news.volyx.in

Checkout.com hacked, refuses ransom payment, donates to security labs (checkout.com)

622 points by StrangeSound · 253 days ago · 284 comments on HN

Article summary

Checkout.com, a global payments network, was targeted by a criminal group known as 'ShinyHunters' who gained access to a legacy third-party cloud file storage system, affecting less than 25% of their current merchant base. The company has stated that their live payment processing platform was not impacted and no merchant funds or card numbers were accessed. Checkout.com has refused to pay the ransom and instead donated the ransom amount to fund cybercrime research. The company has taken responsibility for the incident and is working to identify and contact those impacted.

Main themes

  • Cybersecurity
  • Data Breach
  • Ransomware
  • Corporate Responsibility
  • Apology and Accountability

What commenters say

  • The company's apology is seen as genuine and refreshing by some, while others view it as insincere and lacking in concrete actions to prevent future incidents.
  • Some argue that every company will eventually be hacked, and what matters is how they respond to the incident, while others believe that proper security measures can prevent breaches.
  • The decision not to pay the ransom is widely supported, but some question the company's decision to leave a legacy system online with outdated user data, highlighting a lack of security hygiene.
  • There is a debate about the effectiveness of apologies in corporate settings, with some arguing that they can be seen as empty words and others believing that they can be a meaningful step towards accountability.
  • Some commenters emphasize the importance of transparency and concrete actions to prevent future incidents, rather than just apologizing for past mistakes.
  • The discussion also touches on the topic of data retention and deletion, with some arguing that companies should prioritize deleting unnecessary data to minimize liability and others suggesting that some data should be kept to prevent account re-use.