PC streaming service Shadow discloses security breach

Share via:

Shadow, which offers services that let you stream a Windows PC, has disclosed a security breach that led an attacker taking some private customer data. The company is sending emails to customers notifying them that a bad actor was able to extract their first and last name, email address, date of birth, billing address, and credit card expiration date.

Shadow’s CEO confirmed the breach in a statement to The Verge. “We were recently the victim of a highly sophisticated social engineering attack which led to the exfiltration of the database of one of our service providers, resulting in the unauthorized exposure of certain customer data,” Eric Sele says. “We have since then taken immediate steps to secure our systems, including reinforcing the security protocols we apply with all our service providers. Most importantly, no passwords or financial data have been compromised.”

Here’s what happened, according to the email sent to customers (which you can see on Reddit):

At the end of September, we were the victim of a social engineering attack targeting one of our employees. This highly sophisticated attack began on the Discord platform with the downloading of malware under cover of a game on the Steam platform, proposed by an acquaintance of our employee, himself a victim of the same attack.

Our security team took immediate action. Despite our actions, the attacker was able to exploit one of the stolen cookies to connect to the management interface of one of our SaaS providers. Thanks to this cookie, now deactivated, the attacker was able to extract, via our SaaS provider’s API, certain private information about you.

The company says it has “reinforced the security protocols we apply with all our SaaS providers” and that it will be “upgrading our internal systems to render compromised workstations harmless.”

A since-removed Reddit post from a user that identifies as a community manager also included instructions to delete your Shadow account and advises users to “take proactive steps to enhance your online privacy and identity protection.” You can see that post on the Wayback Machine.

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We StartupNews.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It’s possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.

Popular

More Like this

PC streaming service Shadow discloses security breach

Shadow, which offers services that let you stream a Windows PC, has disclosed a security breach that led an attacker taking some private customer data. The company is sending emails to customers notifying them that a bad actor was able to extract their first and last name, email address, date of birth, billing address, and credit card expiration date.

Shadow’s CEO confirmed the breach in a statement to The Verge. “We were recently the victim of a highly sophisticated social engineering attack which led to the exfiltration of the database of one of our service providers, resulting in the unauthorized exposure of certain customer data,” Eric Sele says. “We have since then taken immediate steps to secure our systems, including reinforcing the security protocols we apply with all our service providers. Most importantly, no passwords or financial data have been compromised.”

Here’s what happened, according to the email sent to customers (which you can see on Reddit):

At the end of September, we were the victim of a social engineering attack targeting one of our employees. This highly sophisticated attack began on the Discord platform with the downloading of malware under cover of a game on the Steam platform, proposed by an acquaintance of our employee, himself a victim of the same attack.

Our security team took immediate action. Despite our actions, the attacker was able to exploit one of the stolen cookies to connect to the management interface of one of our SaaS providers. Thanks to this cookie, now deactivated, the attacker was able to extract, via our SaaS provider’s API, certain private information about you.

The company says it has “reinforced the security protocols we apply with all our SaaS providers” and that it will be “upgrading our internal systems to render compromised workstations harmless.”

A since-removed Reddit post from a user that identifies as a community manager also included instructions to delete your Shadow account and advises users to “take proactive steps to enhance your online privacy and identity protection.” You can see that post on the Wayback Machine.

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We StartupNews.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It’s possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.

Website Upgradation is going on for any glitch kindly connect at office@startupnews.fyi

More like this

Coinbase chief legal officer responds to cbBTC service terms...

Coinbase's cbBTC is backed at a 1:1 ratio...

Apple’s next iPhone will be one of the cheapest,...

Now that the iPhone 16 lineup has been...

iPhone 16 teardown shows new simpler replaceable battery system

The iPhone 16 lineup include a few advancements...

Popular

Upcoming Events

Startup Information that matters. Get in your inbox Daily!