{"id":6412,"date":"2025-08-26T00:02:23","date_gmt":"2025-08-26T00:02:23","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/26\/weekly-update-466\/"},"modified":"2025-08-26T00:02:23","modified_gmt":"2025-08-26T00:02:23","slug":"weekly-update-466","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/26\/weekly-update-466\/","title":{"rendered":"Weekly Update 466"},"content":{"rendered":"<p>    Weekly Update 466<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/www.troyhunt.com\/content\/images\/2025\/08\/Splash-Template.jpg?ssl=1\" alt=\"Weekly Update 466\"><\/p>\n<p>I&#8217;m fascinated by the unwillingness of organisations to name the &#8220;third party&#8221; to which they&#8217;ve attributed a breach. <a href=\"https:\/\/securityaffairs.com\/180445\/data-breach\/allianz-life-data-breach-exposed-the-data-of-most-of-its-1-4m-customers.html?ref=troyhunt.com\" rel=\"noreferrer\">The initial reporting on the Allianz Life incident from last month<\/a> makes no mention whatsoever of Salesforce, nor does any other statement I can find from them. And that&#8217;s very often the way with many other incidents too, which, IMHO, sucks. My view is that when our data is provided to a third party and that party exposes it, we have a very reasonable expectation to know who lost it. My own personal info was exposed in <a href=\"https:\/\/www.teg.com.au\/statement-regarding-ticketek-cyber-incident\/?ref=troyhunt.com\" rel=\"noreferrer\">the Ticketek breach last year<\/a>; can you find any mention whatsoever in that disclosure notice of Snowflake DB? Nope, but that&#8217;s the &#8220;reputable, global third party supplier&#8221; they refer to. Another fun fact: the other third party they don&#8217;t name is HIBP: &#8220;We are aware some customers\u00a0have recently been contacted by a third party regarding the impact to their information&#8221;. \ud83e\udd37\u200d\u2642\ufe0f<\/p>\n<p><!--kg-card-begin: html--><\/p>\n<div>\n<div style=\"width: 170px; display: inline-block; margin-right: 3px;\"><a href=\"https:\/\/itunes.apple.com\/au\/podcast\/troy-hunts-weekly-update-podcast\/id1176454699?ref=troy-hunt\"><img decoding=\"async\" src=\"https:\/\/www.troyhunt.com\/content\/images\/2018\/05\/Listen-on-Apple-Podcasts.svg\" alt=\"Weekly Update 466\"><\/a><\/div>\n<div style=\"width: 175px; display: inline-block; margin-right: 3px;\"><a href=\"https:\/\/www.youtube.com\/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com\"><img decoding=\"async\" src=\"https:\/\/www.troyhunt.com\/content\/images\/2024\/09\/Watch-and-Listen-on-YouTube.svg\" alt=\"Weekly Update 466\"><\/a><\/div>\n<div style=\"width: 118px; display: inline-block; margin-right: 3px;\"><a href=\"https:\/\/open.spotify.com\/show\/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt\"><img decoding=\"async\" src=\"https:\/\/www.troyhunt.com\/content\/images\/2019\/10\/spotify.svg\" class=\"kg-image\" alt=\"Weekly Update 466\"><\/a><\/div>\n<div style=\"width: 120px; display: inline-block;\"><a href=\"https:\/\/omny.fm\/shows\/troy-hunt-weekly-update\/playlists\/podcast.rss?ref=troy-hunt\"><img decoding=\"async\" src=\"https:\/\/www.troyhunt.com\/content\/images\/2018\/07\/Download-via-RSS.svg\" alt=\"Weekly Update 466\"><\/a><\/div>\n<p><iframe loading=\"lazy\" width=\"100%\" height=\"480\" src=\"https:\/\/www.youtube.com\/embed\/TNRlFEyBoXY\" frameborder=\"0\" allow=\"autoplay; encrypted-media\" allowfullscreen><\/iframe>\n<\/div>\n<p><!--kg-card-end: html--><\/p>\n<h2 id=\"references\">References<\/h2>\n<ol>\n<li><a href=\"https:\/\/1password.com\/troyhunt?ref=troyhunt.com\" rel=\"noopener\">Sponsored by:\u00a01Password Extended Access Management: Secure every sign-in for every app on every device.<\/a><\/li>\n<li>\n<a href=\"https:\/\/haveibeenpwned.com\/Breach\/AllianzLife?ref=troyhunt.com\" rel=\"noreferrer\">Allianz Life was breached with 1.1 million <em>unique email addresses<\/em> affected<\/a> (the unnamed third party is apparently Salesforce)<\/li>\n<li>\n<a href=\"https:\/\/x.com\/troyhunt\/status\/1956826362628751781?ref=troyhunt.com\" rel=\"noreferrer\">The 16 million record PayPal &#8220;breach&#8221; always smelled bad<\/a> (probably because it&#8217;s not a PayPal breach!)<\/li>\n<\/ol>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Troy Hunt<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/www.troyhunt.com\/weekly-update-466\/\">Go to troyhunt<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Weekly Update 466 I&#8217;m fascinated by the unwillingness of organisations to name the &#8220;third party&#8221; to which they&#8217;ve attributed a breach. The initial reporting on the Allianz Life incident from last month makes no mention whatsoever of Salesforce, nor does any other statement I can find from them. And that&#8217;s very often the way with [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[51,135],"tags":[143,1739,1740],"class_list":["post-6412","post","type-post","status-publish","format-standard","hentry","category-troyhunttroyhunt","category-weekly-update","tag-breach","tag-party","tag-third"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6412"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6412"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6412\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6412"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6412"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}