Chinese police arrested 21 suspects for theft of customer information from Alibaba Group Holding’s logistics affiliate Cainiao Network.
More than 10 million pieces of client data was compromised.
Compromised information includes user names, phone numbers and parcel tracking numbers.
Barcode scanners used in its distribution stations had been infected with malware.
Police investigation determined that none of the illegally obtained data had been shared with any third parties.
TPRM report: https://scoringcyber.rankiteo.com/company/alibaba-com
"id": "ali212330922",
"linkid": "alibaba-com",
"type": "Breach",
"date": "09/2018",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'More than 10 million',
'industry': 'Logistics',
'location': 'China',
'name': 'Cainiao Network',
'type': 'Logistics Company'}],
'attack_vector': 'Malware',
'data_breach': {'number_of_records_exposed': 'More than 10 million',
'personally_identifiable_information': True,
'type_of_data_compromised': ['User names',
'Phone numbers',
'Parcel tracking numbers']},
'description': 'Chinese police arrested 21 suspects for theft of customer '
'information from Alibaba Group Holding’s logistics affiliate '
'Cainiao Network. More than 10 million pieces of client data '
'was compromised, including user names, phone numbers, and '
'parcel tracking numbers. Barcode scanners used in its '
'distribution stations had been infected with malware. Police '
'investigation determined that none of the illegally obtained '
'data had been shared with any third parties.',
'impact': {'data_compromised': ['User names',
'Phone numbers',
'Parcel tracking numbers'],
'systems_affected': ['Barcode scanners']},
'motivation': 'Theft of Customer Information',
'post_incident_analysis': {'root_causes': 'Infected Barcode Scanners'},
'response': {'law_enforcement_notified': True},
'threat_actor': '21 suspects arrested by Chinese police',
'title': "Data Breach at Alibaba's Cainiao Network",
'type': 'Data Breach',
'vulnerability_exploited': 'Infected Barcode Scanners'}