Flow
Flow
Flow
TriniTuner.com  |  Latest Event:  

Forums

Hackers claim Courts, PriceSmart cybersecurity breached

this is how we do it.......

Moderator: 3ne2nr Mods

User avatar
shaneelal
Riding on 16's
Posts: 1236
Joined: February 10th, 2007, 10:25 pm

Re: Customers claim to be getting extra charges from PriceSmart

Postby shaneelal » November 12th, 2023, 11:51 am

Pricesmart.com hacked.

Might need it's own thread, not sure exactly what info the hackers got.
Be cautious if you had credit card info stored on Pricesmart.com
Attachments
Pricesmart_hack.png
Last edited by shaneelal on November 12th, 2023, 1:06 pm, edited 2 times in total.

User avatar
The_Honourable
TriniTuner 24-7
Posts: 10516
Joined: June 14th, 2009, 3:45 pm
Location: Together We Conspire, Together We Deceive

Re: Customers claim to be getting extra charges from PriceSmart

Postby The_Honourable » November 12th, 2023, 11:56 am

Sheeeet... courts get hack too...

Customer data from 200,000 orders stolen

https://twitter.com/HackingGavin/status ... 6193403328

User avatar
maj. tom
TriniTuner 24-7
Posts: 11305
Joined: March 16th, 2012, 10:47 am
Location: ᑐᑌᑎᕮ

Re: Customers claim to be getting extra charges from PriceSmart

Postby maj. tom » November 12th, 2023, 12:04 pm

Seems like developing countries are a field day for hackers. Want to play high tech but not really.

triniterribletim
Trinituner Peong
Posts: 481
Joined: February 17th, 2020, 3:23 pm

Re: Customers claim to be getting extra charges from PriceSmart

Postby triniterribletim » November 12th, 2023, 12:08 pm

Looks like fallout from the TSTT debacle. I wonder who else relied on TSTT for backend infrastructure?

User avatar
aaron17
Trying to catch PATCH AND VEGA
Posts: 6165
Joined: June 13th, 2006, 7:54 pm

Re: Customers claim to be getting extra charges from PriceSmart

Postby aaron17 » November 12th, 2023, 12:15 pm

Well yes

Kenjo
punchin NOS
Posts: 3585
Joined: March 19th, 2009, 10:31 pm
Location: Home

Re: Customers claim to be getting extra charges from PriceSmart

Postby Kenjo » November 12th, 2023, 12:43 pm

maj. tom wrote:Seems like developing countries are a field day for hackers. Want to play high tech but not really.

lol all over the world .

User avatar
paid_influencer
TriniTuner 24-7
Posts: 9057
Joined: November 18th, 2017, 4:15 pm

Re: Customers claim to be getting extra charges from PriceSmart

Postby paid_influencer » November 12th, 2023, 12:49 pm

shaneelal wrote:Pricesmart.com hacked.

Might need it's own thread, not sure exactly what info the hackers got.
Be cautions if you had credit card info stored on Pricesmart.com


yea put this in its own thread

looks like every islander's dp/id/date of birth going to be out in the open now

pugboy
TunerGod
Posts: 29391
Joined: September 6th, 2003, 6:18 pm

Re: Customers claim to be getting extra charges from PriceSmart

Postby pugboy » November 12th, 2023, 3:13 pm

tstt executives are pleased

redmanjp
TriniTuner 24-7
Posts: 17685
Joined: September 22nd, 2009, 11:01 pm
Contact:

Cyberattacks in T&T - TTpost hacked

Postby redmanjp » November 14th, 2023, 6:43 pm

Last edited by redmanjp on November 16th, 2023, 4:28 pm, edited 1 time in total.

AlphaMan
3NE2NR is my LIFE
Posts: 794
Joined: June 1st, 2021, 5:53 pm

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby AlphaMan » November 14th, 2023, 6:53 pm

Someone going home for this...Lisa Agard resigned today.. :drinking:

redmanjp
TriniTuner 24-7
Posts: 17685
Joined: September 22nd, 2009, 11:01 pm
Contact:

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby redmanjp » November 16th, 2023, 4:27 pm

wtf TTPost was hacked months ago

TTPost hacked, minister urges vigilance

https://newsday.co.tt/2023/11/15/ttpost-hacked-minister-urges-vigilance/

User avatar
st7
3ne2nr Toppa Toppa
Posts: 5346
Joined: October 23rd, 2006, 1:13 am

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby st7 » November 16th, 2023, 4:34 pm

waiting to hear about trinituner.com

User avatar
maj. tom
TriniTuner 24-7
Posts: 11305
Joined: March 16th, 2012, 10:47 am
Location: ᑐᑌᑎᕮ

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby maj. tom » November 16th, 2023, 6:02 pm

Well is only a matter of time given the trends of 2023. Could be a local hacker who just want to play because I not sure what user data Trinituner can offer in terms of selling it off to scammers, but they could probably take the website offline for a while. Trinituner running on Apache/2.2.15 which is very outdated and has serious security flaws.
Powered by: PHP 5.6.40 [outdated]
No cloud based firewall protection.

https://sitecheck.sucuri.net/results/trinituner.com

https://httpd.apache.org/security/vulnerabilities_22.html
Apache httpd 2.2 is End-of-Life since December 2017 and should not be used. This page only lists security issues that occurred before the End-of-Life. Subsequent issues may have affected 2.2 but will not be investigated or listed here. Users are advised to upgrade to the currently supported released version to address known issues.


I guess if/when it happens, the web admins could have fixed this before it happened. End-users should be using their own OS/browser security features for protection. One of the security flaws listed is potential ClickJacking.

User avatar
fokhan_96
Riding on 18's
Posts: 1828
Joined: July 12th, 2011, 3:23 pm
Location: Pain is weakness leaving the body

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby fokhan_96 » November 17th, 2023, 8:58 am

st7 wrote:waiting to hear about trinituner.com
The identity of "Duane 3NE 2NR" shall finally be revealed...

User avatar
aaron17
Trying to catch PATCH AND VEGA
Posts: 6165
Joined: June 13th, 2006, 7:54 pm

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby aaron17 » November 17th, 2023, 9:29 am

Can someone hack odpm so that rowley can resign? Lol

User avatar
gastly369
TriniTuner 24-7
Posts: 10467
Joined: May 15th, 2009, 4:40 pm
Location: trinidad

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby gastly369 » November 17th, 2023, 9:36 am

aaron17 wrote:Can someone hack odpm so that rowley can resign? Lol
For the right price anything can be done

User avatar
Dohplaydat
3ne2nr Toppa Toppa
Posts: 5150
Joined: December 17th, 2019, 8:31 pm

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby Dohplaydat » November 17th, 2023, 3:32 pm

aaron17 wrote:Can someone hack odpm so that rowley can resign? Lol


Yea just bitcoin some north Korean hackers and files buss

User avatar
stev
TriniTuner 24-7
Posts: 7903
Joined: May 26th, 2010, 11:29 am
Location: Central

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby stev » November 24th, 2023, 1:18 am

Anybody find blue waters data as yet?

factory worker said he scratching balls for 2 weeks now and counting. Laptops taken away for a few days then returned...no internet access on work etc.

pugboy
TunerGod
Posts: 29391
Joined: September 6th, 2003, 6:18 pm

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby pugboy » November 24th, 2023, 5:18 am

has anyone gotten back the shortchange from pricesmart ?

I just check my october statement and those double transactions are showing up,
what is strange is the october statement showing those transactions from august.

I certainly didnt have them on my september statement when the issue arose in october

User avatar
The_Honourable
TriniTuner 24-7
Posts: 10516
Joined: June 14th, 2009, 3:45 pm
Location: Together We Conspire, Together We Deceive

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby The_Honourable » December 10th, 2023, 12:43 am

kkkkk... blue waters got hacked...

User avatar
shaneelal
Riding on 16's
Posts: 1236
Joined: February 10th, 2007, 10:25 pm

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby shaneelal » December 10th, 2023, 6:22 pm

The_Honourable wrote:kkkkk... blue waters got hacked...




Blue Waters hit by cyber attack
https://newsday.co.tt/2023/12/10/blue-w ... ber-attack

Blue Waters Products Ltd is the latest local entity to fall victim to a cyber attack with over 10 gigabytes of company information released on the dark web including passport and clients' credit card information.

Company CEO Dominic Hadeed told Newsday assessments were still ongoing and said an update would be provided on Monday afternoon.

Done by the LockBit3 group, Enterprise Risk Consultant, senior cybersecurity lecturer and forensic investigator Shiva Parasram described the attacker as the current "deadliest and most aggressive group in the world" which typically targets large companies. This is why, he said, the company may be in trouble.


"They have incredible skills set inside of there. So once they get inside of there, inside Blue Waters, they would have mapped out every single piece of technology service, third party provider, every single thing," he said. "They would have essentially done a full audit on the Blue Waters network."

Viewing the leaked data on the dark web, Parasram said it appears as though all of the company's data was posted. However, he noted he did not do a deep dive into the information because it is a private sector company and he did not want to intrude or run afoul of the law.

"They (LockBit3) have 10 links on their website...and each one of those links has different information. So there's one called, I think, Bank.zip, HR.zip, confidential.zip, salaries.zip, insurance.zip. There's even one called passports.zip and visas.zip. So I'm assuming they have very very confidential data inside of there."

He said the hacker group uses aggressive tactics and does not "skimp" on their approaches. He said these groups are also known for leaving backdoors open to companies they breached to allow for repeated attacks.

"Blue Waters is in a very tough place and they will literally have to do everything from scratch," he said.

He said the company's deadline to pay the group's ransom was on December 9, before the information was released. Parasram said the group usually demands ransoms ranging from US $80,000 to US $1 million.

Over the last year, numerous local entities fell victim to cyber attacks like the office of the Attorney General, Courts and TSTT.

User avatar
stev
TriniTuner 24-7
Posts: 7903
Joined: May 26th, 2010, 11:29 am
Location: Central

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby stev » December 11th, 2023, 1:09 am

Why is it looking like Movietowne fell victim?

Their website normal for anyone else or is it just me?

Chimera
TunerGod
Posts: 20049
Joined: October 11th, 2009, 4:06 pm

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby Chimera » December 11th, 2023, 6:36 am

Hadda stop using credit card on any of these websites yes wtf.

Hope they don't hit websource

User avatar
aaron17
Trying to catch PATCH AND VEGA
Posts: 6165
Joined: June 13th, 2006, 7:54 pm

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby aaron17 » December 11th, 2023, 5:46 pm

Did they ever hack nlcb ?

Sent from my SM-G610M using TriniTuner mobile app

User avatar
supercharged turbo
punchin NOS
Posts: 3677
Joined: January 19th, 2011, 6:53 pm
Location: turn around

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby supercharged turbo » December 11th, 2023, 7:59 pm

I wonder if Carib ever get hack

redmanjp
TriniTuner 24-7
Posts: 17685
Joined: September 22nd, 2009, 11:01 pm
Contact:

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby redmanjp » December 17th, 2023, 9:20 am

Chimera wrote:Hadda stop using credit card on any of these websites yes wtf.

Hope they don't hit websource


I hope so too. Some years ago when I forgot my password websource emailed it to me instead of a password reset link. If they can send the actual password then it's NOT encrypted!

Hope they changed this because hackers would be getting all the passwords in plain text, along with other info they didn't encrypt.

User avatar
paid_influencer
TriniTuner 24-7
Posts: 9057
Joined: November 18th, 2017, 4:15 pm

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby paid_influencer » December 17th, 2023, 12:35 pm

redmanjp wrote:
Chimera wrote:Hadda stop using credit card on any of these websites yes wtf.

Hope they don't hit websource


I hope so too. Some years ago when I forgot my password websource emailed it to me instead of a password reset link. If they can send the actual password then it's NOT encrypted!

Hope they changed this because hackers would be getting all the passwords in plain text, along with other info they didn't encrypt.


:shock:

User avatar
shaneelal
Riding on 16's
Posts: 1236
Joined: February 10th, 2007, 10:25 pm

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby shaneelal » December 21st, 2023, 6:06 am

PriceSmart hacked again
Ransomware group gives company ultimatum


Ransomware group AlphV/Black Cat says it has hacked and stolen 500 gigabytes (GB) of data from the system of warehouse shopping giant PriceSmart.

The company has been listed as a victim on AlphV/Black Cat’s dark web blog again.

It was first listed on November 12.

Enterprise risk and security consultant Shiva Parasram confirmed yesterday that AlphV/Black Cat stated on its dark web blog that it plans to start attacking “pretty much everyone and everything” after it was seized by international law enforcement on Tuesday between 7 a.m. and 9 a.m.

The group said it took back control of its blog around noon that day.

“The group has put out a release stating that they are very upset with law enforcement–FBI and law enforcement agencies–and that they are just going to start attacking ‘pretty much everyone and everything’,” Parasram told the Express yesterday.

He said the group has also given the company 48 hours to contact them.

He said the amount of data was not listed when the site was taken back by the group.

“Under PriceSmart’s listing, they said it has 48 hours to contact them and usually that’s an indication that they need to either demand and get their payment within 48 hours or they want to start negotiations to see how much PriceSmart will pay. AlphV/Black Cat is known for asking for as much as US$8 million and more sometimes in ransom demands which is why they go after such large companies.”

He speculated that since AlphV/Black Cat has not announced what they have, certain details like the history and pictures of customers’ PriceSmart cards could be among the information.

“(Many) people have PriceSmart cards, so a history of possibly the card, a picture of the card, its details like your address and phone number can be released. (AlphV/Black Cat) could possibly have banking information, I can’t say, but the personally identifiable information (PII), it could have that.”

He added that people’s purchases and times of purchases could also be released which he said people may not be interested in unless it is their banking information.

But hackers can do a lot with PII, he said during a phone interview.

“The thing is hackers and other groups could use the information to target individuals because what we’ve realised is that ransomware groups, even AlphV/Black Cat, have actually promised to target individuals inside corporations, not just corporations.”

He said he was not sure if this will continue or not, but he was “very concerned”.

“I am also a PriceSmart cardholder, so I am thinking at least my name, address, phone number, purchases, purchase history, the amount and details of PriceSmart’s system and its network can be released,” Parasram said.

He added, “It could be damaging for a bit, it all depends on how Trinidadians decide to take it, I feel like a Trinidadian might say ‘Well, my information is out there, once they didn’t touch my bank account’. But the implications stem from photo IDs being out there since people can use them for all types of fraud, in terms of opening and closing accounts, and verifying authenticity online. Hackers can do amazing things these days with a little bit of information from social engineering to phishing to hacking.”

Asked about safety precautions that can be taken by PriceSmart, he suggested, “They have a lot of work to do in terms of increasing security and maybe doing penetration tests and vulnerability assessments more often. It previously might have been once a year, but for some companies I do these tests maybe two times a month now. Staff training, staff awareness, deploying things end-point detection and response systems, reviewing firewall logs, making sure firewall policies are updated, and doing internal and external threat management could be done.”

But he noted that he was not aware of what systems PriceSmart already has in place.

He added, “Honestly, sometimes, no matter what you have in place, these groups have some of the most intelligent IT professionals in the world and they have business analysts there as well...” He said it is “very worrying” that the group said it was previously able to steal 500 GB of data.

“The amount of information that came out of the Telecommunications Services of T&T was only six GB, this is 500 GB of information, so for that amount of information to have been allegedly leaked without their notice, it is very worrying about what systems they have in place,” Parasram said.

The Express contacted PriceSmart for comment via e-mail but there was no immediate response yesterday.

November attack

On November 13, the day after it was first listed as a victim of AlphV, PriceSmart said it had launched an “ongoing investigation process” with the support of third-party experts.

It stated, “PriceSmart is investigating a cybersecurity incident that affected some of the internal systems, and it has initiated an investigation process with the support of leading third-party experts. The company is aware a malicious actor has claimed to have taken data from our systems and has been working with leading cybersecurity experts to aggressively gather facts while working to ensure members’ information remains protected.”

It added, “At this time, we have no reason to believe that any personal information has been compromised. However, if the investigation concludes that this incident has impacted sensitive information, PriceSmart will contact affected organisations and individuals as appropriate.”

https://trinidadexpress.com/news/local/ ... 070ca.html

User avatar
aaron17
Trying to catch PATCH AND VEGA
Posts: 6165
Joined: June 13th, 2006, 7:54 pm

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby aaron17 » December 22nd, 2023, 7:53 pm


User avatar
The_Honourable
TriniTuner 24-7
Posts: 10516
Joined: June 14th, 2009, 3:45 pm
Location: Together We Conspire, Together We Deceive

Re: Hackers claim Courts, PriceSmart cybersecurity breached

Postby The_Honourable » December 27th, 2023, 12:47 am

Damn... NIB suffered a ransomware attack on boxing day
Attachments
NIB Release.jpg

Advertisement

Return to “Ole talk and more Ole talk”

Who is online

Users browsing this forum: Google [Bot] and 54 guests