Security

Samsung UK discloses year-long breach, leaked customer data

Chaebol already the subject of suits for a pair of past indiscretions


Updated The UK division of Samsung Electronics has allegedly alerted customers of a year-long data security breach – the third such incident the South Korean giant has experienced around the world in the past two years.

An email to customers, shared on social media by web security consultant and Have I Been Pwned creator Troy Hunt, detailed that the breach exposing data of customers who made purchases between July 1, 2019 and June 30, 2020 was discovered on November 13.

Samsung Electronics UK said an unauthorized individual exploited a vulnerability in a third-party business application used by the firm. Exposed information included names, phone numbers, plus physical and email addresses.

Samsung previously acknowledged a nearly 200GB breach by extortion gang Lapsus in March 2022 that included internal information such as Galaxy smartphone source code.

Only a few months passed before Samsung's US outpost reported another breach: a late July intrusion that targeted customer data. Samsung revealed that customers potentially had names, contact and demographic information, birth date and product registration information stolen, but not social security numbers.

After the July 2022 hack, Samsung gave assurances that it had taken action to secure affected systems and that it was working with authorities.

Despite such promises, the combination of the two cyber intrusions earned the chaebol a class action lawsuit in September 2022. The suit alleged Samsung unnecessarily collects personally identifiable information from its customers and subsequently fails to protect it.

The lawsuit asserts that customers were forced into handing over their data or else functions and features on TVs and printers would be disabled.

Samsung "was aware that the fraudsters and criminals who had access to the stolen source codes and authentication-related information (among other confidential data) could penetrate defendant's weak systems," argued the suit.

Updated to add at 1137 UTC

Samsung has been in touch to say: "We were recently alerted to a cybersecurity incident, which resulted in certain contact information of some Samsung UK e-store customers being unlawfully obtained.

"No financial data, such as bank or credit card details, or customer passwords, were impacted.

"We have taken all necessary steps to resolve this security issue, including reporting the incident to the Information Commissioner's Office and contacting affected customers."

Send us news
4 Comments

Samsung creates a group dedicated to inventing whatever comes next

Exec who led memory and battery businesses to global dominance gets the job of defining Chaebol's future

23andMe responds to breach with new suit-limiting user terms

Also: 'well-known Bay Area tech' firm's laptops stolen and check out some critical vulns

UK mulls next-gen satellite subsidies for Brit companies

Almost £100M in handouts available for LEO connectivity projects

2.5M patients infected with data loss in Norton Healthcare ransomware outbreak

AlphV lays claims to the intrusion

Yet another UK public sector data blab, this time info of pregnant women, cancer patients

NHS Trust admits highly sensitive data left online for nearly three years

BlackCat ransomware crims threaten to directly extort victim's customers

Accounting software firm Tipalti says it’s investigating alleged break-in of its systems

Government and the latest tech don't mix, says UK civil servant of £11B ESN mess

Public sector might want to 'wait a bit' before buying into bleeding edge, Sir Matthew Rycroft muses

Hershey phishes! Crooks snarf chocolate lovers' creds

Stealing Kit Kat maker's data?! Give me a break

EU lawmakers finalize cyber security rules that panicked open source devs

PLUS: Montana TikTok ban ruled unconstitutional; Dollar Tree employee data stolen; critical vulnerabilities

Regulator says stranger entered hospital, treated a patient, took a document ... then vanished

Scottish health group to tweak security checks, access authorization to avoid a repeat

Admin of $19M marketplace that sold social security numbers gets 8 years in jail

24 million Americans thought to have had their personal data stolen and sold for pennies

Okta data breach dilemma dwarfs earlier estimates

All customer support users told their info was accessed after analysis oversight