article thumbnail

Booking.com Phishers May Leave You With Reservations

Krebs on Security

According to the market share website statista.com , booking.com is by far the Internet’s busiest travel service, with nearly 550 million visits in September. Booking.com did not respond to questions about that, and its current account security advice urges customers to enable 2FA.

Phishing 268
article thumbnail

Report: Healthcare haunted by account security

SC Magazine

. “One of the foundations of trust is that if you’re providing information to somebody like a health provider, that they’re keeping safe,” said David Gibson, Varonis’ chief marketing officer, a former engineer and CISSP. It is not really keeping up with that trust.”

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Weekly Update 369

Troy Hunt

All that said, I don't know how we build systems that are resilient to a single person coming along and entering someone else's (probably) reused credentials into a normal browser session, at least not without introducing additional barriers to entry that will upset the marketing manager. Protect your identity now.

article thumbnail

Sendgrid Under Siege from Hacked Accounts

Krebs on Security

Many companies use Sendgrid to communicate with their customers via email, or else pay marketing firms to do that on their behalf using Sendgrid’s systems. “Twilio believes that requiring 2FA for customer accounts is the right thing to do, and we’re working towards that end,” Pugh said. Image: Wikipedia.

article thumbnail

Fake Etsy invoice scam tricks sellers into sharing credit card information 

Malwarebytes

In this post, well walk you through exactly how this scam works, show you what to watch out for, and give you tips on keeping your Etsy account secure. This is an immediate red flag: Etsy never requires you to provide credit card information for identity verification outside of its standard, secure payment setup.

Scams 123
article thumbnail

Experian’s Credit Freeze Security is Still a Joke

Krebs on Security

Finally, your basic consumer (read: free) account at Experian does not give users the option to enable any sort of multi-factor authentication that might help stymie some of these PIN retrieval attacks on credit freezes. Thomas said he’s furious that Experian only provides added account security for consumers who pay for monthly plans.

article thumbnail

Robinhood data breach exposes 7 Million users’ information

Security Affairs

Robinhood disclosed a security breach, an unidentified threat actor gained unauthorized access to approximately 7 million customer records. Robinhood Markets , Inc. is an American commission-free stock trading and investing platform, it had 18 million accounts as of March 2021, with over $80 billion in assets.