Sunday, March 8, 2020

Zendesk will need to meditate after this one: Pwned!

Zendesk is a cloud-based ticketing platform widely used. There are 145k customers across 160 countries. With the issue, there are Zendesk “customers” who are companies who have contracted with Zendesk and have embedded their software for customer chat and support ticketing system into the customer’s websites. There are also agents who are the employees of these companies, who are actively managing the tickets and answering the user’s chats.
Breach
Zendesk was breached in November 2016.  This, unfortunately, happens all too often in this day and age. The issue is this was announced in early October 2019. Zendesk stated they just detected the breach on September 24, 2019. Somehow the unauthorized third party was able to compromise the parameter and breach their systems and maintain a presence for nearly three years, unknown and undetected. The circumstances beg the question, how did other organizations accomplish for so long?
To add to this, Zendesk was alerted by a third party of the compromise, per their Updated Notice Regarding the 2016 Security Incident. Both of these combined make one wonder what the cybersecurity team was doing instead of monitoring their logs, operations, etc.
This does sound bad, and it clearly is, however, this goes beyond the normal level of breach. This also lists its customers like Airbnb, Slack, Uber, Shopify, Tesco, and OpenTable.
There are a number of open questions at this time. One of which involves the attacker’s access. Were they able to move laterally whenever they wanted, accessing everything, and only part of the attack was published? The company website noted the company follows industry standards as this relates to storage. While that sounds great, what would this really mean in simple English?
Data
Email addresses, names, and phone numbers of agents (employees of the companies that work with the Zendesk software for ticketing and chats with users) and end-users of certain Zendesk products were included in the compromise. Also, agent and end-user passwords (these were hashed and salted), TLS encryption keys for approximately 700 clients, configuration settings of apps installed from the Zendesk app marketplace or private applications. These were in a database, which the attackers were able to gain access to. Thus, there was PII involved with the compromise, which did not help the situation much.
The data affected was for tens of thousands of persons. On September 24, 2019, they identified nearly 15k Zendesk Support and Chat accounts affected by this. Later, approximately 7k customer accounts, some no longer active, had their authentication information accessed.
Post-Compromise

The attackers did access 10k passwords. While this is a detriment, Zendesk noted they detected no evidence that the passwords were used in a malicious manner.
Zendesk appreciates the level of error this involves. To address this, they have expanded their single sign-on (SSO) and multi-factor authentication across their workspaces increased their security monitoring and logging, increased security scanning at the application level and corporate enterprise. Zendesk is also expanding its third party testing. This should definitely assist with the prevention of future issues.
Zendesk also has contacted law enforcement, naturally, and forensic experts to help with the breach investigation.
There have been financial repercussions from this also. Zendesk (NYSE: ZEN) lost approximately 4% of its stock value the day after the disclosure. The markets watch this type of activity closely in the short term.
Notification
Of all their clients, the affected sample is, fortunately, a small ratio of their entire customer base. This could easily have been much worse.
Given the magnitude and depth of the breach, Zendesk was required to notify the affected parties. This was done with the mass number of emails. Zendesk also plans on a large password reset for the users in the system prior to November 1, 2016. This is a massive task. There are going to be many, many calls to the IT Help Desk from the affected parties. Fortunately, if anyone had changed their password since the breach or who have been using the single sign-on (SSO) are exempt from this. This will reduce the potential call-load for complaints and questions.
Not the first rodeo
Usually, a company gets pwned once at this scale and there are no issues heard for a long-long time. Well, this isn’t Zendesk’s first incident with this type of issue. Zendesk was also successfully attacked in 2013. This breach affected Twitter, Tumblr, and Pinterest.
Resources
Betz, B. (2019, October 2). Zendesk -4% after disclosing data breach. Retrieved from https://seekingalpha.com/news/3503496-zendeskminus-4-after-disclosing-data-breach
Cimpanu, C. (2019, October 12). Zendesk discloses 2016 data breach. Retrieved from https://www.zdnet.com/article/zendesk-discloses-2016-data-breach/
Daniel, E. (2019, October 22). Zendesk-Discloses 2016 data breach after three years. Retrieved from https://medium.com/datadriveninvestor/zendesk-discloses-2016data-breach-after=three-years-i-e-on-september-24-2019-820d14d14fa0bea
Duran. (2019, October 3). Zendesk reveals that a data breach affected the emails and passwords of 10,000 users in 2016. Retrieved from https://www.cyclonis.com/zendesk-reveals-data-breach-affected-emails-passwords-10000-users-2016/
Gatlan, S. (2019, October 2). Zendesk security breach may impact orgs like uber, slack, and fcc. Retrieved from https://www.bleepingcomputer.com/news/security/zendesk-security-breach-may-impact-orgs-like-uber-slack-and-fcc/
Hashim, A. (2019, October 3). Zendesk alerts users of data breach that occurred in 2016! Retrieved from https://latesthackingnews.com/2019/10/03/zendesk-alerts-users-of-data-breach-that-occurred-in-2016/
Heller, M. (2019, October 3). Zendesk breach in 2016 affected 10,000 customers. Retrieved from https://searchsecurity.techtarget.com/news/252471927/Zendesk-breach-in-2016-affected-10000-customers
Kovacs, E. (2019, October 3). Zendesk discloses old data breach affecting 10,000 accounts. Retrieved from https://www.securiytweek.com/zendesk-discloses-old-data-breach-affecting-10000-accounts
Muncaster, P. (2019, October 3). Zendesk breach hits 10,000 corporate accounts. Retrieved form https://www.infosecurity-magazine.com/news/zendesk-breach-hits-10000/
Panettieri, J. (2019, October 2). Zendesk discloses chat data breach. Retrieved from https://www.channele2e.com/technology/security/zendesk-chat-data-breach/
Paganini, P. (2019, October 2). Zendesk 2016 security breach may impact uber, slack, and other organizations. Retrieved from https://securityaffairs.co/wordpress/92051/data-breach/zendesk-2016-security-breach.html
Payne, D. (2019, October 2). Zendesk has disclosed a 2016 data breach. Retrieved from https://www.internetnewsflash.com/zendesk-has-disclosed-a-2016-data-breach/
Pawluk, A. (2019, October 3). Security breach in zendesk discovered. Retrieved from https://blog.verohum.com/news/security-breach-in-zendesk-discovered/
Secure Reading. (2019, October 3). Zendesk discloses security breach. Retrieved from https://securereading.com/zendesk-discloses-security-breach/
Swartz, J. (2019, October 2). Shares of Zendesk drop 4% after it discloses security breach. Retrieved from https://www.marketwatch.com/story/shares-of-zendesk-drop-4-after-it-discloses-security-breach-2019-10-02
Van Horenbeeck, M. (2019, November 22). Updated notice regarding 2016 security incident. Retrieved from https://www.zendesk.com/blog/security-update-2019/
Winant, D. (2019, October 6). Zendesk discloses 2016 data breach. Retrieved from https://seclists.org/dataloss/2019/q4/20



Friday, March 6, 2020

Overlake Medical Center has more than phishing to deal with: Medical records leaked




Through our lifetimes, we will need to visit a hospital, medical center or clinic for one reason or another. This may consist of the obligatory annual physical, stitches after a fall, or to refill medications. For various reasons, the commonality is the persons are visiting the medical facility for medical services. Dependent on the individual needs, this may be critical or a standard appointment. With these, the patient requires the services. When there is an issue with providing the service, this affects the medical facility, but also every single patient that would have received medical care at the facility. We’ve seen the effects of phishing attacks on most industries. Dependent on the specific attack, this can be especially problematic for the medical facilities. The Overlake Medical Center & Clinics have experienced this recently.
Overlake Medical Center & Clinics
The Overlake Medical Center & Clinics is based in Bellevue, Washington. The facility is non-profit and has 364 beds. All was well until the issue was detected.
Attack
The medical facility was the victim of the infamous, yet uncomplicated, phishing attack. In early December 2019, a small number of employees had seen the phishing lure and decided the email was legitimate when it actually was not, clicking on the link, image, or whatever the attack tool used was in this case. It was noted the unauthorized party, who had harvested the credentials, had infected the accounts between December 6-9, 2019. This was detected once the attackers began to access the email accounts on December 9th. Within hours, the medical center did secure the affected email accounts and began their investigation.
Data
For some reason, the patient data was stored in the email accounts for the 109k affected patients. This possibly included names, dates of birth, phone numbers, addresses, health insurance information, insurer number, diagnoses, and treatment information. This is a treasure trove for the attackers. This data may be sold in whole or sliced into usable sections for specific malicious parties.
Post-Attack
After the compromise was detected, the medical facility was required to notify the affected. This began on February 7, 2020, as they started to contact 109,000 patients. This is a rather arduous task due to the number of patients, and the subject matter. Even if a small ratio of the persons called the medical center seeking answers to their questions, there would still be a mass amount of labor to take the calls and talk to each proactive affected patient.
As of the notification date, this was the third-largest breach for the year.
The medical center did state there was no evidence the data had been used by the unauthorized parties. This is a hollow statement though. With the attackers having this, they or the purchasers, if applicable, could wait to use this, or if this was used, it may be difficult to pinpoint this compromise as the cause.
Additional Security Features
Due to the successful attack, the medical facility did reset the employee passwords and put into place additional security features (e.g. multi-factor authentication and email retention policies). The facility was also enhancing their staff education to attempt to assist them to better recognize and then avoid the phishing emails.
Questions
There is a question of the timing. They found the credentials had been compromised and used from December 6th through the 9th, 2019. They did not start to notify the affected parties until February 7, 2020. Granted the medical facility has to complete their investigation, including the attack vector analysis, and determining who was affected. If this were have taken a month, this still leaves a month for the medical practice to arrive at the data, which seems a bit long, even for a conservative approach to the forensic review.
Helpful Tips
While phishing attacks are an epidemic, there are measures which the medical facilities may put into place to reduce this issue to a reasonable level of acceptable risk. These include, however certainly are not limited to
·        Having secured storage in place and tested regularly. Simply having storage in place is not enough. This would need to be tested to ensure the storage is viable.
·        Log collection. This is a very useful tool. This allows the organization to periodically check activities, including attempted connections, and connections. There are several SIEMs in the market which will analyze these for the organizational, reducing significantly the labor overhead which would need to be expended otherwise. One such highly regarded tool to accomplish this is Splunk.
·        File integrity monitoring. This is coupled with the secured storage. If the files are lacking integrity, they are not exceptionally useful.
·        Event detection. In order to know there has been an issue, the event has to be detected. This is another situation where a SIEM would provide the organization with the data and analysis to show the compromise and begin the incident response protocol. Two SIEMs which could be used to accomplish this are Splunk or AlienVault.
Resources
Davis, J. (2020, February 20). 109k patient records impacted in overlake medical phishing attack. Retrieved from https://healthitsecurity.com/news/109k-patient-records-impacted-in-overlake-medical-phishing-attack
Garrity, M. (2020, February 4). 10 tips for hospitals to mitigate ransomware attacks. Retrieved from https://www.beckershospitalreview.com/cybersecurity/10-tips-for-hospitals-to-mitigate-ransomware-attacks.html
Garrity, M. (2020, February 20). 364-bed Washington community hospital notifies 109,000 patients of phishing attack. Retrieved from https://www.beckershospitalreview.com/cybersecurity/364-bed-washington-community-hospital-notifies-109-000-patients-of-phishing-attack.html
McGee, M.K. (2020, February 25). Phishing in healthcare: Yet another major incident. Retrieved from https://www.databreachtoday.com/phishing-in-healthcare-yet-another-major-incident-a-13767
Overlake Medical Center & Clinics. (2020, February 7). Notice of phishing incident. Retrieved from https://www.overlakehospital.org/notice-of-phishing-incident



Monday, March 2, 2020

EA's code oversight


Everyone loves a good video game every now and again. These vary in their genre and computing power. These grasp and hold the player’s attention for hours upon hours. This has grown into such an industry, there are massive corporations creating and hosting these games, and also hosting the tournaments. One example is Electronic Arts (EA).
Issue
As part of its services, EA offers a tournament series. The subject here is EA’s FIFA 20 Global Series. To those unfamiliar with the group and game, this is a big deal. This is a $3M competitive circuit. This is a rather competitive tournament using the organizations’ FIFA 20 soccer-themed game and the focus. There just happened to be a minor issue with this. On October 3, 2019, right after the website used to sign people up was put online, the gamers noted immediately the other person’s private information was being leaked. EA inadvertently leaked approximately 1,600 user’s personal data, who previously entered the data with EA’s service.
Data
What would happen is the gamer would enter their information and while entering their respective information, the gamers were shown other gamer’s data. Naturally, this created an issue as the gamer is not going to confirm other gamer’s information as to their own. The leaked data included the user/player’s ID, birthday, email address(es), and country of origin. While this is not a good thing, it could have been much worse. This is more embarrassing than an epic fail. Once the leak was discovered, the website was taken down, which took approximately 30 minutes. While this is much quicker than other companies, this still allowed for 1,600 user’s information to be leaked. This quick response was definitely a positive thing. If they would have been the victim of paralysis by analysis, this would have been much worse.
Remediation
EA has apologized for their oversight, which is fair. At this point, no information or data was leaked which could be used for identity theft. This was, however, their oversight and a portion of the affected gamers are still displeased with EA.
Resources
Carpenter, N. (2019, October 4). EA data breach could impact 1,600 FIFA 20 players. Retrieved from https://www.polygon.com/2019/10/4/20898543/fifa-20-global-series-data-breach-ea-sports
Cimpanu, C. (2019, October 4). EA website snafu leaks data of 1,600 FIFA 20 pro gamers. Retrieved from https://www.zdnet.com/article/ea-website-snafu-leaks-data-of-1600-fifa-20-pro-gamers/
Lyles, T. (2019, October 4). EA discloses massive data breach affected thousands of competitive FIFA players. Retrieved from https://www.digitaltrends.com/gaming/ea-fifa-data-breach/

Saturday, February 22, 2020

Compromising an Electronics Giant


Mitsubishi Electric is a global leader in electronics and electrical equipment manufacturing. With their expansive product line and capabilities, they are a giant in the industry. That being said, they still are targeted!
Breach
The breach occurred on June 28, 2019. This was not announced until January 2020. This may never have been announced publicly, except for two newspapers (Nikkei and Asahi Shimbun) publishing articles on the same. This was probably not the optimal strategy. This may have led to or added onto a mistrust. With a compromise of business this size, the issue was bound to become known in public circles.
Bad Actor
The newspapers both named Tick as the malicious party behind the compromise. Tick is a Chinese-linked cyber-espionage group. While this may not be well-known in the enterprise community, this group is known in InfoSec.
Symptoms of the Issue
Everything appeared fine until that fateful day. The Mitsubishi Electric staff detected a suspicious file on one of their servers. Also, at this time there was unusual network behavior and irregular activity, which added to the suspicion. Once determined there was an issue, this was traced back to a compromised user’s account. Through this avenue, the attack continued. They gained access to approximately 14 other company department networks, including sales and head administration networks. The attack ended up compromising tens of PCs and services in Japan and other locations. In a stroke of genius, the attackers also deleted access logs, in an attempt to cover their tracks.
Data
Once the abnormal behavior was noted, external access was restricted immediately. While this action was heroic, there was data exfiltrated from the internal network. The estimate is 200 MB of data was stolen. There is a mixture of reports on what was exfiltrated. The data pool, for the most part, consists of mostly business documents relating to government agencies, and other business partners. This may have also included email exchanges with the Defense Ministry, Nuclear Registry Authority, and projects with private firms (e.g. utilities, railway operators, communications, and automakers). This also involved personal information and recruitment application information and new graduate recruitment applications for 1,987 persons. Lastly, there were 2012 survey results regarding personnel treatment for 4,566 employees and 1,569 retirees in the data pool exfiltrated. While not in the several hundred thousand affected, this is still a rather large number of persons affected.
???
One question that comes to mind is why this took so long to report. The investigation itself was complex. The attackers thought through the attack and deleted activity logs. This coupled with the attack method would make the investigation an interesting activity. Simply investigating the compromise on its own footing takes a bit of time due to the many opportunities for attack.
It’s not likely more substantive details will follow. This would have been another opportunity to learn from, so others would be able to build their defenses against like attacks.
Resources
Cimpanu, C. (2020, January 20). Mitsubishi electric discloses security breach, china is main suspect. Retrieved from https://www.zdnet.com/article/mitsubishi-electric-discloses-security-breach-china-is-main-suspect/
Gatlan, S. (2020, January 20). Mitsubishi electric warns of data leak after security breach. Retrieved from https://www.bleepingcomputer.com/news/security/mitsubishi-electric-warns-of-data-leak-after-security-breach/
Japan Times. (2020, January 20). Mitsubishi electric data likely compromised in massive cyberattack blamed on Chinese group. Retrieved from https://www.japantimes.co.jp/news/2020/01/20/business/corporate-business/mitsubishi-electric-cyberattack-china/?mid=1#cid=9238821
National Cybersecurity. (2020, January 20). Mitsubishi electric discloses information leak. Retrieved from https://nationalcybersecurity.com/infosec-mitsubishi-electric-discloses-information-leak/
Nikkei. (2020, January 20). Mitsubishi electric data may have been compromised in cyberattack. Retrieved from https://asia.nikkei.com/Business/Companies/Mitsubishi-Electric-data-may-have-been-compromised-in-cyberattack
Paganini, P. (2020, January 20). Mitsubishi electric discloses data breach, media blame china-linked APT. Retrieved from https://securityaffairs.co/wordpress/96636/data-breach/mitsubishi-electric-data-breach.html

Thursday, February 13, 2020

Photography service pwned!


Photography has been a hobby for decades. People take pictures on vacation, of their friends,
pets, and virtually everything else. For special events, e.g. a wedding, graduation, or other events,
they may hire a professional to not only take but also print the pictures with quality paper.
Target
In this instance, the Target was 500px. This is a photography website used, among other
services, to store portfolios. The breach occurred at approximately Jul 5, 2018. This directly
affected 14,870,304 of the service’s user accounts, or nearly all the accounts. Put another
way, if the user had an account on or before July 5, 2018, they were impacted.
Attack
The organization was the victim of a successful attack, breach, and compromise. The data
exfiltrated included names, user names, email addresses, birth date if the user provided it,
city, state, country, and gender. This data is easily sold or otherwise used maliciously. This
could be easily sold, used by the attackers, or simply used for credential stuffing attacks.
???
The timing seems unique for the breach and detection. The detection appears to have taken
nearly 7.3 months to notice. This seems a bit long for any timeline. Seemingly any SIEM
would have detected not only the unauthorized IP, but also the mass amount of data being
floated from the organization. Nearly 15M users involves a mass amount of data. Also,
the organization did not indicate how the attack happened. By now, the hole or vulnerability
would have been fixed at this point. The publication would not have hurt the organization.
Management could have disclosed something about, even at a high level, a successful attack.
Remediation
There was a password reset for the 14.8M affected users. To correct this required a mass
amount of time, which was compounded by calls from the users questioning what happened.

Resources
Digital Trends. (2019, February). 500px reveals almost 15 million users are caught up in
security breach. Retrieved from
https://www.digitaltrends.com/computing/500px-almost-15-million-users-caught-up-in-security-breach/  

Dunn, J.E. (2019, February 15). Photography site 500px resets 14.8 million passwords after
data breach. Retrieved from https://nakedsecurity.sophos.com/2019/02/15/photography-site-600px-resets-14-8-million-passwords-after-data-breach/

Page, C. (2019, February 13). 500px confirms 2018 data breach that exposed data on
15 million users. Retrieved from https://www.theinquirer.net/inquirer/news/3070980/500px-data-breach



Friday, February 7, 2020

Attacked down under: Hospitals pwned!


In our lifetimes, we may visit the hospital two or three times, or more. With the medical facilities, they require data and information to operate. This is presently in the form of EHR and EMR (electronic health records and electronic medical records). These allow the doctors to complete their tasks, nurses to pass medications, physical therapists to provide therapy, etc. Without the services being available, there is a mortal danger. There were a number of hospitals attacked in 3Q2019 whose operations were affected.
Targets
For this set of attacks, the medical facilities were located in the Australian state of Victoria. In particular, this affected two large health systems. These were the Gippsland Health Alliance and South West Rural Health Alliance (SWARH). SWARH provides health care services for approximately 23k square miles. This range is from West Melbourne to the border of south Australia. While this is substantial, this also affected Barwon Health, a regional network in the Geelong region, and West Gippsland Healthcare Group. Overall, at least seven major hospitals were breached. There were also unfortunately, other servers across the state compromised during this set of attacks. The hospitals needed to segregate and disconnect systems to stop the wave of compromised systems. In effect, the hospitals quarantined the systems from the internet.
Attack
The hospitals were already prepped to some extent for cyber-attacks. While this is the case, the attackers were able to bypass the security controls which were already in place. The means for this was ransomware. This has become an epidemic in the industry. Through the attack, they were able to gain unauthorized access. The ransomware was used, as with the myriad of other attacks, to encrypt the hospital’s respective files. The attacks focused on patient booking and financial systems. The attack was designed to bring down their operations. With any patient booking system that is down, unless you have the next few days or weeks printed, you can’t know for certain what appointments are in the future, or the types of procedures. Due to this, the hospitals were not able to plan for the operations. Without the financial system able to be used, the hospital could not pay salaries or bills. Their budgeting processes would not work, and the finance department also would not be able to ensure the departments are within their spending limits. As of 10/2/2019, there was no specific ransom demanded.
Effects
At least one hospital was forced to resort to using pen and paper systems for booking appointments and procedures. During the outage, the hospitals were not able to access patient histories, charts, images, and other data. This did not affect every department and bypassed the emergency departments.
Data
The press release stated there was no evidence the personal patient information had been accessed. The data, however, is timeless. This could be used for years to come by the unauthorized parties.
Remediation
While this successful attack is significant, the hospitals and other affected systems were assisted by the Victorian Cyber Incident Response Service and the Australian Cyber Security Center. The management for the Victorian Government Cyber Incident Response Service recommended not paying the ransom. This is generally the best route for the breached organizations.

Resources
Australian Associated Press. (2019, September 30). Systems shut down in victorian hospitals after suspected cyber attack. Retrieved from https://www.theguardian.com/australia-news/2019/oct/01/systems-shut-down-in-victorian-hospitals-after-suspected-cyber-attack

Department of Premier and Cabinet. (2019, September 30). Cyber health incident. Retrieved from https://www.vic.gov/au/cyber-health-incident

Gatlan, S. (2019, October 1). U.S. and Australian hospitals targeted by new ransomware attacks. Retrieved from https://www.bleepingcomputer.com/news/security/us-and-australian-hospitals-targeted-by-new-ransomware-attacks/

Goodin, D. (2019, October 1). Ransomware forces three hospitals to turn away all but the most critical patients. Retrieved from https://arstechnica.com/information-technology/2019/10/hamstrung-by-ransomware-10-hospitals-are-turning-away-some-patients/

Hattersley-Gray, R. (2019, October 1). New ransomware attacks hit U.S., Australian hospitals. Retrieved from https://www.campussafetymagazine.com/news/new-ransomware-attacks-hit-u-s-australian-hospitals/

Kirk, J. (2019, October 2). Australian medical facilities hit by ransomware. Retrieved from https://www.govinfosecurity.com/australian-medical-facilities-hit-by-ransomware-a-13167


Not even dating sites are excluded!

The prominence of the internet has permeated most industries. One notable example is dating applications. These provide the opportunity for people to meet based on personal choices. There are many choices for this with consenting adults. One of these, OKCupid, had the opportunity to practice implementing their incident response plan with expertise! Of the population of industries to attack, what makes the dating applications an attractive target is the data they hold. This may include the names, email addresses, possibly payment information, and other pertinent data. This may be sold on the dark web, but also possibly used for credential stuffing.
Attack
This was a successful attack. A portion of OKCupid’s user accounts appears to have been compromised. The users did state their accounts had been accessed by an unauthorized party and the password had been changed along with the email address for the account. Effectively, this locked the users out of their own accounts. This does appear to be a credential stuffing attack. OKCupid has stated there had been no hacking of the user accounts. This may actually be the case, as the accounts taken over were sporadic, and without a trend. This may have been simply due to user negligence.
Could have, would have, and should have
To decrease the opportunity for this to happen to other organizations, there are a few things the business could do. These are relatively simple, yet effective. One is to have the system set up so that when there is a change in the account, the user receives an email prior to this taking effect. This would serve to notify the user, in case of an attack, of what is occurring with their account. The organization could also use MFA (multi-factor authentication) to assist with this. Generally, there is a cost with this, however, this is used by many businesses and works well.
Resources
Cyware. (2019, February 12). Dating site OKCupid potentially hit by a credential stuffing attack. Retrieved from https://cyware.com/news/dating-stie-okcupid-potentially-hit-by-a-credential-stuffing-attack-6aa9e21f
Dark Reading Staff. (2019, February 11). OKCupid denies data breach amid account hack complaints. Retrieved from https://www.darkreading.com/endpoint/okcupid-denies-data-breach-amid-account-hack-complaints/d/d-id/1333842
Information Security Buzz. (2019, February 12). OKCupid hit by hackers. Retrieved from https://www.itsecuritynews.info/okcupid-hit-by-hackers/
PYMNTS. (2019, February 11). OKCupid user accounts are hacked. Retrieved from https://www.pymnts.com/news/security-and-risk/2019/okcupit-user-accounts-hacked/
Security Experts. (2019, February). OKCupid hit by hackers. Retrieved from http://www.hackbusters.com/news/stories/4348667-okcupid-hit-by-hackers
Security Experts. (2019, February 12). OKCupid hit by hackers. Retrieved from https://www.informationsecuritybuzz.com/expert-comments/okcupid-hit-by-hackers/#disqus_thread