Menu
Browse

Cyber Incident Victim: DID Electrical

Date:

Jun 2016

Location:

Ireland

Summary

An electrical goods retailer experienced a cybersecurity breach affecting 324 online customers, with unauthorized access compromising personal and financial data for 253 individuals and exposing name and address details for 71 others. The incident was detected during routine monthly monitoring, prompting immediate action to identify the source, mitigate risks, and notify impacted customers via phone and email. The company engaged relevant authorities, including data protection and law enforcement agencies, while reinforcing its commitment to customer security through third-party audits and enhanced site monitoring. No retail customers were affected by the breach.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

DID Electrical experienced a data security breach affecting its website, DID.ie, which was discovered during routine monthly checks. The company was notified late on Monday, June 27, 2016, that the site had been compromised by a sophisticated cyberattack. Forensic analysis determined the breach occurred between June 15 and June 26, 2016. The incident impacted 324 online customers exclusively, with no retail customers affected. Of these, 253 individuals had both personal/financial data and name/address details accessed, while 71 customers had only their name and address information exposed. The company identified and eliminated the unauthorized access point following detection. DID Electrical emphasized that customer security protocols triggered the discovery through scheduled monitoring activities, though the exact intrusion method wasn't disclosed publicly.

Cyber Incident Image

Upon confirmation of the breach on June 27, DID Electrical initiated containment measures overnight and throughout June 28 to assess the scope. Beginning Wednesday, June 29, the company contacted all 324 affected customers via phone and email, advising those with compromised financial data to review card statements since June 15 and report anomalies to their banks. All impacted customers were instructed to consider canceling and replacing payment cards used on the site. DID established a dedicated contact point for victim support and formally notified Ireland's Office of the Data Protection Commissioner and An Garda Síochána (national police). The retailer stated it would continue collaborating with third-party security providers to audit and reinforce website protections, maintaining coordination with authorities throughout the investigation. No operational disruptions or additional attack vectors were reported beyond the confirmed 11-day compromise window.

Sources
Sources available to members
1 source