{"id":36520,"date":"2024-12-02T00:05:27","date_gmt":"2024-12-01T23:05:27","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=36520"},"modified":"2024-12-02T02:09:34","modified_gmt":"2024-12-02T01:09:34","slug":"stiga-data-leak-garden-and-sport-tools","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2024\/12\/02\/stiga-data-leak-garden-and-sport-tools\/","title":{"rendered":"STIGA data leak (garden and sport tools)"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2024\/12\/02\/datenschutzvorfall-bei-stiga-gartengeraete\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]The company STIGA, active as a supplier in the field of robotic lawnmowers, gardening equipment and sporting goods, has suffered a data protection incident. A reader had made enquiries and received confirmation from the provider. Customer data has been leaked and is now being offered on the Darknet.<br \/>\n<!--more--><\/p>\n<h2>Who is STIGA?<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg05.met.vgwort.de\/na\/b1e4a998b8ee4b7fa5b01ea88f3bffea\" alt=\"\" width=\"1\" height=\"1\" \/>Stiga S.p.A., referred to here as STIGA, is a manufacturer of garden tools and sports products based in Castelfranco Veneto, Italy.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/i.postimg.cc\/Pq1BX9cb\/image.png\" alt=\"STIGA Ger\u00e4te\" width=\"496\" height=\"309\" \/><\/p>\n<p>On the company's website, for example, you can find out that STIGA manufactures autonomous robotic mowers and lawn tractors. The group also offers tennis rackets.<\/p>\n<p>The company was founded in Sweden in 1934 and was independent until 2000. From 2000, it became part of the Global Garden Products (GGP) group, although the Stiga name was retained as a trademark.<\/p>\n<p>After changing its name to Stiga Group and relocating its headquarters to Italy, the company now employs 1,750 people and has an annual turnover of around 500 million euros.<\/p>\n<h2>A reader's tip<\/h2>\n<p>A reader who does not wish to be named contacted me by email on November 27, 2024. He wrote that he had been informed via Google that there had been a data breach at STIGA. He mentioned that the company STIGA sells garden machinery, garden tools and sporting goods. The reader did not provide any details about the Google find, but wrote that he had received information along the lines of: \"STIGA. Your data has been exposed due to a data breach and was found on the dark web on 08. Nov. 2024.\"<\/p>\n<h2>Asked STIGA<\/h2>\n<p>The reader then contacted STIGA by email and received an answer. They confirmed a data breach.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i.postimg.cc\/B6k2nSzt\/image.png\" alt=\"STIGA Datenschutzvorfall\" width=\"640\" height=\"208\" \/><\/p>\n<p>On 24, September 2024, STIGA IT staff discovered that an unauthorized third party had penetrated the system. He had obtained the access data from one of STIGA's suppliers.\u00a0It remains unclear to me why a supplier can access customer data &#8211; in other words, the attacker was probably able to access other data in the network once he was in the system.<\/p>\n<p>In any case, customer data has been stolen and is now being offered on the Darknet. STIGA writes that the affected data includes first name, surname, billing and delivery address, e-mail, telephone number and order data that customers have transmitted via the Internet.<\/p>\n<p>No sensitive information such as financial data, payment details or credit card information is said to have been leaked. I consider the statement that no special categories of personal data relating to health, racial or ethnic origin, political or religious beliefs, etc. were compromised to be bullshit bingo. The GDPR does recognize these categories, but I was not previously aware that I had to provide STIGA with information about my health, race or religious beliefs when I wanted to buy a lawn mower.<\/p>\n<p>The reader writes that it is surprising that customers were not informed immediately, but apparently only on request. As the reader bought equipment from Stiga, all his data is now on the Darknet. He finds this justifiably bad and unfortunately the \"immediate measures taken\" no longer help him personally.<\/p>\n<h2>Notification from STIGA<\/h2>\n<p>Her is the Notification from STIGA &#8211; it's in German.<\/p>\n<p>Was geschah: Am 24. September hat das IKT-Team der STIGA einen Versto\u00df festgestellt, der unsere Systeme betraf. Aufgrund einer unsachgem\u00e4\u00dfen Verwendung von Zugangsdaten, die einem unserer Lieferanten zugewiesen wurden, kam es zu einem unbefugten Zugriff und einer vor\u00fcbergehenden Verbreitung einiger Ihrer Daten.<\/p>\n<p>Welche personenbezogenen Daten waren betroffen: Zu den von der Sicherheitsverletzung betroffenen Daten geh\u00f6ren Vorname, Nachname, Rechnungs- und Lieferadresse, E-Mail, Telefonnummer und Bestelldaten, die uns \u00fcber das Internet \u00fcbermittelt wurden. Weder sensible Informationen wie Finanzdaten, Zahlungsdetails oder Kreditkarteninformationen noch besondere Kategorien personenbezogener Daten wie Daten \u00fcber Gesundheit, Rasse oder ethnische Herkunft, politische oder religi\u00f6se \u00dcberzeugungen sind gef\u00e4hrdet.<\/p>\n<p>Was wir tun:<\/p>\n<ul>\n<li>Wir haben sofortige Ma\u00dfnahmen ergriffen, um unsere Systeme zu sichern und jeden weiteren unbefugten Zugriff oder jede weitere Verbreitung zu verhindern (z. B. Sperren des verletzten Kontos und \u00c4ndern der Passw\u00f6rter anderer Konten).<\/li>\n<li>Wir haben die erforderlichen \u00dcberpr\u00fcfungen durchgef\u00fchrt, die best\u00e4tigt haben, dass nur die oben beschriebenen personenbezogenen Daten betroffen sind und weder andere Systeme noch Datenbanken kompromittiert wurden.<\/li>\n<li>Unser Team arbeitet aktiv mit externen Experten zusammen, um sicherzustellen, dass das Problem vollst\u00e4ndig gel\u00f6st wird.<\/li>\n<li>Wir haben die Datenschutzaufsichtsbeh\u00f6rde benachrichtigt und Anzeige bei den Strafbeh\u00f6rden erstattet.<\/li>\n<\/ul>\n<p><strong>Was sind die m\u00f6glichen Folgen?<\/strong><\/p>\n<p>Aufgrund der geringen Sensibilit\u00e4t der betroffenen Daten erwarten wir keine schwerwiegenden Folgen als Folge des Versto\u00dfes. Dennoch kann das Risiko eines Identit\u00e4tsdiebstahls oder eines Missbrauchs Ihrer Daten nicht v\u00f6llig ausgeschlossen werden.<\/p>\n<p>Was Sie tun k\u00f6nnen: Wir empfehlen die folgenden Ma\u00dfnahmen, um Ihre Daten zu sch\u00fctzen:<\/p>\n<p>1. \u00dcberwachen Sie Ihre Konten: Bitte \u00fcberwachen Sie alle relevanten Konten auf verd\u00e4chtige Aktivit\u00e4ten.<br \/>\n2. Seien Sie vorsichtig bei Phishing- oder Betrugsversuchen: Seien Sie vorsichtig bei unaufgeforderten Mitteilungen, in denen Sie um Ihre pers\u00f6nlichen Daten gebeten werden (z. B. indem Sie immer die Identit\u00e4t des Absenders \u00fcberpr\u00fcfen), und klicken Sie nicht auf verd\u00e4chtige Links.<br \/>\n3. \u00c4ndern Sie Ihre Online-Zugangsdaten, falls diese leicht aus den oben angegebenen personenbezogenen Daten abgeleitet werden k\u00f6nnen. In jedem Fall best\u00e4tigen wir, dass\u00a0keine Daten oder Informationen im Zusammenhang mit Ihren Zugangsdaten von der Verletzung betroffen sind.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]The company STIGA, active as a supplier in the field of robotic lawnmowers, gardening equipment and sporting goods, has suffered a data protection incident. A reader had made enquiries and received confirmation from the provider. Customer data has been leaked &hellip; <a href=\"https:\/\/borncity.com\/win\/2024\/12\/02\/stiga-data-leak-garden-and-sport-tools\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-36520","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/36520","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=36520"}],"version-history":[{"count":6,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/36520\/revisions"}],"predecessor-version":[{"id":36526,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/36520\/revisions\/36526"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=36520"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=36520"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=36520"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}