Cancer Research UK targeted by Russian hackers
Cancer Research UK has been targeted by Russian hackers, according to reports appearing in national newspapers this weekend.
RiskIQ, a cybersecurity consultancy, said the group “tried to steal the card details of people in the UK who had brought items through the cancer charity’s online gift shop”.
According to the Daily Telegraph: “Cancer Research UK runs an online shop where customers can buy items including skin treatment lotions and bandanas for chemotherapy patients.
“The hackers planted malicious code into Cancer Research UK’s website, which was designed to siphon off the credit card information of people who made purchases through the site.”
A spokeswoman for the charity confirmed that CRUK shops had been hacked in June 2016, but said no credit card information had been stolen.
She also provided a statement from Nigel Armitt, chief financial officer at CRUK, which said: “We advised customers who might have been affected to contact their bank as a preventative measure, so they could be advised if any additional action needed to be taken.
“The online store services were immediately disabled to ensure the exposure was limited and a subsequent investigation conducted by a third-party firm confirmed that there were no supporters impacted by the event.
“The investigation of this incident and its containment was our highest priority.
“Our life-saving work is only possible thanks to public support. We take online data protection and cyber security extremely seriously.
“We reported the incident to the Information Commissioner’s Office, who were fully apprised of the situation and took no further action.”
CRUK was one of a number of UK-based companies and organisations targeted by the same group, which included British Airways and Ticketmaster.
The ICO has been contacted for a comment.
Source civilsociety
Industry: Cyber Security News
Latest Jobs
-
- PCI QSA needed. Discreet Opportunity | London | Client facing
- London
- N/A
-
CH08421 PCI QSA needed. Discreet Opportunity | London | Client facing. Payment Card Industry - Qualified Security Assessor - London Seeking someone looking to accelerate their career, into a variety of interesting clients / projects. Must be happy to be onsite with clients- this is not a fully remote role. You must currently hold a valid CISSP or CISM or ISO27001 lead implementer certification AND one of the following; CISA, GSNA, iso27001 lead Auditor, CIA or IRCA ISMS auditor+ Visa sponsorship not available. Apply today for more information chris.holt@dclsearch.com Use this whatapp link to reach out https://wa.me/message/6USF5RAQBOZIP1
-
- Network / Security Infrastructure Engineer | West London | Permanent
- London
- N/A
-
Network / Security Infrastructure Engineer | West London | Current Config, Install, upgrade experience On prem / Datacetner experience essential. Hands on experience MUST include: Routing, Switching, Network Security (firewall, IDS etc), Microsoft exchange / Exchange 365. Scripting / automation experience wanted. Python, Powershell etc Regular travel to West London is required. Visa sponsorship not available. Apply today for more information chris.holt@dclsearch.com Use this whatapp link to reach out https://wa.me/message/6USF5RAQBOZIP1
-
- Security Operations / information Security Analyst / Engineer. London
- London
- N/A
-
Security Operations / information Security Analyst / Engineer needed for a London opportunity. A technical hands on role to investigate, escalate and proactively work to protect a globally recognised brand. Someone with SOC Analyst / security engineering background would be well suited. This position will join a small team and would suit someone that has broad experience across the security threat landscape. Experience / knowledge across industry GRC standards such NIST, ISO27001 etc very advantageous and a priority. You will work across multiple teams proactively working to secure the business. Must be able to commute to Central London 3 days a week. Visa sponsorship not available Apply today to find out more.
-
- Security Cleared Penetration Tester: United Kindom
- N/A
- N/A
-
Security Cleared Penetration Tester Deliver technical Penetration tests to the NCSC CHECK standard. Active CHECK Member or Leader status desirable either in Web Application or Infrastructure. Reach out to find out more. Whatsapp directly here https://wa.me/message/6USF5RAQBOZIP1 Or apply today