Snapchat has apologised after a phishing attack saw details of its employees’ salaries leaked online.
The photo-sharing app, which is famous for not storing the images it carries (instead deleting them after ten seconds), made the confession in a blog post, confirming that a member of its human resources department had been tricked into handing over payroll information about “some current and former employees”.
The luckless worker had been fooled by an email purporting to come from Snapchat’s CEO asking for a detailed run-down of payment information at the company.
The firm said it responded “swiftly and aggressively” to the scam, reporting the incident to the FBI within four hours of it occurring, and identifying which employees were affected, offering them two years of free identity-theft insurance and monitoring.
“None of our internal systems were breached, and no user information was accessed,” the company said in a statement. “When something like this happens, all you can do is own up to your mistake, take care of the people affected, and learn from what went wrong.
“To make good on that last point, we will redouble our already rigorous training programs around privacy and security in the coming weeks. Our hope is that we never have to write a blog post like this again.”
Kevin Epstein from security firm Proofpoint said that the phishing attack should serve as yet another reminder to organisations and employees that people remain the weakest link in security.
“Phishing attacks have become so sophisticated that they entice even the most-senior executives to click on a link in email or reply with requested sensitive information, without verbally confirming confidential information directives before sending,” he said.
“People are being used as a key part of criminal attacks; any defence must assume natural human behaviour will occur, and compensate accordingly.”
How much do you know about mobile apps? Take our quiz here!
Fourth quarter results beat Wall Street expectations, as overall sales rise 6 percent, but EU…
Hate speech non-profit that defeated Elon Musk's lawsuit, warns X's Community Notes is failing to…
Good luck. Russia demands Google pay a fine worth more than the world's total GDP,…
Google Cloud signs up Spotify, Paramount Global as early customers of its first ARM-based cloud…
Facebook parent Meta warns of 'significant acceleration' in expenditures on AI infrastructure as revenue, profits…
Microsoft says Azure cloud revenues up 33 percent for September quarter as capital expenditures surge…