CERT-In Advisory
CIAD-2019-0035
OnePlus Data Breach
Original Issue Date: November 26, 2019
Severity Rating: Medium
Description
It has been reported that OnePlus suffered a data breach recently. Data regarding users of OnePlus online store such as contact numbers, names, email addresses, users order information and shipping addresses are reported to have been exposed. It is learnt that less than 3000 Indian customers' orders were exposed. OnePlus has clarified that no payment card, bank account details or passwords were breached. OnePlus has stated that all affected users have already been notified by email.
Recommendations
- Users may receive spam and phishing emails as a result of this incident and they need to stay alert against these kinds of mails.
- The kind of information exposed such as name, address, email can be abused to impersonate as victim and gain access to other accounts. Even though OnePlus has claimed that password data was not accessed, users are still advised to change their OnePlus account passwords with a strong password.
- Do not open attachments and never click on a URL contained in an unsolicited e-mail, even if the link seems benign.
References
OnePlus
https://forums.oneplus.com/threads/security-notification.1144088/
Forbes
https://www.forbes.com/sites/kateoflahertyuk/2019/11/23/oneplus-confirms-hackers-accessed-customer-details-heres-what-to-do/#203d467c23c6
The Verge
https://www.theverge.com/2019/11/22/20978455/oneplus-discloses-data-breach-names-numbers-emails-addresses-exposed
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|