Attackers leveraged stolen employee credentials to infiltrate Rite Aid's network and facilitate the theft of customer data from June 6, 2017, to July 30, 2018.
In a filing with the Securities and Exchange Commission, Bassett Furniture disclosed that while the operations of its retail stores and e-commerce platforms continue, order fulfillment activities have been affected by the ransomware incident.
Included in the leaked customer profiles, which have been generated with the combination of a list of 500 million email addresses fed into the API and the returned account details, were users' full names, email addresses, and other public account information.
Nearly $15 million of the received payment, which was also confirmed by another source close to the matter, has been reallocated to over 20 addresses across five global exchanges.
While RansomHub admitted to having compromised Rite Aid customers' ID numbers and rewards numbers, Rite Aid emphasized that none of its clients' health information, financial details, and Social Security numbers have been exposed.
Infiltration of American Golf's systems has purportedly enabled the exfiltration of members' information, user IDs, passwords, and secret keys, as well as emails, licenses, passports, reports, and financial details.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.