HomeSecurityCRM platform SevenRooms confirmed to have been breached

CRM platform SevenRooms confirmed it was breached

Restaurant customer relationship management ( CRM ) platform “SevenRooms” has confirmed that it has suffered a data breach after a threat actor began selling stolen data on a hacking forum. SevenRooms is a restaurant customer relationship management (CRM) platform used by international restaurant chains and hospitality providers, including MGM Resorts, Bloomin' Brands, Mandarin Oriental, Wolfgang Puck and many others. See also: Metropolitan Opera: Which systems were affected by the cyberattack



SevenRooms crm platform hacking

On December 15, a threat actor posted samples of the data on the hacking forum Breached, claiming to have stolen a 427GB backup database containing thousands of files containing information about SevenRooms customers.

The samples provided by the vendor included folders with names of major restaurant chains, SevenRooms customers, API, promotional codes, payment reports, reservation lists, and more.
SevenRooms security officials confirmed that it was their own data that was stolen and that it was caused by an unauthorized access to the systems of one of its suppliers.

“We recently learned that a third-party vendor’s FTI (file transfer interface) had gained unauthorized access,” a SevenRooms spokesperson told BleepingComputer.

See also: RootAyyildiz: Hacker attack on Leo Messi’s e-shop 

SevenRooms crm platform hacking
sample of the stolen data

The company clarified that guests’ credit cards, bank account details , social security numbers or any other similar information were not exposed in the attack, as they were not stored on the compromised servers . What may have been affected are some API credentials that have expired, as well as some of their guests’ data, such as their emails and phone numbers . SevenRooms claims that its systems were not directly compromised and that they remain secure against unauthorized external access. “We have taken measures to prevent anyone from accessing the interface and have launched an investigation to find out if any of SevenRooms’ private databases were affected,” said a SevenRooms spokesperson. SevenRooms has also hired an independent cybersecurity firm to help investigate the incident and will provide updates as more information becomes available. While it's unclear which restaurants or customers were affected by the breach, it's likely we'll see more announcements from restaurants whose customer data has been compromised later. Source: BleepingComputer.com









📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS