An unauthorized party stole encrypted internal data related to employee user accounts from home and small business security provider ADT, the company said Monday in a filing with the Securities and Exchange Commission.

The company detected the unauthorized access Oct. 2, according to the filing, and said the “unauthorized actor had illegally accessed ADT’s network using compromised credentials obtained through a third-party business partner.”

The incident is the second cyberattack disclosed by the company in two months. In an Aug. 7 SEC filing, the company disclosed that during a “cybersecurity incident … unauthorized actors illegally accessed certain databases containing ADT customer order information” that included email addresses, phone numbers and postal addresses.

That incident did not include credit card data or banking information, the company said in the filing, nor was there any reason to believe that home security systems were compromised as a result of the incident.

A spokesperson for the Florida-based company told CyberScoop on Tuesday that the company is “investigating a cyberattack on our network,” and pointed to Monday’s SEC filing for any additional information.

The spokesperson did not answer questions about whether the two incidents are distinct, or share any additional context around the nature or context associated with the third-party business partner.

The post Security provider ADT discloses second cybersecurity incident in two months appeared first on CyberScoop.

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

The Not-So-Secret Network Access Broker x999xx

July 3, 2024 0 Comments 0 tags

Most accomplished cybercriminals go out of their way to separate their real names from their hacker handles. But among certain old-school Russian hackers it is not uncommon to find major

CISA Adds Two Known Exploited Vulnerabilities to Catalog

July 23, 2024 0 Comments 0 tags

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2012-4792 Microsoft Internet Explorer Use-After-Free Vulnerability CVE-2024-39891 Twilio Authy Information Disclosure Vulnerability These

Ransomware saw a resurgence in 2023, Mandiant reports

June 3, 2024 0 Comments 0 tags

As law enforcement agencies conduct global operations against ransomware gangs, the number of incidents continue to rise unabated, per a new report from the cybersecurity firm Mandiant. Researchers with the