Estos de Ledger parecen tener dificultades en saber gestionar los comunicados. Primero, diría que en Julio 2020, informar de un hackeo, minimizando el volumen de clientes impactados con datos personales (9.500) + 1M emails. Luego, en diciembre, informan que la cifra es de 272.00 (tras ver la BD en Raidforum).
Ahora, envían un nuevo comunicado relativo al breach de Shopify, que es su proveedor de e-comerce (al comprar en la página de Ledger, entiendo que va a través de Shopify). Por las fechas que indican en comunicado abajo citado, estamos hablando de los mismo (dicen que hasta el 21/12/2020 no supieron que Ledger era de los productos sobre los cuales se extrajo información desde Shopify – la fecha es la misma que la oficialización del hackeo tras Raidforum).
O me he perdido algo, o el comunicado abajo citado no referencia el recibido el 21/12/2020 por parte de las personas perjudicadas. Si hablan de lo mismo, deberían explicitarlo, e indicar que este comunicado es un intento de descarga de responsabilidad sobre Shopify. Si son dos cosas distintas, ¿son conjuntos distintos con posibles coincidencias? ¿Es un hackeo o dos?
Hablan de que Shopify se lo comunicó el día 23/12/2020, lo cual no me cuadra con el segundo comunicado, que fue anterior (del 21/12/2020).
O estoy espeso, o tienen problemas de comunicación …
Dear client,
On December 23, 2020, Shopify, our e-commerce service provider, informed Ledger of an incident involving merchant data. Rogue agent(s) of their customer support team obtained Ledger customer transactional records in April and June 2020. This is related to the incident reported by Shopify in September 2020, which concerns more than 200 merchants, but until December 21, 2020, Shopify had not identified this affected Ledger as well.
We were able to examine the stolen data together with a third party forensic firm to identify the impacted customers.
We regret to inform you that you are part of the customers whose detailed personal information was stolen by Shopify rogue agent(s). Specifically, your name and surname, detail of product(s) ordered, phone number and your postal address were exposed.
We notified the French Data Protection Authority on December 26, 2020. We are continuing to work with Shopify and law enforcement on the case; an investigation is already underway, led by the FBI and the RCMP. Ledger also reported the events to the French Public Prosecutor and filed a complaint against the rogue agent(s).
Thefts and attacks such as this cannot go uninvestigated or unprosecuted. We continue to work with law enforcement as well as private investigators on these cases, and we are adding more firepower by hiring additional private investigation capacity, adding experience and approaches to finding those responsible for these data thefts.
FINALLY, keeping you secure is our reason for existing. We will soon release a technical solution that will remove the 24 words as the single pillar of the security of our hardware wallets and will open the door to funds insurance.
If you would like more detail on the many steps we are taking to prevent such incidents in the future, please read this blog post.
Sincerely,
Pascal Gauthier
Ledger CEO
En su momento, dijeron que lo de Shopify no les afectaba (ver
https://www.ledger.com/our-ecommerce-database-has-not-been-hacked). Tururú …