Experts Reaction On Staples Data Breach

Staples has informed some customers that data relating to their orders has been accessed without permission, but dubbed the data as ‘Non-sensitive” according to researcher Troy Hunt. Cybersecurity experts reacted below.

Chloé Messdaghi, VP of Strategy,  Point3 Security
September 15, 2020
We don’t know how the breach happened but we do know that this is the exact kind of data that can be used maliciously.
For Staples to say that customer order data is non-sensitive is ridiculous. Any social engineer attacker can use that type of data for a phone phishing campaign like this: ‘When you bought (name of purchased product) under xxxxxxxxxxxx confirmation number, we seem to have overcharged you. Can you please provide your full details of the credit card on file with the xxxx last four digits, so I can ....
[Read More >>]
Laurence Pitt, Global Security Strategy Director,  Juniper Networks
September 16, 2020
Any breach in which personal data is stolen needs to be treated as highly serious and punishable.
Many people will see this as a relief that ‘only names, email addresses, and phone numbers’ were shared – their credit cards are safe and their transactions remain a secret. However, this is not the case. These pieces of PII still have value on the black market and can be used in order to gain access to other, and perhaps more sensitive, information. The combination of ‘email address and ....
[Read More >>]
Saryu Nayyar, CEO,  Gurucul
September 15, 2020
In this day and age, there is very little information that can't be leveraged in some way for nefarious purposes.
While the Staples breach appears to be "low impact" in that no sensitive customer information was released, even supposedly non-sensitive information can be leveraged by a savvy attacker. Knowing what a person or business has ordered, and when, can be just the hook an threat actor needs to formulate an effective phishing email or other social engineering attack. In this day and age, there is very ....
[Read More >>]

If you are an expert on this topic:

Submit Your Expert Comments

In this article