Mobile payments service Cash App has suffered a data breach after an ex-employee accessed sensitive customer data.
The company behind the service, Block (formerly Square), reported the incident to the US Securities and Exchange Commission (SEC) earlier this week.
In the filing, the company explained that the person was allowed to access this data as part of their past job responsibilities, but that access should have been barred the moment they left. Block has so far declined to explain why the employee was still able to access the data.
We’re looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn’t take more than 60 seconds of your time, and entrants from the UK and US will have the chance to enter a draw for a £100 Amazon gift card (or equivalent in USD). Thank you for taking part.
Personally identifiable information
The motive behind the exfiltration is unclear, but we know the person took customers’ full names and brokerage account numbers, and in some cases, brokerage portfolio value, brokerage portfolio holdings, and stock trading data.
Block also refrained from revealing the number of customers affected, but did say it was reaching out to more than eight million current and former customers about the breach. All of them reside in the United States.
“At Cash App we value customer trust and are committed to the security of customers’ information,” a spokesperson told TechCrunch.
“Upon discovery, we took steps to remediate this issue and launched an investigation with the help of a leading forensics firm. We know how these reports were accessed, and we have notified law enforcement. In addition, we continue to review and strengthen administrative and technical safeguards to protect information.”
Earlier this week, cybersecurity experts from Imperva published a new report that suggested the majority of companies fail to take insider threat as seriously as they should.
Based on a survey of 500 security professionals, the report revealed that companies are often guilty of underestimating the extent of the threat posed by insiders, a conclusion perhaps reinforced by the Cash App breach.
According to Imperva, businesses need to add insider risk to their overall data protection strategy, and set up a diverse insider threat detection system that combines several tools.