
A new data breach, discovered by security researchers at vpnMentor, allows access to Tech Data client servers. According to the researchers, Noam Rotem and Ran Locar, the exposed data includes invoices, SAP integrations, plaintext passwords, and more.
Tech Data recently reported quarterly earnings that beat expectations, showing an increase from last year. More than 1 in 4 Fortune 500 companies have been hacked in the past decade, making Tech Data a particularly vulnerable group.
What information was leaked?
Tech Data is an infrastructure company with 45 years of presence in the field, which collaborates with suppliers such as Apple, Cisco, Samsung, Symantec, etc. The data leak it suffered affects a large amount of corporate and personal data concerning both customers and employees.
System-wide data was leaked from a login management server, which included users' email and personal information data, as well as reseller and invoice contact information, payment and credit card details, internal security logs, unencrypted logins and passwords, and more.
Specifically, some of the leaked data are:
Private API keys
Bank Information
Payment details
Username and unencrypted passwords
Full PII (personally identifiable information) is visible, such as:
Full names
Job titles
Email addresses
Postal addresses
Phone numbers
Fax numbers
Information regarding machines and processes of customers' internal systems was also leaked.
What is the risk of information exposure?
Much of the leaked information is easy to find with a simple search and includes payment information, PII, as well as full company and account details for end users and service providers (MSPs).
In addition to hackers , however, this breach could be an "easy prey" for Tech Data's competitors, who could exploit the leaked information to their advantage.
What do the experts advise?
According to security experts, this leak could have been prevented. There are a number of steps companies can take to avoid such a situation:
The most important thing is to secure their servers.
Second, implement appropriate access rules.
Finally, never leave a system that does not require authentication open to the Internet.
