UPDATED 22:01 EDT / OCTOBER 09 2018

SECURITY

Garmin-owned marine navigation company latest to expose customer data

Navionics srl a socio unico, a division of Garmin Ltd. that offers marine navigation services, is the latest to suffer from a data breach, exposing the records of more than 260,000 customers.

The data, discovered by security researcher Bob Diachenko, were left open to all and sundry on an unsecured MongoDB database and was indexed by the Shodan search engine on Sept. 10.

Some 19 gigabytes of data was exposed consisting of 261,259 records that included information such as email addresses, customer names and in some cases purchased product IDs and user IDs. Navionics confirmed the breach, saying in a statement that it’s “grateful that Mr. Diachenko notified us of this misconfiguration using the responsible disclosure model.”

“Once notified, we immediately investigated and resolved the vulnerability,” the company noted. “Following our investigation, we confirmed that none of the records or data were otherwise accessed or exfiltrated and none of the data was lost. Even so, Navionics still notified affected customers via e-mail by October 8, 2018.”

Discussing the news, Ryan Wilk, vice president of customer success for NuData Security Inc., told SiliconANGLE that it’s yet another example of how difficult monitoring and securing data is, as well as a reminder that patching vulnerabilities and reviewing security architecture and authentication is “not a checkbox, but an ongoing process.”

“Consumer data has been going through the meat grinder lately with the number of exposures, attacks and information that has been stolen, by cybercriminals,” he said. “Once this information falls into the wrong hands it is used to make synthetic identities, and take over identities and accounts.”

As a result, he added, companies are implementing layered defenses, including passive biometrics and behavioral analytics to identify consumers by their behavior. “By doing so, inadvertent mistakes like a misconfigured database exposing personal information won’t put the victim’s identity at risk,” he said.

Image: Navionics

A message from John Furrier, co-founder of SiliconANGLE:

Your vote of support is important to us and it helps us keep the content FREE.

One click below supports our mission to provide free, deep, and relevant content.  

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well” – Andy Jassy

THANK YOU