Stake团队关于信息安全警告- Mixpanel安全漏洞事件
-
我们想告知您,我们使用的第三方分析服务提供商 Mixpanel 近期发生了一起安全漏洞事件。
Mixpanel 无法访问 Stake 的基础设施。此次漏洞事件发生在 Mixpanel 的系统中,并影响了多家使用其服务的公司。
Stake 的平台和基础设施并未受到访问。您的密码和资金仍然安全。
我们最近了解到,部分 Stake 用户信息包含在被泄露的数据中。我们分享此信息是为了提醒您保持警惕。
事件经过
Mixpanel 遭受了短信钓鱼攻击,导致其系统遭到未经授权的访问。该事件已于周末被制止。后续调查显示,攻击者在 Mixpanel 控制事件之前导出了包含 Stake 用户个人资料信息的文件。
Mixpanel 已确认,此次事件中泄露的数据包括:用户名、电子邮件地址、出生日期和电话号码。
我们已部署在线监控服务,以查找与此事件相关的其他信息。
我们已采取的措施
已验证我们的系统未受影响
已确认 Mixpanel 已完全控制此次事件
Mixpanel 已保护其系统,目前正在与执法部门合作。
您可以采取的措施
我们强烈建议您为账户添加密码,以避免身份冒用诈骗和网络钓鱼攻击;如果您无法使用密码,请启用双因素身份验证。
我们还提供以下建议,以帮助您保持安全
请警惕冒充 Stake 的电子邮件或请求
Stake 绝不会索要您的密码或双因素身份验证码
请确保您的设备和操作系统保持最新状态
此致,
Stake 团队
英文通知:
We want to let you know about a recent security breach that occurred through one of our third-party providers we use for analytics, Mixpanel.Mixpanel has no access to Stake’s infrastructure. This breach occurred in Mixpanel’s systems and impacted multiple companies that use their services.Stake’s platform and infrastructure was not accessed. Your password and funds remain secure.We recently learned that some Stake user information was included in the data that was accessed. We are sharing this information so you can stay vigilant.What HappenedMixpanel was breached through a SMS phishing (smishing) attack that resulted in unauthorized access to their systems. The incident was stopped that weekend. The ensuing investigation determined that the attacker exported files containing Stake user profile information before Mixpanel contained the incident.Mixpanel have confirmed the following data was included as part of this incident: username, email, date of birth and phone number.Online monitoring services are in place to look for additional information relating to this incident.What We’ve DoneValidated that our systems have not been impactedConfirmed that Mixpanel have fully contained the incident Mixpanel has secured their systems and is currently working with law enforcement.What You Can DoWe strongly recommend to avoid impersonation scams and phishing attacks, that you add passkeys to your account, or alternatively if you cannot use passkeys, enable 2-factor authentication.We also have the following suggestions to help stay safe Be cautious with emails or requests pretending to be from StakeStake will never ask for your password or 2fa codeKeep your devices and operating systems up to date Best regards,The Stake Team
没有自制力的人慎入,后果自负!!!
推荐阅读
标签: Stake
声明: 除非有特别说明,文章皆由 优才网是稳定靠谱的资源网站 原创
本文链接: https://yc.xinyun28.com/youcai/305.html,欢迎转载,请添加本文链接,自觉的人天不负!
分享本文:

本文暂时没人发表意见,说几句吧
发表评论