HomeSecurityTravel company servers seized due to breach

Travel company servers seized due to breach

The Privacy Protection Authority in Israelhas seized servers hosting several travel booking websites because their operator failed to address issues , resulting in data breaches affecting more than 300,000 people.

See also: OpenSea reveals data breach – warns of phishing attacks

servers

At least 10 websites operated by Gol Tours LTD in Israel have been shut down following a notice from the agency regarding the patching of security vulnerabilities that allowed malicious actors to steal personal information and data belonging to customers.

Israel's Privacy Protection Authority confirmed the cyberattack, which is believed to be the work of an Iranian threat actor, the Times of Israel.

Ram Levi, CEO of Konfidas, a cyber and crisis management company, said the hackers belong to an Iranian group called the Sharp Boys.

Levi notes that the websites have been shut down and the agency is reviewing the systems as part of its investigation.

See also: Emails warn of copyright infringement and install LockBit ransomware

The owner of Gol Tours said that hackers only stole names and phone numbers for the website's databases and that the agency's accusations of refusing to improve security were false.

infringement

"We never said we wouldn't upgrade security because it would cost us money," Gol Tours said, adding that "the authority had sent us a faulty document and did not respond to our messages."

On its website, the Sharp Boys gang describes itself as “an independent hacker group.” They announced the breach on June 11, saying they had stolen databases containing names, phone numbers, email, credit card data, passport numbers and travel history of customers.

The above list published by the threat actor includes the same websites that have been reported to have been shut down by the Israeli Privacy Protection Authority.

See also: Flagstar Bank: Data breach affects 1.5 million customers

In the days following the announcement of the breach, Sharp Boys leaked 300,000 customer data files.

The gang also shared a screenshot of a remote desktop connection that showed they had access to more than two dozen domains allegedly belonging to Gol Tours.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS