
According to a report published by TV2 a short while ago, the EasyPark app, widely used in Denmark for paying for parking spaces in most parts of Denmark, has been hacked by internet hackers.
وبناء على ذلك فقد قامت شركة EasyPark بإرسال رسائل عبر البريد الإلكتروني للعملاء اليوم الجمعة، يفيد بأن الشركة تعرضت لهجوم إلكتروني في 10 ديسمبر/كانون الأول الجاري، وتذكر الشركة أن هذه معلومات “غير حساسة”، ولكنها مع ذلك تشجع العملاء على أن يكونوا على دراية بشيء واحد على وجه الخصوص، وهو أن الهجوم أدى إلى تسرب بيانات العملاء غير الحساسة، حسبما كتب EasyPark في البريد الإلكتروني بحسب ما ورد في المصدر.
According to EasyPark, hackers were able to access certain information from many of the service's customers. This information includes full name, phone number, address, and email address. They were also able to access parts of customers' credit card information, which is displayed in connection with payment in the application. However, according to the source quoting EasyPark, the information cannot be used to make payments because it is insufficient in this regard.
The company adds that the hackers were unable to access data describing where customers stopped or the customer's registered vehicles.
وقد صرحت لينا ليندال رئيسة قسم الاتصالات في EasyPark لقناة TV 2 بالقول أن أمان وسرية بيانات العملاء لهما أهمية قصوى ولذلك فإن الوضع يزعجهم أيضاً، مضيفة “إننا نشعر بحزن عميق لحدوث ذلك، وسنواصل العمل الجاد كل يوم لكسب ثقة العملاء”.
ولأسباب أمنية، لا تستطيع EasyPark مشاركة تفاصيل الحادث ولا كم عدد الدنماركيين الذين تأثروا بها، ومع ذلك، فإن هذا جزء من عملاء التطبيق في جميع أنحاء أوروبا بحسب لينا ليندال، والتي وضحت أيضاً للمصدر أنه عندما تصف EasyPark المعلومات التي تم الوصول إليها بأنها “غير حساسة”، فإن ذلك يتوافق مع لوائح الاتحاد الأوروبي المعمول بها في المنطقة.
احذر من “التصيد الاحتيالي”
على الرغم من أنها معلومات “غير حساسة” تمكن المتسللون من الوصول إليها، إلا أن التسريب يمكن أن يخلق حالة من عدم اليقين بين مستخدمي التطبيق، كما تعترف مديرة الاتصالات لينا ليندال: “نحن ندرك أن التعرض لخرق البيانات يثير القلق، وكما هو الحال دائمًا، يجب أن تكون على دراية بمحاولات التصيد الاحتيالي ، وهي شائعة للأسف”.
ما هو “التصيد”؟
- Fake emails and text messages are called phishing and scams. These are the methods criminals use to steal your personal information electronically.
- This usually happens when you receive a phishing email or SMS message in which the sender tries to persuade you to hand over your personal information, such as payment card information, MitID information, or other private information via email, a fake website, or something else.
- Phishing can also occur when you are contacted and informed that you have won a contest, for example, and that you must provide your personal information in order to receive the prize.
Source: Sikkerdigital.dk, citing TV2
EasyPark reported that the attack was dealt with quickly and an overview of affected customers was created, where all affected customers will be contacted.
Although some parking service customers may not have been aware of the attack until the email was sent on Friday, EasyPark has been reporting the attack via its app and website since December 14, explains Lena Lindahl. She adds that the Danes who received the email on Friday were those who did not open the message sent in the app, and some may also have been contacted via text message.
The attack on EDC, a well-known real estate company
According to the source, EasyPark is not the only major company that has recently been subjected to cyberattacks that led to data leaks. Last November, EDC was attacked by a pro-Russian hacking group called Black Basta. The group obtained a large amount of customer data, including nearly 100,000 social security numbers of current and former EDC customers. More than 700,000 pieces of common customer data, such as name, email, and address, were compromised.
كما ذكرت EDC بعد الهجوم أن نسخًا من جوازات السفر ورخص القيادة والتأمين الصحي تعرضت للخطر أيضًا بحسب ما ورد من المصدر، وقد هددت Black Basta لاحقًا بالإفراج عن البيانات المخترقة ما لم يتم دفع ستة ملايين دولار لها – حوالي 41 مليون كرون دنماركي، وعندما لم يتم دفع الفدية، في نهاية نوفمبر/تشرين الثاني، قامت بلاك باستا بمشاركة نسخ من جوازات سفر 1300 شخص ورخص القيادة وشهادات التأمين الصحي عبر الإنترنت، بحسب موقع TV2.