HomeSecurityCheckout.com: Apologizes for breach - Donates ransom for cybersecurity research

Checkout.com: Apologizes for Breach – Donates Ransom for Cybersecurity Research

One of the sad truths in this world of constant cyberattacks and data breaches is that companies simply don't apologize. Even as customers, partners, and employees wonder when their data will be released on the dark web, breached organizations seem to be doing everything they can to avoid saying what seems to be the hardest word of all: sorry. But that's not the case for Checkout.com.

Checkout.com data breach

Businesses that have been hacked often delay, evade, and hide behind phrases like “out of an abundance of caution” and “we take your security seriously.” What they usually don’t do is admit they were wrong, own up to their mistakes, and promise to make things better.

They may fear that if they admit their weaknesses, there is a risk of a class action lawsuit, while building trust with your customers, business partners, and employees takes a back seat.

See also: Lazarus' new ScoringMathTea RAT allows remote command execution

However, payment processing service Checkout.com handled the situation differently. It appears that the hacker group ShinyHunters is responsible for a breach that allowed access to data from an older cloud storage system operated by Checkout.com.

According to Mariano Albera, CTO of Checkout.com, it is believed that “less than 25%” of the company’s current merchant base was affected by the data breach. Essentially, the breach affected a system that was “used for internal operational documents and merchant onboarding materials at the time.”

Checkout.com: Apologizes for Breach - Donates Ransom for Cybersecurity Research

Fortunately, Checkout.com's live payment platform was not compromised and payment card information was not in the hands of hackers. In fact, it was an old system that was used "since 2020 and before."

The hackers allegedly stole data and demanded a ransom from Checkout.com, threatening to publish the stolen information on the dark web if the company did not comply.

See also: UNC1549 targets aerospace and defense systems

Checkout.com: Apologizes for Data Breach

According to Bitdefender, Checkout.com did not provide any excuses. Instead, it publicly disclosed the incident and apologized, stating, “This was our mistake, and we take full responsibility. We are sorry.” They also stated: “We will not succumb to the criminals’ blackmail. We will not pay this ransom… We will donate the ransom amount to Carnegie Mellon University and the Oxford University Security Center to support their research in the fight against cybercrime.”

Checkout.com: Apologizes for Breach - Donates Ransom for Cybersecurity Research

Indeed, this response is interesting and contrasts with the typical “We are investigating,” “We take security seriously,” and “We have no further comment at this time…”.

But as good as that is, the truth is that Checkout.com also failed to protect its data. They may have been quick to communicate and take responsibility for what happened, but that doesn't erase the security failure.

See also: Microsoft: Azure network “hit” by 15 Tbps DDoS attack

The data ended up in the hands of attackers, via an older system that the company had seemingly not used since 2020. Older systems are a liability – often left accessible, unattended, poorly configured, and without updates. Ultimately, the reason this data breach occurred was because an older data storage system had not been fully retired.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS