Online grocery store Rohlík.cz has told customers about a major personal data leak: an outsider gained access to part of their communication with customer support. The company said so in an email it sent to shoppers.
The leaked data includes names, email addresses and the content of conversations with the store. Depending on how customers got in touch, this may be emails, chats with uploaded files, or transcripts of phone calls with the phone number, both with human operators and with the virtual assistant. The leaked messages may also contain details customers provided themselves, such as a delivery address or an order number. Also affected are the list of items recently added to or removed from the basket, and short notes the assistant saved after conversations.
According to the company, the leak covers chats and communication from 1 April to 5 October this year, call transcripts from 28 April to 5 October, and emails from 28 June to 22 September.
“We blocked the attacker's access immediately, fixed the flaw and keep strengthening the security of our systems,” the email says. As required by law, the incident was reported to the Office for Personal Data Protection and to the national cybersecurity agency NÚKIB. Rohlík.cz spokesperson Ondřej Obergruber did not answer questions on how many customers were affected, when the company discovered the leak, whether the culprit has been found and whether the police were notified.
Erwin Brunner, Retail CEO of Rohlik Group, said the incident affected only the content of conversations with customer support. The login and payment systems were not compromised, and the e-shop and the app work without restrictions. Customers who wrote their password or bank card details in the conversation were contacted directly by the store.
The company asks customers to be cautious about messages and calls made in the name of Rohlík: fraudsters may mention goods you bought recently to sound more convincing. The store will never ask for your password or card details and does not normally require payment outside its website and app. The exceptions are payment links and emails with bank transfer details, which are sent only by prior agreement.
Do not click unexpected links in emails and text messages, and do not enter any data there. Anyone who ever wrote their password in a conversation with the store is advised to change it everywhere it is used. For questions, call customer support at 800 730 740.
Source: novinky.cz