Did you pay for your pizza with your personal data?

DOMINOS INDIA DATA BREACH.

Introduction

Pizza delivery service Dominos India is the latest victim of a massive data breach that exposed order details of 18 crore pizza orders made via the service. The data breach includes a data dump weighing 13TB of employee data files and customer details. The attackers who are responsible for the breach, also created a webpage on the dark web that pulls the data for any of the leaked order details simply by searching for a phone number or an email address. The data now appears to be publicly available and anyone can search for it easily.

What makes this breach unusual from others?

Dominos India brand owner Jubilant Foodworks experienced an information security breach on 24th March, 2021 wherein their systems were attacked by a hacker. After the incident, many Dominos customers found their data leaked and publicly available to anyone who has their mobile number or email address, allowing anyone to input a phone number or email address and find out the person’s other details, including residential addresses where the order got delivered, and how much they have spent on the pizza chain’s orders. The information was available via a darknet URL that the attacker had created, which could be easily accessed from any smartphone or computer. It no longer requires a browser like TOR or Onion.

The worst part of this breach is that this data is being used to spy on people. Anybody can easily search any mobile number and can check a person’s past locations with date and time, which seems like a real threat to an individual’s privacy. Domino’s uses PayTM as one of it’s payment gateway, which also got breached in the recent past. Domino’s hired an external global forensics agency to do an impact assessment and contain the breach. Meanwhile, the darknet page that made the leaked data publicly available has been taken down and can no longer be accessed. The company confirmed that no financial details like credit cards and CVVs were exposed in the data breach.

Implications of Data Breach

The ramifications of such a breach could be multifold. The first thing for companies to take charge when something happens, is to change their passwords to reset every account in their database rather than sending emails to consumers. This way, customers will be forced to change their passwords. The implication is that these individual customers can now be exploited. Not all consumers are that educated so it’s a big exposure. The Cyber Crime Cell of India was informed and the Free Software Movement of India said it would be taking the matter to the courts after it wrote a letter to CERT-IN seeking an investigation into the incident, but did not receive a response yet.

Proactively disclosing a data breach not only helps maintain trust and transparency amongst consumers, but also helps in reducing the cost incurred by such data breaches. The overall cost of a breach often depends on how it is disclosed. “While it may be tempting to try to quietly resolve any issues without the public knowing, it is much more effective if businesses are proactive about disclosing what has occurred. To reduce the chances of their losses increasing, organisations can take control of the situation and make it publicly known that a breach has happened,” Kaspersky said.  

Need for regulation

The Domino’s Pizza data breach is just the latest in a long list of companies that have had data breaches in recent times. Businesses who are a victim of a data breach today not only are responsible to protect their consumer’s data, but also prevent it from being misused by the cybercriminals as an aftermath of a data breach. Therefore, it is high time India gets its data protection law. There is a strong need for regulations on cybersecurity and compliance which needs to be put in place. Privacy alone is not enough. We need to have a regulator who will be regulating, auditing, and making sure that the security controls are in place. A mandated reporting of breaches should be necessitated and penalties must be levied. We need empowered regulators who can penalise people and debar them from doing business if need be. All public listed companies have an obligation to their shareholders. If there is a breach that can have a material impact on their shareholders, there should be regulations for them to report it to BSE and NSE.

Recommendations

Here’s a list Tsaaro recommends people, they find that they have been impacted by a data breach:

  1. Use different emails and passwords on different accounts. Regular password changes reduce the risk of running into unannounced data breaches.
  2. Mandatorily turn on two-factor authentication for all accounts. Apps such as Authy could be helpful.
  3. Have a secondary email address that doesn’t contain personal information that people can give out to companies or entities, and keep a primary email only for           trusted entities.
  4. Consider a credit freeze. This stops anyone from using your data for identity theft and borrowing in your name.
  5. Check your credit report to ensure you know if anyone is applying for debt using your details.
  6. Try to find out exactly what data might have been stolen. That will give you an idea of the severity of the situation. For instance, if tax details and other identity numbers (Aadhaar/ PAN) have been stolen, you’ll need to act fast to ensure your identity isn’t stolen. This is more serious than simply losing your credit card details.
  7. Don’t respond directly to requests from a company to give them personal data after a data breach; it could be a social engineering attack. Take the time to read the news, check the company’s website, or even phone their customer service line to check if the requests are legitimate.
  8. Stolen data can turn up on the dark web years after the original data breach. This could mean an identity theft attempt occurs long after you’ve forgotten the data     breach that compromised that account. Monitor your accounts for signs of any new activity.
  9. Close accounts you don’t use rather than leaving them dormant. That reduces your vulnerability to a security breach.
  10. When you’re accessing your accounts, make sure you’re using the secure HTTPS protocol and not just HTTP.

Conclusion

Organisations handling end-user data should be investing more in cybersecurity solutions and practices that will enhance their security posture. In today’s digitalised world, protecting end-customer information is vital and implementing technology solutions such as ZTNA, DLP, XDR and security posture management is key. Complementing these with employee education around data handling, vigilance, tight security controls, processes and audits would help create the desired culture of healthy cyber hygiene.

103 thoughts on “Did you pay for your pizza with your personal data?”

  1. What i do not realize is in fact how you are no longer actually much more wellfavored than you might be right now Youre very intelligent You recognize thus considerably in relation to this topic made me in my view believe it from numerous numerous angles Its like men and women are not fascinated until it is one thing to do with Lady gaga Your own stuffs excellent All the time handle it up

  2. Simply wish to say your article is as amazing The clearness in your post is just nice and i could assume youre an expert on this subject Well with your permission let me to grab your feed to keep updated with forthcoming post Thanks a million and please carry on the gratifying work

  3. What i do not realize is in fact how you are no longer actually much more wellfavored than you might be right now Youre very intelligent You recognize thus considerably in relation to this topic made me in my view believe it from numerous numerous angles Its like men and women are not fascinated until it is one thing to do with Lady gaga Your own stuffs excellent All the time handle it up

  4. Excellent blog here Also your website loads up very fast What web host are you using Can I get your affiliate link to your host I wish my web site loaded up as quickly as yours lol

  5. This article is fantastic! The insights provided are very valuable. For those interested in exploring more, check out this link: LEARN MORE. Looking forward to the discussion!

  6. Fantastic beat I would like to apprentice while you amend your web site how could i subscribe for a blog site The account helped me a acceptable deal I had been a little bit acquainted of this your broadcast offered bright clear concept

  7. Hello my loved one I want to say that this post is amazing great written and include almost all significant infos I would like to look extra posts like this

  8. I loved as much as youll receive carried out right here The sketch is tasteful your authored material stylish nonetheless you command get bought an nervousness over that you wish be delivering the following unwell unquestionably come more formerly again since exactly the same nearly a lot often inside case you shield this hike

  9. Your blog is a treasure trove of valuable insights and thought-provoking commentary. Your dedication to your craft is evident in every word you write. Keep up the fantastic work!

  10. Your blog is like a beacon of light in the vast expanse of the internet. Your thoughtful analysis and insightful commentary never fail to leave a lasting impression. Thank you for all that you do.

  11. Somebody essentially lend a hand to make significantly articles Id state That is the very first time I frequented your website page and up to now I surprised with the research you made to make this actual submit amazing Wonderful task

  12. What i dont understood is in reality how youre now not really a lot more smartlyfavored than you might be now Youre very intelligent You understand therefore significantly in terms of this topic produced me personally believe it from a lot of numerous angles Its like women and men are not interested except it is one thing to accomplish with Woman gaga Your own stuffs outstanding Always care for it up

  13. Fantastic beat I would like to apprentice while you amend your web site how could i subscribe for a blog site The account helped me a acceptable deal I had been a little bit acquainted of this your broadcast offered bright clear concept

  14. Your blog is a beacon of light in the often murky waters of online content. Your thoughtful analysis and insightful commentary never fail to leave a lasting impression. Keep up the amazing work!

  15. obviously like your website but you need to test the spelling on quite a few of your posts Several of them are rife with spelling problems and I to find it very troublesome to inform the reality on the other hand Ill certainly come back again

  16. Its like you read my mind You appear to know so much about this like you wrote the book in it or something I think that you can do with a few pics to drive the message home a little bit but other than that this is fantastic blog A great read Ill certainly be back

  17. I was recommended this website by my cousin I am not sure whether this post is written by him as nobody else know such detailed about my difficulty You are wonderful Thanks

  18. Eu amei o quanto você será realizado aqui O esboço é de bom gosto, seu assunto de autoria é elegante, mas você fica nervoso por querer entregar o seguinte mal, inquestionavelmente, vá mais longe anteriormente, exatamente o mesmo quase muitas vezes dentro caso você proteja esta caminhada

  19. My admiration for your creations is as substantial as your own sentiment. The visual presentation is tasteful, and the written content is sophisticated. Yet, you seem uneasy about the possibility of presenting something that may cause unease. I’m confident you’ll be able to resolve this issue efficiently.

  20. Usually I do not read article on blogs however I would like to say that this writeup very compelled me to take a look at and do so Your writing taste has been amazed me Thanks quite nice post

  21. Baddiehubs naturally like your web site however you need to take a look at the spelling on several of your posts. A number of them are rife with spelling problems and I find it very bothersome to tell the truth on the other hand I will surely come again again.

  22. For en utmerket artikkel! Å lese den var virkelig lærerikt for meg. Du ga ekstremt godt organisert materiale, og dine forklaringer var både klare og korte. Din tid og energi brukt på forskning og skriving av denne artikkelen er sterkt verdsatt. Enhver som er interessert i dette emnet vil uten tvil dra nytte av denne ressursen.

  23. Fantastic beat I would like to apprentice while you amend your web site how could i subscribe for a blog site The account helped me a acceptable deal I had been a little bit acquainted of this your broadcast offered bright clear concept

  24. helloI really like your writing so a lot share we keep up a correspondence extra approximately your post on AOL I need an expert in this house to unravel my problem May be that is you Taking a look ahead to see you

  25. I loved as much as youll receive carried out right here The sketch is tasteful your authored material stylish nonetheless you command get bought an nervousness over that you wish be delivering the following unwell unquestionably come more formerly again since exactly the same nearly a lot often inside case you shield this hike

  26. Damian will gather and compile a comprehensive collection of high-quality links, ensuring you have access to all the information and resources you need. This way, you’ll have a well-rounded and reliable source to refer to, making your research or task much easier. Let’s dive in and get started!

  27. I have been surfing online more than 3 hours today yet I never found any interesting article like yours It is pretty worth enough for me In my opinion if all web owners and bloggers made good content as you did the web will be much more useful than ever before

  28. dodb buzz You’re so awesome! I don’t believe I have read a single thing like that before. So great to find someone with some original thoughts on this topic. Really.. thank you for starting this up. This website is something that is needed on the internet, someone with a little originality!

  29. Keep up the fantastic work! Kalorifer Sobası odun, kömür, pelet gibi yakıtlarla çalışan ve ısıtma işlevi gören bir soba türüdür. Kalorifer Sobası içindeki yakıtın yanmasıyla oluşan ısıyı doğrudan çevresine yayar ve aynı zamanda suyun ısınmasını sağlar.

Leave a Reply

Your email address will not be published. Required fields are marked *