HomeSecurityGuess reveals data breach after ransomware attack

Guess reveals data breach after ransomware attack

American brand Guess is notifying affected customers of a data breach following a ransomware attack in February that led to data theft.

Guess has 1,041 retail stores in the Americas, Europe and Asia, and its distributors and partners run another 539 stores worldwide as of May 2021. Stores belonging to the Guess retail network currently operate in approximately 100 countries around the world.

See also: Mint Mobile hit by data breach

Guess

Personal and financial data stolen in the attack

The fashion retailer identified the addresses of all affected individuals after completing a full review of documents stored on compromised systems on June 3, 2021.

Guess began sending breach notification letters to affected customers on June 9, offering free identity theft protection services and one year of free credit monitoring through Experian to all affected individuals.

According to breach notifications sent out on Friday, the information exposed in the attack includes personal and financial details.

While the breach notification letters do not disclose the number of people affected, information submitted to the Maine Attorney General's office indicates that over 1,300 people were affected during the February attack.

The recorded breach data also reveals that the information obtained during the incident is as follows: “Financial account number or credit/debit card number (in combination with a security code, password, passcode, or PIN for the account).”

Guess has implemented additional measures to enhance its security protocols and is cooperating with law enforcement as part of an ongoing investigation into the incident.

See also: CNA reports data breach after ransomware attack

DarkSide ransomware likely behind the attack

Although Guess did not provide information about the identity of the threat actor behind the ransomware attack, DataBreaches.net reported in April that the DarkSide ransomware gang had reported Guess on its data breach website.

At the time, the group claimed to have stolen files from the company's network before attempting to encrypt its systems.

DarkSide has been active since at least August 2020, focusing on corporate networks and demanding millions of dollars for decryptors and the promise not to leak stolen data online.

The ransomware gang came under the spotlight of US law enforcement after it hacked Colonial Pipeline, the largest fuel pipeline in the US.

See also: Volkswagen/Audi: Data breach affects 3.3 million customers

After being scrutinized by law enforcement and the seizure or collapse of some of their infrastructure, the DarkSide operation suddenly shut down in late May, with operators fearing arrest.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS