Click here to return to the home page.
Image of a road.
Who's Online Now
6 registered members (James B W, nick w, vincentvg, John V6, CLPlusFour, BobtheTrain), 347 guests, and 12 spiders.
Key: Admin, Global Mod, Mod
Top Posters(30 Days)
+8Rich 121
John V6 106
OZ 4/4 104
Newest Members
IndianaJon, Colin916, HerrVorragend, Alan1973, Lost Treasure
8359 Registered Users
Newest Topics
EV article from Rowan Atkinson
by +8Rich. 03/06/23 09:17 PM
Some advice please…ter
by Woodywoo. 03/06/23 09:01 PM
Today at Kemble/Cotswold airfield
by Graham, G4FUJ. 03/06/23 05:05 PM
For Sale - 2016 Morgan Three Wheeler
by KenShapiro. 03/06/23 02:25 PM
Treacle
by BobtheTrain. 03/06/23 01:04 PM
Isle of Man practise time.
by +8Rich. 02/06/23 08:54 PM
Grease gun
by William s. 02/06/23 04:27 PM
Latest Photos
Spotted In Amboise Loire
Wiscombe Park
Morgan Challenge Thruxton 7th May 2023
MTWC Meet at Woolpit Suffolk yesterday
Sod the rain
Forum Statistics
Forums32
Topics45,151
Posts764,716
Members8,359
Most Online1,033
Dec 28th, 2019
Today's Birthdays
No Birthdays
Previous Thread
Next Thread
Print Thread
Page 1 of 3 1 2 3
Ouch - Who has been cyber hacked. #772307
22/03/23 10:52 PM
22/03/23 10:52 PM
Joined: Mar 2009
Posts: 10,280
Hampshire
Alistair Offline OP
Smile, it confuses them
Alistair  Offline OP
Smile, it confuses them
Member of the Inner Circle

Joined: Mar 2009
Posts: 10,280
Hampshire
A friend who owns a red car just received this email.
Fair enough, they have owned up and are dealing with it. More than many companies have done.

Howard - change your password!


From: Ferrari.com <ferrari@mail.ferrari.com>
Sent: Monday, March 20, 2023 10:17 PM
To: redcardriver@mailtool.moc
Subject: Client Communication

We regret to inform you of a cyber incident at Ferrari, where a threat actor was able to access a limited number of systems in our IT environment. As part of this incident, certain data relating to our clients was exposed including names, addresses, email addresses and telephone numbers. Your data may have been included as part of this incident. However, based on our investigation, no payment details and/or bank account numbers and/or other sensitive payment information, nor details of Ferrari cars owned or ordered have been stolen.

CLIENT COMMUNICATION

Dear Ferrarista,

We regret to inform you of a cyber incident at Ferrari, where a threat actor was able to access a limited number of systems in our IT environment. As part of this incident, certain data relating to our clients was exposed including names, addresses, email addresses and telephone numbers. Your data may have been included as part of this incident. However, based on our investigation, no payment details and/or bank account numbers and/or other sensitive payment information, nor details of Ferrari cars owned or ordered have been stolen.

We were recently contacted by a threat actor with a ransom demand related to such customer data. As a policy, Ferrari will not be held to ransom as paying such demands continues to fund criminal activity and enables threat actors to perpetuate their attacks. Moreover, it does not fundamentally change the data exposure.

Upon receipt of the ransom demand, we started an investigation in collaboration with a leading global third-party forensics firm and have confirmed the data’s authenticity. In addition, we informed the relevant authorities and are confident they will investigate to the full extent of the law.

We have worked with third party experts to further reinforce our systems and are confident in their resilience. We can also confirm the breach has had no impact on the operational functions of our company.

We take the confidentiality of our clients seriously and understand the significance of this incident and for this reason we have notified you promptly.

If you would like to contact Ferrari for additional information, please email us at customerservice@owners.ferrari.com or privacy@ferrari.com where a team will be able to assist you.

We would like to take this opportunity to apologise sincerely for this event and rest assured we will do everything in our power to regain your trust.

Yours sincerely,

Benedetto Vigna
Chief Executive Officer
Ferrari S.p.A.


Everyone loves a Morgan. Even me, unless it's broken again.
Re: Ouch - Who has been cyber hacked. [Re: Alistair] #772309
22/03/23 11:06 PM
22/03/23 11:06 PM
Joined: Mar 2009
Posts: 3,295
N
nick w Online content
Talk Morgan Addict
nick w  Online Content
Talk Morgan Addict
N

Joined: Mar 2009
Posts: 3,295
Rather good that they have grasped the nettle. I'd be impressed if I was an owner.

Re: Ouch - Who has been cyber hacked. [Re: Alistair] #772311
23/03/23 06:27 AM
23/03/23 06:27 AM
Joined: Nov 2018
Posts: 5,126
Northants, UK
TBM Offline
Charter Member
TBM  Offline
Charter Member

Joined: Nov 2018
Posts: 5,126
Northants, UK
Happened to the company (a very large German trade supplier) my Mrs works for - although it wasn't just a data breach, they hacked in and immobilised every single system.They lost all the company records, stock details,SAP, website, internet, all the staff information, payroll, all the IT systems, even the phones went down.

Everything (inlcuding my details as a 'next of kin') is now up for sale on the darkweb.

They also refused to pay the ransom, and over the last month or so have been slowly rebuilding everything. At the start, there were only two mobile phones working across the entire global operation (one was my other halfs as she had performed the daily update schedule earlier than she should have, so missed the hack). One of the last things still to be fixed is the automated pick and pack operation, which is causing massive headaches for company and customers.

Lessons have been learnt and everything is being rebuilt to protect against something similar happening but just shows the power these hackers have in this automated world.

And if your having any building work done and it's being delayed, you now know why!


1972 4/4 4 seater - 3G Morganeer
1981 MGB GT
Too many ratty motorbikes
Re: Ouch - Who has been cyber hacked. [Re: Alistair] #772328
23/03/23 10:33 AM
23/03/23 10:33 AM
Joined: Aug 2013
Posts: 15,544
Salisbury, UK
Peter J Offline
Formerly known as Aldermog
Peter J  Offline
Formerly known as Aldermog
Member of the Inner Circle

Joined: Aug 2013
Posts: 15,544
Salisbury, UK
Clearly trying to find out why the Ferrari F1 team is so slow....


Peter,
66, 2016 Porsche Boxster S
No longer driving Tarka, the 2014 Plus 8...

Re: Ouch - Who has been cyber hacked. [Re: Alistair] #772382
23/03/23 03:59 PM
23/03/23 03:59 PM
Joined: Mar 2009
Posts: 10,280
Hampshire
Alistair Offline OP
Smile, it confuses them
Alistair  Offline OP
Smile, it confuses them
Member of the Inner Circle

Joined: Mar 2009
Posts: 10,280
Hampshire
That's the exact game TBM, ransomware. Get a payload into the target customer (spearfishing) and let it settle, then spread far and wide around the systems. Then extract as much data as you can for later fun. Turn on the encryption and lock up the data on everything you can find. If they pay up then you (may) send the decryption key and let them take it back.

One of the vendors we play with (Sentinel One) has some cool roll-back tools that massively reduces this approach as well as including insurance in the offer so that should it happen (and you were correctly deployed etc etc) there is policy to help you recover. It is a more up to date approach to this scourge.

We have been looking at products that watch for these little tic's hiding inside your systems and the market is expanding rapidly. One monitors for software trying to reach out to known nasty addresses and go across the other computers within the site which is a classic action. Sadly it does not point at it and hit it with a 200lb hammer. As many tools as are installed it is the device behind the MkI eyeball in the monitoring room which is often asleep at the wheel as well.


Everyone loves a Morgan. Even me, unless it's broken again.
Re: Ouch - Who has been cyber hacked. [Re: Alistair] #772505
24/03/23 05:06 PM
24/03/23 05:06 PM
Joined: Jan 2009
Posts: 5,645
H
howard Offline
Charter Member
howard  Offline
Charter Member
H

Joined: Jan 2009
Posts: 5,645
Originally Posted by Alistair
A friend who owns a red car just received this email.
Fair enough, they have owned up and are dealing with it. More than many companies have done.

Howard - change your password!



As luck would have it, the password used for Ferrari is unique to them so no need to change.

Re: Ouch - Who has been cyber hacked. [Re: howard] #772507
24/03/23 05:54 PM
24/03/23 05:54 PM
Joined: Dec 2009
Posts: 32,446
Devonshire
+8Rich Offline
Tricky Dicky
+8Rich  Offline
Tricky Dicky
Member of the Inner Circle

Joined: Dec 2009
Posts: 32,446
Devonshire
Originally Posted by howard
Originally Posted by Alistair
A friend who owns a red car just received this email.
Fair enough, they have owned up and are dealing with it. More than many companies have done.

Howard - change your password!



As luck would have it, the password used for Ferrari is unique to them so no need to change.

Howard you have extraordinary faith in the Mafiosa to do the right thing grin2


Regards Richard

1999 Indigo Blue +8
2009 4/4 Sport Green prev
1993 Connaught Green +8 prev





Re: Ouch - Who has been cyber hacked. [Re: Alistair] #772517
24/03/23 06:43 PM
24/03/23 06:43 PM
Joined: Nov 2015
Posts: 6,032
People's Republic of South Yor...
CooperMan Offline
Just barreling along
CooperMan  Offline
Just barreling along
Talk Morgan Sage

Joined: Nov 2015
Posts: 6,032
People's Republic of South Yor...
Because I was suspicious my password was compromised several times the other week, the poor cat's had his name changed three times blush


Jon M
Re: Ouch - Who has been cyber hacked. [Re: CooperMan] #772518
24/03/23 06:52 PM
24/03/23 06:52 PM
Joined: Dec 2009
Posts: 32,446
Devonshire
+8Rich Offline
Tricky Dicky
+8Rich  Offline
Tricky Dicky
Member of the Inner Circle

Joined: Dec 2009
Posts: 32,446
Devonshire
So no longer Cookin Fat then Jon grin2


Regards Richard

1999 Indigo Blue +8
2009 4/4 Sport Green prev
1993 Connaught Green +8 prev





Re: Ouch - Who has been cyber hacked. [Re: Alistair] #772527
24/03/23 07:21 PM
24/03/23 07:21 PM
Joined: Jan 2010
Posts: 1,540
Lampeter, Wales
Jon G4LJW Offline
Talk Morgan Enthusiast
Jon G4LJW  Offline
Talk Morgan Enthusiast

Joined: Jan 2010
Posts: 1,540
Lampeter, Wales
These days I often use the Apple iCloud "Hide My Email" system. This gives you a random email address for any new site you want to create an account for. I guess it's fine until iCloud gets hacked! grin2

Page 1 of 3 1 2 3

Moderated by  TalkMorgan 

Powered by UBB.threads™ PHP Forum Software 7.7.1