This UK pub chain left 17,000 customer details exposed online
The personal details of thousands of beer drinkers were left exposed thanks to a Wi-Fi provider proving leakier than a smashed pint glass.
Brewhouse & Kitchen is a small chain of pubs with 23 locations across the UK. These include locations in London, Nottingham, Chester, Cardiff and Bristol.
Patrons attempting to access its free Wi-Fi were asked to hand over their names, emails, date of birth, phone numbers and other personal details. Oliver Hough, an independent security researcher, stumbled across a spreadsheet file containing more than 17,000 such records on an open directory hosted by Brewhouse's Wi-Fi provider, Focus Group.
"Looking for potential data breaches is somewhat of a hobby, at the time I was looking for open directories," he says. Finding the open directory was "pretty easy as the server was indexed on the Shodan search engine." Shodan is a search engine for internet connected devices, handy for researchers looking for anything that shouldn't be online.
The Brewhouse database included which pub the users logged into and when — and whether the customer wanted to be added to marketing lists (the majority of people said). "Phone numbers, email addresses could be used in scams or phishing campaigns," Hough says. "The other details such as date of birth, device type etc can be used to add legitimacy to a scam."
There's nothing to suggest scammers or hackers have downloaded the data. It was merely left exposed online for anyone with the technical know how to access.
Hough contacted Brewhouse on November 9; five days later, the directory was removed from open access. Both companies said they've contacted the Information Commissioner's Office (ICO) to report the incident.
"Focus Group were made aware of a possible breach of Brewhouse & Kitchen's data on November 14 2018. We have subsequently followed our GDPR policy and are in the process of notifying the ICO," Focus Group's director Vicki Rishbeth said in an emailed statement.
Brewhouse & Kitchen said in a statement that it had worked with Focus Group to identify the source of the breach and stopped the leak. "We consider the management of our customers’ personal data to be the utmost priority, the incident in question has prompted a stringent review of the systems and infrastructure in place across all of our sites by our contracted service provider, ensuring a repeat or similar situation cannot arise again," the statement added.
Industry: Cyber Security News
- CONTRACT SIEM Cyber Security Operations Engineer. REMOTE
- United Kingdom
REFCH8165 CONTRACT SIEM Cyber Security Operations Engineer. REMOTE UK SIEM Engineer. 6 month Contract. Inside IR35 Working towards a "SOC 2" environment. CLOUD (AWS) experience essential. Three key functions; Monitor, Escalate and Triage incidents. Vulnerability Management / threat intel. SIEM configuration / management, review, enhancement More specifically; Work with internal teams to identify assets. Identity applicable threat feeds and work with internal teams to remediate. Patch Patch Patch. (Help mature process / identify gaps) Configuration / fine tuning of SIEM alerts. Create dashboards, Compliance reporting. Log ingestion. Experience across ISO27001 / SOC2 / SIEM / End Point Security is essential Contact me today for more information Chris.Holt@dclsearch.com Or 07884666351
- Cyber Security Operations Engineer. REMOTE UK. SOC2
- United Kingdom
REF8164 Cyber Security Operations Engineer. REMOTE UK Internal opportunity. New position. Exclusive to DCL Search. You will be the hands on technical eyes and ears of the Cyber security capability actively working to ensure and enhance the adherence to ISO27001 and "SOC 2" controls. You role will touch on the following · Security Monitoring- SIEM · Vulnerability Management / Testing · Incident Management · Asset management · Disaster Recovery planning · Change Management AWS Cloud experience is essential as is the ability to ensure patch management is prioritised across the business. Any CLOUD SIEM experience highly desirable. Contact me today for more information Chris.Holt@dclsearch.com Or 07884666351
- Lead Security Architect
- United Kingdom
Engage with key clients in an Architectural / technical presales capacity. Including Stakeholders, end users / partners. Working on new and existing Security projects to confirm that proposed solutions are fit for purpose from both a technical and regulatory capacity. Working closely with multiple vendor . Managed security service background ideal CLOUD Security (AZURE OR AWS), IDAM background ideal.
- Threat Vulnerability Management Analyst
- United Kingdom
To monitor, identify and alert internal teams of cyber threats and vulnerabilities. MIRE Att&ck, CIS, OWASP, Vulnerability management tools MUST be able to commute to central London MUST be able to achieve UK SC Clearance. On going support and development.