Parenting Retailer Kiddicare Hit By Data Breach

A major UK childrens’ retailer has suffered a major data breach that led to hundreds of thousands of customer details being leaked online.

Kiddicare has emailed 794,000 people which may have been affected by the incident, with names, addresses and telephone numbers all feared to have been leaked, although no card details are thought to be at risk.

Leaked

Peterborough-based Kiddicare said that it first became aware of a possible breach after being contacted by customers who had received suspicious SMS messages purporting to be from the company asking them to take part in a survey.

Following separate contact from unnamed security company with further information, the breach was then discovered to be linked to a “test” website Kiddicare used in November 2015 apparently with real customer data.

In an FAQ on its site, Kiddicare is advising customers to beware any unsolicited contact via email, post or telephone call/SMS.

“The personal information exposed has limited use and therefore the risk to you is low,” it said.

“However any personal information can be used in phishing attacks and scams and so you should be extra vigilant and be alert to any suspicious communication. If you are unsure whether a communication is genuine, you should always contact the company the message is purporting to be from to confirm authenticity.”

The company says it has now deleted the test site from its servers, made “significant upgrades and improvements” to its security, and also reported itself to the UK’s Information Commissioner Office (ICO).

An ICO spokesperson told TechWeekEurope, “We’re aware of an incident and are making enquiries.”

This latest breach goes to show how important it is to continually monitor for anomalous activity across the entire breadth of the network, security commentators have said.

“While it’s admirable that Kiddicare has gone straight to the UK’s Information Commissioner, it’s not good enough that the breach was discovered by customers whose information had not only been lost but already used with bad intentions,” said Justin Harvey, chief security officer at Fidelis Cybersecurity.

“Kiddicare and similar organisations need to switch from such a reactive approach and, instead, be proactively hunting for the malicious activity within its network that allows data to be exposed.”

What do you know about some of the world’s biggest data breaches? Take our quiz to find out!

Mike Moore

Michael Moore joined TechWeek Europe in January 2014 as a trainee before graduating to Reporter later that year. He covers a wide range of topics, including but not limited to mobile devices, wearable tech, the Internet of Things, and financial technology.

View Comments

  • All the actions companies take (including retroactively) is good, but the real question is why aren't the police taking a more vigorous action against the actual data thieves. Would they be so complacent if it was physical items being stolen - Data can be worth more and pose a real physical risk to people, including children

  • It is not surprising to hear that another business has suffered the fate of a data breach. Learning from this, it is imperative for businesses to understand that it is not enough to solely rely on Information Security teams to advise if a breach has occurred. These attacks are happening on a daily basis and businesses only usually find out once the data has been sold and their customers become the victim of targeted phishing attempts; unfortunately by this point, the damage is already done.

    Normal cyber defences are no longer enough. Companies must be proactive and test the security of the whole business – from the perimeter all the way through to employee awareness training. Put simply, taking a proactive stance in relation to Information Security is the only way that companies are going to stop these hacks from happening.

    Tony Sweeney, Cyber Security Director for the KCS Group Europe

Recent Posts

EU Widens Investigations Into Chinese Imports, Subsidies

After the United States imposes 100 percent tariffs on certain Chinese goods, Europe widens its…

2 days ago

Reddit Deal With OpenAI Gives ChatGPT Access To Content

OpenAI strikes deal with Reddit to train its AI tech on user posts and give…

2 days ago

Microsoft Invests 4 Billion Euros In France For AI, Cloud

Global spending spree from Microsoft continues, with huge investment for new data centre to drive…

2 days ago

Toshiba Axes 4,000 Staff In Post-Delisting Restructuring Operation

Workforce blow. Newly privatised Toshiba has embarked on a 'revitalisation plan' that will entail the…

3 days ago

European Union Opens Child Safety Probe Into Meta

European Commission opens an official child safety investigation into Facebook and Instagram-owner Meta Platforms

3 days ago