HomeSecurityRollbar reveals data breach

Rollbar reveals data breach

Rollbar , a software bug-tracking company , has disclosed a breach data that affected customer access tokens . Unknown hackers breached the company’s systems in early August and gained access to the tokens.

Rollbar data breach

The breach was discovered by Rollbar on September 6th while examining data warehouse logs. The examination showed that a service account was used to connect to the cloud- based error tracking platform .

According to the company, the attackers searched the company's data for cloud credentials and Bitcoin wallets.

See also: Hackers stole $53 million worth of cryptocurrencies from CoinEx

“ When we became aware of this access, we disabled the service and began analyzing what actions had been taken by the unauthorized party account ,” Rollbar said in a letter informing about the data breach

The company also says that the attackers first tried to launch compute resources but failed due to a lack of permission. So, they entered the data warehouse and performed searches that indicated they were interested in Bitcoin wallets or cloud credentials.

According to the investigation, hackers had access to Rollbar's systems from August 9 to August 11, 2023.

During their presence on Rollbar's servers, the attackers had access to sensitive customer information, including addresses usernames and email, account names, and project information.

See also: 3AM Ransomware: A new malware family

Rollbar reveals data breach
Rollbar reveals data breach

Data Breach: Customer Access Tokens Stolen

Most importantly, customers' project access tokens, which allow them to interact with Rollbar projects, were also stolen during the attack.

The company says that access tokens that allow access to Rollbar project data have expired, while those that allow data to an active project will expire in 30 days.

“While our investigation is ongoing, we consider the security of data to be of paramount importance and, as such, we are writing to update you on the discovery and the steps we have taken,” Rollbar said.

“We will also hire an external consultant to assist us in verifying these findings“.

See also: BianLian ransomware group stole data from Save The Children

Rollbar says its services are used by 400 million+ app end users and thousands of companies around the world, including Salesforce, Twilio, Uber, Twitch, and Pizza Hut.

This breach highlights the need for continued cybersecurity measures. It is vital for companies to continuously monitor and analyze the cybersecurity of their systems in order to promptly address any issues that arise. The revelations from this Rollbar case indicate that cybercriminal attacks are becoming increasingly sophisticated and multi-faceted, targeting valuable customer and organizational data

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS