Zomato hacked: Security breach results in 17 million user data stolen

Zomato attributed the breach to human error, where an employee’s development account got compromised and hackers got to lay their hands on the data.

Zomato hacked: Security breach results in 17 million user data stolen
Zomato has suffered a security breach with over 17 million user records stolen from the food-tech company's database. The stolen information has email addresses and hashed passwords of customers.

According to Hackeread.com, a user by the name of " nclay" claimed to have hacked Zomato and was willing to sell data pertaining to 17 million registered users on a popular Dark Web marketplace.

This included emails and password hashes of registered Zomato users with the price set for the whole package at $1,001.43 (BTC 0.5587) - BTC here stands for Bitcoins. Hackeread adds the vendor also published data and evidence to prove it was genuine.

Hashing turns an original password into an incoherent set of characters, bringing down the possibility of it being easily converted back to plain text. Furthermore, passwords of Zomato's 120 million users are reportedly salted as well, whereby characters are added at random before the password hashed, rendering it unintelligible even if the hash is translated.

Also read: Zomato says hacker agrees to destroy 17 million user details, taken off dark web marketplace

Although in theory the password may still be safe, Zomato is encouraging its users to change that password if used for any other services.
ADVERTISEMENT

Amid the news of the leak, no payment information or credit card data has been stolen, the company said in a note released to the press. 'In our security investigation, we have found no evidence of unauthorized access to financial information,' it states. 'Payment related information on Zomato is stored separately from this (stolen) data in a highly secure PCI Data Security Standard (DSS) compliant vault,' it further added.

Despite assurances that increased levels of precautions were made to safeguard users' data, the company, as a preventive measure, has reset the passwords for all affected users and logged them out of its app and website. 'Since we have reset the passwords, affected users' Zomato account as well as credit card information is secure, so there is nothing to worry about there.'

In the blogpost, Zomato has attributed human error as the cause of the security breach where an employee’s development account got compromised. 'Our team is actively scanning all possible breach vectors and closing any gaps in our environment,' the blog stated.

Over the next couple of weeks, the company will reportedly work towards plugging further security gaps - if any - in its systems. This will include adding a layer of authorisation for internal teams having access to such data to avoid the possibility of any human breach.
ADVERTISEMENT


Here is the full text of Zomato's statement:

ADVERTISEMENT
Over 120 million users visit Zomato every month. What binds all of these varied individuals is the desire to enjoy the best a city has to offer, in terms of food. When Zomato users trust us with their personal information, they naturally expect the information to be safeguarded. And that’s something we do diligently, without fail. We take cyber security very seriously - if you’ve been a regular at Zomato for years, you’d agree.

The reason you’re reading this blog post is because of a recent discovery by our security team - about 17 million user records from our database were stolen. The stolen information has user email addresses and hashed passwords.

We hash passwords with a one-way hashing algorithm, with multiple hashing iterations and individual salt per password. This means your password cannot be easily converted back to plain text. We however, strongly advise you to change your password for any other services where you are using the same password.

Important note - payment related information on Zomato is stored separately from this (stolen) data in a highly secure PCI Data Security Standard (DSS) compliant vault. No payment information or credit card data has been stolen/leaked.

As a precaution, we have reset the passwords for all affected users and logged them out of the app and website. Our team is actively scanning all possible breach vectors and closing any gaps in our environment. So far, it looks like an internal (human) security breach - some employee’s development account got compromised.

How can this stolen information be misused?
ADVERTISEMENT

Since we have reset the passwords for all affected users and logged them out of the app and website, your zomato account is secure. Your credit card information on Zomato is fully secure, so there’s nothing to worry about there.

What next?

Over the next couple of days and weeks, we’ll be actively working to plug any more security gaps that we find in our systems.

We’ll be further enhancing security measures for all user information stored within our database
ADVERTISEMENT
A layer of authorisation will be added for internal teams having access to this data to avoid the possibility of any human breach.
We regret any disruption this may cause and appreciate your immediate attention to this information. If you have queries/concerns, please do not hesitate to contact our security team by sending an email directly to support@zomato.com and we’ll reach out to you right away.
Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
5 ways to become a smaller target for ransomware hackers
1/4
Once your files are encrypted, your options are limited. Recovery from backups is one of them. "Unfortunately, most people don't have them," Abrams says. Backups often are also out of date and missing critical information. With this attack, Abrams recommends trying to recover the "shadow volume" copies some versions of Windows have.

Some ransomware does also sometimes targets backup files, though.
You should make multiple backups — to cloud services and using physical disk drives, at regular and frequent intervals. It's a good idea to back up files to a drive that remains entirely disconnected from your network.
Once your files are encrypted, your options are limited. Recovery from backups is one of them. "Unfortunately, most people don't have them," Abrams says. Backups often are also out of date and missin..
Read More
Using antivirus software will at least protect you from the most basic, well-known viruses by scanning your system against the known fingerprints of these pests. Low-end criminals take advantage of less-savvy users with such known viruses, even though malware is constantly changing and antivirus is frequently days behind detecting it.
Using antivirus software will at least protect you from the most basic, well-known viruses by scanning your system against the known fingerprints of these pests. Low-end criminals take advantage of l..
Read More
Basic protocol such as stressing that workers shouldn't click on questionable links or open suspicious attachments can save headaches. System administrators should ensure that employees don't have unnecessary access to parts of the network that aren't critical to their work. This helps limit the spread of ransomware if hackers do get into your system.
Basic protocol such as stressing that workers shouldn't click on questionable links or open suspicious attachments can save headaches. System administrators should ensure that employees don't have un..
Read More
Some organisations disconnect computers as a precautionary measure. Shutting down a network can prevent the continued encryption — and possible loss — of more files. Hackers will sometimes encourage you to keep your computer on and linked to the network, but don't be fooled.

If you're facing a ransom demand and locked out of your files, law enforcement and cybersecurity experts discourage paying ransoms because it gives incentives to hackers and pays for their future attacks. There's also no guarantee all files will be restored. Many organisations without updated backups may decide that regaining access to critical files, such as customer data, and avoiding public embarrassment is worth the cost.
Some organisations disconnect computers as a precautionary measure. Shutting down a network can prevent the continued encryption — and possible loss — of more files. Hackers will sometimes encourage ..
Read More
READ MORE
ADVERTISEMENT

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

Related Companies

More from our Partners

Loading next story
Business News › Small Biz › IT › Security › Zomato hacked: Security breach results in 17 million user data stolen
Text Size:AAA
Success
This article has been saved

*

+