Telus Digital confirms breach after claim of a stolen petabyte
Canadian outsourcing provider Telus Digital has confirmed a data breach. The group ShinyHunters claims responsibility and says it took nearly one petabyte of data, including call records for the telecoms operator Telus. According to BleepingComputer, the actor obtained Telus Digital's Google Cloud Platform credentials through last year's Salesloft Drift breach.
What this means for your business
The chain here is worth noting: a breach at one cloud service provider yielded credentials used many months later against an entirely different company. If you outsource customer service, case handling or support, your customer data sits with someone else while accountability to customers and regulators stays with you. The question for leadership is not whether the supplier is secure, but how quickly you will hear about it when they are not.
Berigo recommends
- Review which outsourced suppliers actually process customer data, and which cloud environments that data sits in.
- Put a notification deadline in the contract, with a specific number of hours from the supplier detecting an incident to informing you.
- Rotate the access and API keys suppliers hold to your environments, and give them expiry dates.
- Determine whether your own organisation was exposed through the Salesloft Drift incident, and verify that affected credentials have genuinely been replaced.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch