Malware

Trend Micro Customers Data Leaked – An Insider Bypassed Sophisticated Security Controls

Trend Micro disclosed an insider security breach that exposes a set of its consumer customers’ data such as phone numbers, first&Last name, Email address exposed.

The incident was learned by Trend Micro in August 2019, as some of their consumer customers who using home security solutions started receiving spam calls from cybercriminals mimicking as Trend Micro Support.

How the Data Leak Occurs?

The information shared by the cybercriminals over the phone let Trend Micro launch an investigation. the investigation confirms there is no external, but some internal source exfiltrated the data.

Further investigation reveals that “a malicious internal source that engaged in a premeditated infiltration scheme to bypass our sophisticated controls,” reads Trend Micro report.

An Employee uses fraudulent methods to gain access to the customer support database that contains customer details such as names, email addresses, Trend Micro support ticket numbers, and in some instances telephone numbers.

There are no indications that any other information such as financial or credit payment information was involved, or that any data from our business or government customers was improperly accessed.   

The investigation revealed that the employee sold the information to malicious actors, “We took swift action to contain the situation, including immediately disabling the unauthorized account access and terminating the employee in question, and we are continuing to work with law enforcement on an ongoing investigation.”

The company also confirmed that the company “will never call you unexpectedly. If a support call is to be made, it will be scheduled in advance.”

Insider Threat

Insider threats are the cybersecurity threats within the organization, possibly it is an employee or a vendor – even ex-employees.

The insider threats categorized into five different types of Disgruntled employees, Malicious insiders, Inside agents, Regular employees, and Third-party providers and contractors.

According to the 2018 threat report, 53% of the companies have confirmed that insider attacks against their organizations in 12 months and 27% said that insider attacks are more frequent.

You can follow us on LinkedinTwitterFacebook for daily Cyber security and hacking news updates.

Also Read

Top Cyber Security Trends Expected In 2020

Over 21 Million Stolen Login Credentials of Fortune 500 Companies Available on Dark Web

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago