SECURITY
SECURITY
SECURITY
Home improvement site Houzz has suffered a data breach, with an unknown amount of user information stolen.
The hack, discovered in late December but only revealed on Friday, involved the theft of profile information, including name, city, state, country and profile description, along with internal identifiers such as the region and location of the user and whether each has a profile image.
Houzz added that usernames and encrypted passwords were stolen as well. The hack did not involve the theft of Social Security numbers or payment card, bank account, or other financial information.
The company provided no details as to how the hack took place, saying on an FAQ page that it “continue(s) to investigate the incident both with our internal team and with a leading forensics firm.” Affected users have been notified by email and asked to reset their passwords as a precaution.
@troyhunt FYI, web site @houzz got hacked. Just got this email notice. pic.twitter.com/QKB7iUGu1W
— Stewart Rand (@stewssr) January 31, 2019
Houzz is a 10-year-old forum and home improvement service that connects people with services in home remodeling, architecture, interior design, decorating, landscaping and home improvement. The company was valued at $4 billion as of its last venture capital fundraising and has raised $613.6 million to date, meaning it can afford to implement decent security.
Tim Erlin, vice president of product management and strategy at Tripwire Inc., told SiliconANGLE that although it might not be clear how this sensitive data was obtained, it’s a good example of the risks of password reuse.
“If you used the same password for your Houzz account that you used for a more sensitive account, then you’ve put that more sensitive account at risk as well,” Erlin explained. “Using unique passwords is a good way to protect yourself from this type of risk.”
Using multi-factor authentication is another way to reduce the risk, he added. “The internet is all about connection, and sometimes those connections work to the advantage of attackers,” he said.
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.