Categories: Data Breach

NetGalley Discloses Data Breach After Website Was Hacked

NetGalley Discloses Data Breach After Website Was Hacked

The NetGalley book promotion site has suffered a data breach that allowed threat actors to access a database with members’ personal information.

NetGalley is a website that allows authors and publishers to promote digital review copies of their books (galleys) to book advocates, influential readers, and industry professionals in the hopes that they will recommend the books to their audience.

On Monday, December 21st, NetGalley’s website was hacked and defaced. After further investigations, it was determined that the threat actors also accessed a backup for the site’s database containing members’ data.

“It is with great regret that we inform you that on Monday, December 21, 2020 NetGalley was the victim of a data security incident. What initially seemed like a simple defacement of our homepage has, with further investigation, resulted in the unauthorized and unlawful access to a backup file of the NetGalley database,” NetGalley disclosed in a data breach advisory.

This backup database included NetGalley members’ personal information, including their login name, password, name, and email address. Other optional information that could have been in the database includes users’ mailing address, birthday, company name, and Kindle email address.

NetGalley states that there was no financial information stored in the database. In response to the breach, NetGalley requires all users to reset their password when they next log in.

Also Read: A Look at the Risk Assessment Form Singapore Government Requires

BleepingComputer has reached out to NetGalley with questions on whether the passwords were hashed in the database but has not heard back.

What should NetGalley users do?

If you are a NetGalley member, you should immediately log in to the site and change your password.

If you use the same NetGalley password at other sites, you should also change the password at those sites to a unique and strong one for that site.

Using unique passwords at every site you have an account prevents a data breach at one site from affecting you at other websites you use.

It is suggested that you use a password manager to help you keep track of unique and robust passwords at every site.

Also Read: How to Send Mass Email Without Showing Addresses: 2 Great Workarounds

Privacy Ninja

Recent Posts

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

2 weeks ago

Prioritizing Security Measures When Launching Webpage

Prioritizing Security Measures When Launching a Webpage That Every Organisation in Singapore should take note…

2 weeks ago

The Importance of Regularly Changing Passwords for Enhanced Online Security

Importance of Regularly Changing Passwords for Enhance Online Security that every Organisation in Singapore should…

3 weeks ago

Mitigating Human Errors in Organizations: A Comprehensive Approach to Data Protection and Operational Integrity

Comprehensive Approach to Data Protection and Operational Integrity that every Organsiation in Singapore should know…

3 weeks ago

The Importance of Pre-Launch Testing in IT Systems Implementation

Here's the importance of Pre-Launch Testing in IT Systems Implementation for Organisations in Singapore. The…

4 weeks ago

Understanding Liability in IT Vendor Relationships

Understanding Liability in IT Vendor Relationships that every Organisation in Singapore should look at. Understanding…

1 month ago