Article Details
Scrape Timestamp (UTC): 2024-09-20 18:36:14.993
Source: https://www.bleepingcomputer.com/news/security/disney-ditching-slack-after-massive-july-data-breach/
Original Article Text
Click to Toggle View
Disney ditching Slack after massive July data breach. The Walt Disney Company is reportedly ditching Slack after a July data breach exposed over 1TB of confidential messages and files posted to the company's internal communication channels. According to CNBC, Disney has already begun migrating to new "streamlined enterprise-wide collaboration tools" and emailed employees this week to say that they will finish the migration at the end of the company's next fiscal quarter. This move comes after the company suffered a massive data breach in July when a threat actor named 'NullBulge' breached Disney's Slack platform and stole 1.1TB of data. The threat actor claimed to steal all messages and files from almost 10,000 Slack channels containing upcoming project details, financial information, information technology information, and other confidential information. Disney suffered another data breach a month earlier when 2.5GB of Club Penguin and corporate data was leaked from the company’s Confluence server on the 4chan message board. It's unclear how employees will communicate after moving away from Slack and whether Disney will be transitioning to another enterprise platform, like Microsoft Teams, or their own internal software. Communication platforms, like Slack, can be a tempting target for threat actors to steal confidential files that can be used to taunt their victims. In 2022, the Lapsus$ hacking group breached Uber's Slack server using an employee's stolen credentials, where they taunted employees about how they were breached. In August 2023, threat actors breached Activision's Slack server, stealing employee data and information about upcoming games.
Daily Brief Summary
The Walt Disney Company will cease using Slack due to a substantial data breach in July, where over 1TB of confidential information was exposed.
A hacker known as 'NullBulge' compromised Disney's Slack server, accessing files and messages from around 10,000 channels, which included sensitive project and financial details.
Disney has initiated a transition to other enterprise-wide collaboration tools, with full migration expected by the end of the next fiscal quarter.
The breach in July was not isolated; another incident in June saw 2.5GB of data from Club Penguin and corporate information leaked on 4chan.
The exact future communication platforms to replace Slack have not been disclosed, raising questions about whether Disney will adopt established software like Microsoft Teams or develop a proprietary system.
Entities like Slack are becoming increasingly popular targets for hackers, engaging in theft of massive datasets used to pressure or taunt victim organizations.