Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Razer Data Leak Exposes Personal Information Of Gamers

Razer Data Leak Exposes Personal Information Of Gamers

Razer

Gaming hardware manufacturer Razer has suffered a data leak after an unsecured database for their online store was exposed online.

Razer is a Singaporean-American gaming hardware manufacturer known for their mice, keyboards, and other high-end gaming devices.

Around August 19th, security researcher Bob Diachenko found an unsecured database that exposed the information of approximately 100,000 people who purchased items from Razer’s online store.

This exposed information included a customer’s name, email address, phone number, order numbers, order details, and billing and shipping addresses, as shown below.

Razer data exposed by unsecured database
Razer data exposed by unsecured database

For a few weeks, Diachenko attempted to contact someone at Razer who could secure the exposed database.

Bob Tweet

In a statement to Diachenko’s LinkedIn article, Razer stated that they finally secured the database server on September 9th, and thanked the researcher for his help.

“We were made aware by Mr. Volodymyr of a server misconfiguration that potentially exposed order details, customer and shipping information. No other sensitive data such as credit card numbers or passwords was exposed. The server misconfiguration has been fixed on 9 Sept, prior to the lapse being made public. 

We would like to thank you, sincerely apologize for the lapse and have taken all necessary steps to fix the issue as well as conduct a thorough review of our IT security and systems. We remain committed to ensure the digital safety and security of all our customers.”

Also read: CCTV Law Singapore Edition: Know Your Rights and Responsibilities

What should affected Razer customers do?

If threat actors accessed this data, they could use the information in targeted phishing campaigns to gather more sensitive information such as passwords and credit card details.

While it is not known if any threat actors accessed the exposed data before it was secured, it is vital for those affected to be diligent against potential spear-phishing campaigns.

If you have ever purchased anything from Razer’s online store, be cautious of any emails that state they are from the gaming company.

Furthermore, if you receive an email claiming to be from Razer, be sure to only log in at razer.com and not at other sites.

Also read: A Look at the Risk Assessment Form Singapore Government Requires

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us