Royal Mail, Samsung information stolen through unreliable supplier – GadgetLad

Royal Mail, Samsung information stolen through unreliable supplier – GadgetLad

Same Old Story: Data Breach Strikes Royal Mail & Samsung

Royal Mail, Samsung information stolen through unreliable supplier – GadgetLad

Alright, hold onto your hats. This one’s a whopper. Our friends at Royal Mail and Samsung (specifically in Germany) have found themselves neck-deep in a serious breach, all thanks to a dodgy third-party software provider in Germany. A group of cyber miscreants known as “GHNA” claims they’ve made off with a staggering 144GB of Royal Mail data and are now tossing it around on the dark web as if it were a yard sale for hackers.

Not the best headline, huh?

GHNA – Who Are These Characters?

GHNA may not be a name you recognize just yet, but they’re certainly carving out a reputation, mostly by wreaking havoc and hoping for attention, much like a tipsy person flashing in a crowded bar.

According to these misguided individuals, they’ve acquired the data through stolen credentials, most likely swiped using infostealer malware from one of Royal Mail’s suppliers, who appears to be the same group responsible for the Samsung Germany breach. We’re talking Excel spreadsheets, Word documents, emails – essentially everything you’d rather keep under wraps unless your security strategy involves a crayon-drawn padlock.

Supply Chain – The Weak Spot in Corporate Security

This isn’t the first instance of a third-party fool leaving the front door ajar for critical assets. The attack here seems to be a classic supply chain compromise. One supplier slacks off on their password management or lets “Dave from marketing” install suspicious “PDF readers” from the internet, and suddenly, BAM – GHNA’s having a field day rummaging through your data like it’s Black Friday.

Royal Mail hasn’t said much – just the typical “We’re investigating” bore-fest. Seriously guys, at least appear to make an effort to tighten up your defenses.

What Was Taken? Nearly Everything Except the Postie’s Footwear

GHNA shared a 1.4GB sample online to demonstrate they’ve got the goods. This data dump consists of:

– Tons of Microsoft Office files (classic)
– Email archives
– Internal documents and corporate communications
– Who knows what else is buried in that full 144GB – likely someone’s cringeworthy lunchbox review.

Now, I can guess what you’re thinking – “But GadgetLad, what are these hackers after?” Money, of course. Or chaos. Or simply the spotlight, akin to a child shaking a tambourine for attention. Either way, they’re hawking Royal Mail’s data like it’s counterfeit merchandise on Northumberland Street.

Samsung Germany – Also in Hot Water

Royal Mail, Samsung information stolen through unreliable supplier – GadgetLad

The same compromised credentials seem to have gained GHNA access to Samsung Germany’s systems as well. It’s unclear if they’ve nabbed anything juicy, but they claimed to have “full access” through the supplier’s portal. If that’s true, it’s a serious misstep. Honestly, it’s like handing your house key to a guy at the pub because he claims to be a ‘freelance plumber.’

Samsung hasn’t made much noise either – just mumblings about looking into the situation. I suppose if you’re accustomed to dealing with foldable screens, security might be a bit of an afterthought.

Why You Should Pay Attention – And Stop Using Password123

I get it. Supply chains can be chaotic. But if you’re managing a multi-billion-pound business, your partners probably shouldn’t be storing sensitive data accessible to Gareth from IT with a password like “welcome1.” It’s 2024. Let’s not act like MFA is some kind of sorcery.

For the rest of us – sure, this story might seem irrelevant. But if your package goes missing or your personal details are getting used to buy counterfeit Yeezys from Bulgaria, you’ll care rather quickly.

The Bottom Line: Big Names, Bigger Breaches

Royal Mail and Samsung getting digitally compromised isn’t shocking anymore – it’s pretty much anticipated. With infostealer malware being as easy to spread as Greggs pastries, everybody’s at risk, especially when vendors prioritize cutting corners over securing them.

GadgetLad advises: if you’re a business handling user data – or any data really – you better start treating your third-party IT partners like sketchy blokes with a white van. Because some of them certainly are.

Stamp it Out: Infostealer malware from German company may be to blame

Summary

“Postman’s Knock: When Cybercriminals Come Calling”

GHNA looted both Royal Mail and Samsung Germany through a supplier that couldn’t keep their own inbox secure, likely using malware that’s drifting around the web like confetti. Royal Mail’s tight-lipped, Samsung’s silent, and the dark web’s just received fresh stock. The lesson here? Vet your suppliers as you would your kebab shop after a night out – poor hygiene leads to disastrous outcomes.

For more rants, reviews, and tech insights – stay tuned at GadgetLad.co.uk.