Industry News: Cyber

Know Your Breach: ENC Security

Written by Cybersecurity | Dec 2, 2022 3:04:48 PM

The Target: ENC Security, Netherlands based data-encryption firm.

The Take: Exposure of security keys for various firm applications and software including: SMTP credentials for sales channels, Ayden, the firm’s single payment platform, email marketing Mailchimp APIs, licensing payment APIs, and public and private keys.

 The Vector: A misconfigured data server was left open and unsecured, meaning anyone with an internet connection could have viewed and downloaded the data.

This breach is critical reminder that authentication controls are an important piece in an overall robust cybersecurity posture and furthermore, that such precautions must in place in all third-party vendors that have access to a firm’s data. Multi-factor authentication and password length and complexity rules are effective strategies to mitigate these kinds of breaches to protect a firm’s data.

Read more...