23 ms·
The first two reference something where there's no strong evidence showing that it actually happened (it's more likely that it was credential stuffing-- using
by JonathonW 4y ago
The first two reference something where there's no strong evidence showing that it actually happened (it's more likely that it was credential stuffing-- using data from other breaches to compromise Disney+ accounts using the same passwords), and the third was Starwood Hotels (now Marriott), not Disney.
- autoexec 4y agoMy fault! One of those first two should have been about this: https://disneynewstoday.net/2016/07/31/disney-interactive-shuts-down-playdom-forums-over-data-breach/ https://disneynewstoday.net/2016/07/31/disney-interactive-sh... I wouldn't give Disney a pass on the credential stuffing. https://www.the-parallax.com/poor-security-password-reuse-disney-plus-breach/ https://www.the-parallax.com/poor-security-password-reuse-di... As for the hotel it's sort of a partnership deal, Disney owns the land, built it, leases the building to another company to run, takes a cut of the profits, and has them branded as part of their Walt Disney Collection of resorts. I think it's fair to give Disney the blame. https://en.wikipedia.org/wiki/Walt_Disney_World_Dolphin https://en.wikipedia.org/wiki/Walt_Disney_World_Dolphin There's also this, which you could argue was outside of their control too, but I think once a company hands your data over to third parties they're on the hook for what happens as a result: https://threatpost.com/epsilon-data-breach-expands-include-capital-one-disney-others-040411/75100/ https://threatpost.com/epsilon-data-breach-expands-include-c...