Malaysia

We take data security seriously, constantly improving, says StoreHub after breach fear

Firm says it is working with independent cybersecurity agency to verify, prevent future vulnerabilities

Updated 4 years ago · Published on 17 Jun 2022 11:44AM

We take data security seriously, constantly improving, says StoreHub after breach fear
POS software service provider StoreHub in a statement says its internal team will continue to work closely with external experts in ensuring the full and thorough protection of its users’ data following a recent potential data breach. – @storehubpos Twitter pic, June 17, 2022

by Amar Shah Mohsen

KUALA LUMPUR – Point-of-sale (POS) software service provider StoreHub has moved to allay concerns among its users over a potential data breach, reassuring them that the security of their personal information remains a priority.

In a statement to The Vibes, the technology firm said it understood the severity of the recent user data vulnerability incident and the potential panic it may have caused.

It is now working with an independent cybersecurity agency to verify and prevent any other future vulnerability.

“We would like to reassure our users that we take the security of our users’ data very seriously and as such, we will continuously work to enhance our data security whilst addressing any and all possible related concerns.”

StoreHub added that its internal team will continue to work closely with external experts in ensuring the full and thorough protection of its users’ data.

Yesterday, The Vibes reported that the data of thousands of affected business premises and their staff, along with some one million of the customers, may have been potentially compromised in the latest of a series of major breaches in the country in recent years.

This is according to Safety Detectives, a publishing group of cybersecurity experts, privacy researchers, and technical product reviewers, who identified the potential data leak to StoreHub, a company headquartered in Petaling Jaya offering the POS software service mostly used in eateries and retail stores.

Based on the report by Safety Detectives, the supposed leak, which was first discovered on January 12, involved over 1.7 billion individual records and over one terabyte of data.

It noted that some of the customers’ personally identifiable information that may have been leaked include their full names, phone numbers, home addresses, and emails, as well as data related to the payments made, such as transaction dates and items ordered.

Separately, it said among the leaked details from the businesses include the employees’ names, their check-in and check-out times from work, the store’s name, address, and email.

According to Safety Detectives, the exposed data was stored on the software provider’s Amazon Web Service (AWS) Elasticsearch server that was neither encrypted nor password-protected.

StoreHub said it was made aware of the vulnerability on February 3 upon being notified by AWS and had swiftly patched and rectified the issue within 24 hours, ensuring that no sensitive or private data were maliciously downloaded by bad actors.

“The investigation also revealed that no sensitive financial data or passwords were contained in the vulnerability. As an extra precautionary measure, StoreHub ensured that no tokens within the dataset could be used to login into a merchant’s account,” it said. – The Vibes, June 17, 2022

Related News

Malaysia / 2y

Padu: No need for excessive information unrelated to one’s financial status, says Abang Jo

World / 3y

EU may fine TikTok millions for violating children’s privacy

World / 3y

European Commission to exclude Huawei, ZTE from 5G networks

Malaysia / 3y

Corporate sector must step up, invest in cybersecurity: Fahmi

Malaysia / 3y

Follow-up to ensure no more data leaks, Khaled tells UiTM

Malaysia / 3y

UiTM working on disabling link to data of potential students

Spotlight

Malaysia

'H1' hits RM10.7 million in H-series registration number bidding

Malaysia

Anwar’s China visit puts Malaysia’s technology, skills and connectivity plans in focus

Malaysia

Ten former Bar Council presidents affirm Tuanku Muhriz as rightful Yang di-Pertuan Besar of Negeri

Malaysia

Ismail Lasim’s continuous shifting stances leave Negeri administration in deeper bind

Malaysia

Loke’s resignation will be huge loss to the people, says Guan Eng

By Ian McIntyre

Malaysia

Attorney-General: Najib house arrest still pending RM50m fine payment

Malaysia

Rosmah Mansor: Overseas friends offer donations to help Najib pay RM50m fine

World

Thai woman found strangled in suitcase in Taiwan office freezer

You may be interested

Malaysia

Tiger suspected of killing Orang Asli man in Sungai Siput

Malaysia

Passenger faints, falls onto tracks at Wangsa Maju LRT station

Malaysia

Melaka assembly set to be dissolved today; state polls next?

By Alfian Z.M. Tahir

Malaysia

Rohingya man allegedly murders 18-year-old housemate on “instruction from God”

Malaysia

Anwar to write Nepal PM over formal mechanism for 55 missing Malaysians

Malaysia

Rosmah Mansor: Overseas friends offer donations to help Najib pay RM50m fine

Malaysia

Woman stabbed 13 times: Ex-technician charged with murdering wife in Kulim

Malaysia

Zahid says he and Negeri MB were not summoned to an audience with Tuanku Muhriz