Victoria’s Secret has a cybersecurity incident ongoing, I understand a ransomware group got into the network.
Conversation
Notices
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 29-May-2025 05:29:32 JST Kevin Beaumont
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 29-May-2025 05:32:27 JST Kevin Beaumont
VPN is down. Website went down with this message:
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 29-May-2025 05:35:46 JST Kevin Beaumont
Looks like word got out amongst investors a day ago as they started selling.
One notable with the retailer incidents, they get attacker impact about two weeks before financial results go live. Obvious extortion tactic.
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 29-May-2025 05:43:03 JST Kevin Beaumont
Meanwhile, staff are busy finding out what is happening on Reddit. It’s really common in ransomware incidents for companies to realise their staff comms system doesn’t work when they have no way to log in to an out of band system.
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 29-May-2025 05:49:03 JST Kevin Beaumont
Meanwhile, there’s other Victoria’s Secrets staff on Reddit assuring customers it’s not a cybersecurity incident but a system update.
Meanwhile, their website has been updated to say security incident.
Have a ransomware/extortion comms plan.
-
Embed this notice
C-rich (crichardson@mstdn.social)'s status on Thursday, 29-May-2025 05:54:56 JST C-rich
I'm sure while everyone else is in the dark there are like 5 systems/security people in a signal chat freaking out
-
Embed this notice
Alex (alex02@cyberplace.social)'s status on Thursday, 29-May-2025 09:45:33 JST Alex
@GossiTheDog how many fucking data breach notices am I going to get in the mail?
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 03-Jun-2025 23:13:58 JST Kevin Beaumont
Victoria’s Secret has been unable to file quarterly financial statements due to their ongoing ransomware incident. https://www.bleepingcomputer.com/news/security/victorias-secret-delays-earnings-release-after-security-incident/
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 14-Jun-2025 00:04:56 JST Kevin Beaumont
Just over 2 weeks later, Victoria’s Secret say they’ve recovered from their ransomware incident. https://www.bleepingcomputer.com/news/security/victorias-secret-restores-critical-systems-after-cyberattack/
-
Embed this notice
RaulV (raulv@cyberplace.social)'s status on Saturday, 14-Jun-2025 00:36:21 JST RaulV
@GossiTheDog if true, that's impressive.
In conversation permalink
-
Embed this notice