the company that owns Affinity, said it’s confident that user passwords were not compromised in the breach.

“Please be reassured that any information accessed does not include any financial data, purchase history, physical addresses, phone numbers or anything else held within your main Affinity account / AffinityID. The forum is a standalone system which is completely separate from your Affinity account,” the company added. 

The Affinity forum data breach has been reported to the UK Information Commissioner’s Office (ICO) and steps have been taken to prevent such incidents in the future.

It’s unclear how the administrator account was compromised, but in many of these types of incidents account hacking is possible because two-factor authentication has not been used.

Advertisement. Scroll to continue reading.

Related: 400,000 Users Hit by Data Breach at Media Player Maker Kodi

Related: 4.8 Million Impacted by Data Breach at TMX Finance

Related: 500k Impacted by Data Breach at Debt Buyer NCB

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Shay Mowlem named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

More People On The Move

Expert Insights

Related Content

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

CISO Strategy

Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop.

Data Breaches

Delta Dental of California says over 6.9 million individuals were impacted by a data breach caused by the MOVEit hack.

Data Breaches

Sony shares information on the impact of two recent unrelated hacker attacks carried out by known ransomware groups. 

Data Breaches

AT&T is notifying millions of wireless customers that their CPNI was compromised in a data breach at a third-party vendor.

Data Breaches

A group of hackers has leaked Atlassian employee records and floorplans, information that was obtained from third-party workplace platform Envoy.