Are you a consumer of Acer’s products? Well, your favourite brand is maintaining its terrible cyber security strategies, a reason you should be worried.
In 2016, Acer admitted that hackers stole a staggering 34,000 customer credit cards after getting the best of the company’s system vulnerabilities. US and Canadian customers who bought Acer’s gadget before April 28, 2016, fell victims to the attack.
The following year, Acer paid $115k to the New York’s Attorney General’s office for leaving users confidential information unprotected.
Engadget reported that the attorney general’s office carried out investigation and found that Acer’s technical support team made some reckless security errors by leaving the company’s e-commerce platform in debugging mode from July 2015 until April 2016.
The setting stores all data transferred through the website in an encrypted, plain-text log file. Secondly, the team misconfigured the company website to allow directory browsing by any unauthorised user.
One gang group at the time, noticed and stole data between November 2015 and April 2016. It resulted to leaked legal names, usernames, passwords, geolocations, and credit card numbers with verification codes for at least 35,000 individuals in the US, Canada, and Puerto Rico. The good news? The hack didn’t include social security numbers. But such breach happening at reputable brand is a painful security snafu.
Four years down the line, Acer got hit by another attack by the bad boys. The Taiwanese computer giant was ordered to pay one of the heftiest ransoms to date.
Known as the REvil ransomware, the gang is demanding $50 million according to a report by tech blog Engadget. The cyberattack is a worrying phenomenon for users who auto-saved their passwords and credit card details, especially on PCs.
The ransom demand is one of the largest, if not the largest – ransomware demands to date. One can be assertive that this demand came precisely because Acer is a massive corporation that reported nearly $3 billion in earnings for the fourth quarter of 2020.
The attackers mined data from thousands of users, including passwords and credit card details. Worse of it all, they are threatening to publicize the data if the company fails to comply with their demand until March 28, 2021.
Last year, the same cyber gang group pounded on Travelex and demanded $6 million in ransom. The group said it breached Acer on a dark web portal earlier this week, posting some images for evidence. They offered a 20 per cent discount if Acer would pay by Wednesday last week, which they did not. They will certainly miss out on discount.
And that means they will have to pay $50 million upfront. Cyberattacks are not a thing to smile amount. However, the negligence of Acer’s technical support team is costing the company the company that much.
Acer is a big brand that spans from Taiwan, the U.S, Europe, and Africa. It has a colossal market in all those continents. However, dwindling confidence in security support negligence could not only badly affect Acer’s market base but also dent its reputation.
