zlacker

[return to "Checkout.com hacked, refuses ransom payment, donates to security labs"]
1. throwa+25[view] [source] 2025-11-13 10:08:35
>>Strang+(OP)
I love this part (no trolling from me):

    > We are sorry. We regret that this incident has caused worry for our partners and people. We have begun the process to identify and contact those impacted and are working closely with law enforcement and the relevant regulators. We are fully committed to maintaining your trust.
I know there will by a bunch of cynics who say that an LLM or a PR crisis team wrote this post... but if they did, hats off. It is powerful and moving. This guys really falls on his sword / takes it on the chin.
◧◩
2. sigmoi+I5[view] [source] 2025-11-13 10:14:32
>>throwa+25
I'll never not think of that South Park scene where they mocked BP's "We're so sorry" statement whenever I see one of those. I don't care if you're sorry or if you realize how much you betrayed your customers. Tell me how you investigated the root causes of the incident and how the results will prevent this scenario from ever happening again. Like, how many other deprecated third party systems were identified handling a significant portion of your customer data after this hack? Who declined to allocate the necessary budget to keep systems updated? That's the only way I will even consider giving some trust back. If you really want to apologise, start handing out cash or whatever to the people you betrayed. But mere words like these are absolutely meaningless in today's world. People are right to dismiss them.
◧◩◪
3. jacque+Q9[view] [source] 2025-11-13 10:45:05
>>sigmoi+I5
I wouldn't be so quick. Everybody gets hacked, sooner or later. Whether they'll own up to it or not is what makes the difference and I've seen far, far worse than this response by Checkout.com, it seems to be one of the better responses to such an event that I've seen to date.

> Like, how many other deprecated third party systems were identified handling a significant portion of your customer data after this hack?

The problem with that is that you'll never know. Because you'd have to audit each and every service provider and I think only Ebay does that. And they're not exactly a paragon of virtue either.

> Who declined to allocate the necessary budget to keep systems updated?

See: prevention paradox. Until this sinks in it will happen over and over again.

> But mere words like these are absolutely meaningless in today's world. People are right to dismiss them.

Again, yes, but: they are at least attempting to use the right words. Now they need to follow them up with the right actions.

◧◩◪◨
4. BoredP+jc[view] [source] 2025-11-13 11:06:48
>>jacque+Q9
There are millions of companies even century or decade old ones without a hacking incident with data extraction. The whole everyone gets hacked is copium for a lack of security standards or here the lack of deprecation and having unmantained systems online with legacy client data. Announcing it proudly would be concerning if I had business with them. It's not even a lack of competence... it's a lack of hygiene.
◧◩◪◨⬒
5. bragr+6e[view] [source] 2025-11-13 11:19:50
>>BoredP+jc
>There are millions of companies even century or decade old ones without a hacking incident with data extraction.

Name five.

◧◩◪◨⬒⬓
6. Retric+Gg[view] [source] 2025-11-13 11:42:28
>>bragr+6e
The pedantic answer is to point to a bunch of shell companies without any electronic presence. However in terms of actual businesses there’s decent odds the closest dry cleaners, independent restaurant, car wash, etc has not had its data extracted by a hacking incident.

Having a minimal attack surface and not being actively targeted is a meaningful advantage here.

◧◩◪◨⬒⬓⬔
7. bragr+Ty1[view] [source] 2025-11-13 18:39:26
>>Retric+Gg
>there’s decent odds the closest dry cleaners, independent restaurant, car wash, etc has not had its data extracted by a hacking incident.

And there's also a decent chance they have. Did we not just have a years long spate of ransomware targeting small businesses?

[go to top]