- Published on
30 Oct 2020 (Straits Times) - The personal information of 1.1 million RedMart user accounts was stolen from a customer database and put up for sale on an online forum.
A spokesman from e-commerce giant Lazada, which owns e-grocer Redmart, confirmed the data breach on Friday (Oct 30), saying that the personal information stolen included names, phone numbers, e-mail, mailing addresses, encrypted passwords and partial credit card numbers.
"Our cyber-security team discovered an individual claiming to be in possession of a RedMart customer database taken from a legacy RedMart system no longer in use by the company," the spokesman said.
The e-commerce giant said the stolen information was from a Redmart database that had not been updated for more than 18 months.
"This RedMart-only information is more than 18 months out of date and not linked to any Lazada database," the spokesman said, adding that the firm has taken action to block unauthorised access to the database.
Also in a notification e-mail sent to affected customers on Friday evening (Oct 30), Lazada said it discovered the security breach the day before (Oct 29) as part of its routine monitoring.
A spokesman from e-commerce giant Lazada, which owns e-grocer Redmart, confirmed the data breach on Friday (Oct 30), saying that the personal information stolen included names, phone numbers, e-mail, mailing addresses, encrypted passwords and partial credit card numbers.
"Our cyber-security team discovered an individual claiming to be in possession of a RedMart customer database taken from a legacy RedMart system no longer in use by the company," the spokesman said.
The e-commerce giant said the stolen information was from a Redmart database that had not been updated for more than 18 months.
"This RedMart-only information is more than 18 months out of date and not linked to any Lazada database," the spokesman said, adding that the firm has taken action to block unauthorised access to the database.
Also in a notification e-mail sent to affected customers on Friday evening (Oct 30), Lazada said it discovered the security breach the day before (Oct 29) as part of its routine monitoring.
In a notification e-mail sent to affected customers, Lazada said it discovered the security breach on Oct 29 as part of its routine monitoring. PHOTO: ST READER
"For the avoidance of doubt, Lazada's current customer data is not affected by this incident," according to the notification e-mail.
As a security measure, the firm has logged every customer out of their existing accounts. When customers log in, they will be asked to create a new password. Customers are also advised to change their passwords frequently.
Lazada also warned customers to be on the alert for phishing e-mails, where scammers ask for sensitive information while pretending to be from Lazada. "Lazada does not request customers to verify your personal information," it said in the e-mail notification.
Lazada is investigating the data breach, and has informed the Personal Data Protection Commission (PDPC) of the breach. A PDPC spokesman said the commission was aware of the incident and is currently investigating.
The Straits Times has reached out to Lazada for comment.
As a security measure, the firm has logged every customer out of their existing accounts. When customers log in, they will be asked to create a new password. Customers are also advised to change their passwords frequently.
Lazada also warned customers to be on the alert for phishing e-mails, where scammers ask for sensitive information while pretending to be from Lazada. "Lazada does not request customers to verify your personal information," it said in the e-mail notification.
Lazada is investigating the data breach, and has informed the Personal Data Protection Commission (PDPC) of the breach. A PDPC spokesman said the commission was aware of the incident and is currently investigating.
The Straits Times has reached out to Lazada for comment.
From Straits Times online on 30 Oct 2020 at 10pm
- Published on
By December, TraceTogether-only SafeEntry will be implemented at all popular venues currently requiring check-in, including workplaces, schools, malls, food and beverage outlets and hotels. A full list of venues is available on the SafeEntry website and will be updated "on an ongoing basis", said The Smart Nation and Digital Government Office (SNDGO).
When TraceTogether-only SafeEntry is implemented at a venue, visitors will no longer be able to enter by scanning QR codes with phone cameras, using SingPass Mobile or physically scanning their personal IDs.
Opening the SingPass app and scanning the SafeEntry QR code before entering a venue has become part and parcel of our lives. Soon, however, that may change as the Government attempts to switch to TraceTogether instead, in light of Phase 3 approaching to prevent the spread of COVID-19 in the community.
When TraceTogether-only SafeEntry is implemented at a venue, visitors will no longer be able to enter by scanning QR codes with phone cameras, using SingPass Mobile or physically scanning their personal IDs.
Opening the SingPass app and scanning the SafeEntry QR code before entering a venue has become part and parcel of our lives. Soon, however, that may change as the Government attempts to switch to TraceTogether instead, in light of Phase 3 approaching to prevent the spread of COVID-19 in the community.
The Smart Nation and Digital Government Office (SNDGO) announced on Tuesday (Oct 20) that TraceTogether-only SafeEntry will be progressively implemented at popular venues across Singapore by the end of the year.
It said that this transition from other SafeEntry methods, such as scanning identity cards, is vital as the country prepares to resume larger-scale events and further reopen its economy safely amid the COVID-19 pandemic.
The TraceTogether programme, which comprises both an app and a token, relies on proximity data to provide an initial list of close contacts for COVID-19 cases. Together with SafeEntry and associated digital systems, the programme would enable contact tracing teams to reduce the time taken to identify and quarantine a close contact from four days to less than two days on average.
The use of TT-only SE (TraceTogether-only SafeEntry) will provide added assurance that everyone present at these larger-scale activities is better protected by effective contact tracing through participation in the TT programme as TT-only SE ensures that if a COVID-19 case is identified, we can quickly inform close contacts in those locations through the TT programme. The close contacts can immediately take the necessary precautions to keep their loved ones safe.
It said that this transition from other SafeEntry methods, such as scanning identity cards, is vital as the country prepares to resume larger-scale events and further reopen its economy safely amid the COVID-19 pandemic.
The TraceTogether programme, which comprises both an app and a token, relies on proximity data to provide an initial list of close contacts for COVID-19 cases. Together with SafeEntry and associated digital systems, the programme would enable contact tracing teams to reduce the time taken to identify and quarantine a close contact from four days to less than two days on average.
The use of TT-only SE (TraceTogether-only SafeEntry) will provide added assurance that everyone present at these larger-scale activities is better protected by effective contact tracing through participation in the TT programme as TT-only SE ensures that if a COVID-19 case is identified, we can quickly inform close contacts in those locations through the TT programme. The close contacts can immediately take the necessary precautions to keep their loved ones safe.
From now until mid-November, TraceTogether-only SafeEntry will be rolled out at venues which host activities that draw larger groups of people. These include cinemas, places of worship with more than 100 attendees, and venues hosting live performances and business events.
“Members of the public who intend to attend these activities are encouraged to download the TT app or collect their TT token as soon as possible,” the SNDGO advised.
“Members of the public who intend to attend these activities are encouraged to download the TT app or collect their TT token as soon as possible,” the SNDGO advised.
From Channelnewsasia article on 20 Oct 2020