Economy

Data-loss prevention company Cyberhaven hit by breach, statement says

By Raphael Satter and AJ Vicens

Hackers compromised an employee of the data-protection company Cyberhaven and used the worker’s access to potentially steal sensitive information from the firm’s users, the company said in a statement distributed to customers and reviewed by Reuters.     The hackers pushed a compromised version of Cyberhaven’s Chrome browser extension to the company’s users early on Wednesday, the statement said. The company urged affected customers to reset passwords and review their logs for malicious activity.    It was not immediately clear when Cyberhaven distributed the statement. The California-based company, which lists major law firms and tech companies among its customers, did not immediately respond to a request seeking comment.

Cyberhaven was not the only organization hit by the hackers, according to Jaime Blasco, cofounder of Austin, Texas-based Nudge Security.

Blasco said by examining details of the hack shared by Cyberhaven, he discovered several other Chrome extensions that had been subverted using similar code.

Browser extensions are typically used by internet users to customize their web-browsing experiences, for example by automatically applying coupons to shopping websites. In Cyberhaven’s case, the Chrome extension was used to help the company monitor and secure client data flowing across web-based applications.

Blasco said the other affected extensions included ones related to artificial intelligence and virtual private networks. He said that suggested an opportunistic effort to vacuum up sensitive data using as many compromised extensions as possible.

“I’m almost certain this is not targeted to Cyberhaven,” Blasco said. “If I had to guess, this was just random.”

This post appeared first on investing.com

    Sign up and get the scoop before anyone else—fresh updates, and secret deals, all wrapped up just for you. We're talking juicy tips, fun surprises, and invites to events you actually want to go to. Don’t just watch from the sidelines—jump in and be part of the magic!

    By signing up, you're cool with getting emails from us. Don’t worry—your info stays safe, sound, and strictly confidential. No spam, no funny business. Just the good stuff.

    The Traders Intelligence
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.