Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

Office Break-in Prompts Vudu to Warn Customers

Vudu, a subscription-based digital entertainment service, says that crooks walked off with a number of items, including hard drives when they broke into their offices last month. The company says the delay in notification was due to a request form law enforcement investigating the break-in.

Vudu, a subscription-based digital entertainment service, says that crooks walked off with a number of items, including hard drives when they broke into their offices last month. The company says the delay in notification was due to a request form law enforcement investigating the break-in.

The company stresses that their corporate website wasn’t hacked, but that thieves broke into their offices on March 24, 2013. The next day, when the break-in was discovered, an inventory discovered a number of missing items, including hard drives containing account information.

Vudu says that the drives themselves contained names, email addresses, postal addresses, phone numbers, account activity, dates of birth and the last four digits of some credit card numbers. Complete credit card details are not maintained by the company, but they are playing it safe with regards to the other data and have reset everyone’s password.

“While the stolen hard drives included VUDU account passwords, those passwords were encrypted. We believe it would be difficult to break the password encryption, but we can’t rule out that possibility given the circumstances of this theft. Therefore, we have reset all customer passwords,” Vudu said in a statement.

“It is possible that you could get spam email, emails asking for personal information, or emails asking you to click on links to other websites. As always, you should never provide personal or account information in response to a call or email claiming to be VUDU (or anyone else) and you should avoid clicking on links in emails you were not expecting.”

In addition to the warnings, password resets, and strengthened password requirements, customers will be notified of the breach by email, and given additional instructions as to how they can enroll in a free credit monitoring service.

Not everyone qualifies for this, only those with passwords on the service will be eligible. 

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Incident Response

Microsoft has rolled out a preview version of Security Copilot, a ChatGPT-powered tool to help organizations automate cybersecurity tasks.