Cyber Incident Victim: Stone Refurb
Date:
Sep 2020
Location:
United Kingdom
Summary
A cyberattack targeting Stone Refurb, an IT company formerly known as Encore PC based in Staffordshire, compromised customer bank details, leading to unauthorized financial transactions and losses exceeding £2,300 for some individuals. The breach occurred over several months, with stolen information used to siphon funds from victims' accounts, prompting a police investigation into the data theft and associated fraudulent activities.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Stone Refurb, an IT company formerly known as Encore PC and based in Stafford, Staffordshire, experienced a cybersecurity incident between March and May 2020 where hackers compromised its website and stole customers' bank details. The breach enabled unauthorized parties to access sensitive financial information belonging to Stone Refurb's clientele. Attackers subsequently used the stolen banking credentials to initiate fraudulent transactions against affected customers during this three-month window. One confirmed victim reported losing over £2,300 through unauthorized payments made with their compromised bank details. Multiple customers came forward with similar reports of financial losses following the breach, though exact numbers of affected individuals weren't disclosed in available reports. The company's operational status during the attack period wasn't detailed, nor were technical specifics regarding the website compromise method provided in source documentation.

Staffordshire Police launched an investigation into the data breach and associated financial crimes following reports from defrauded customers. Stone Refurb's management acknowledged the incident but didn't publicly disclose remediation steps taken to secure their systems post-breach. The incident's financial impact appeared limited to customer losses rather than direct organizational costs, though reputational damage was implied through customer complaints reported in media. No threat actor attribution, ransom demands, or data extortion attempts were documented in available sources. The breach timeline concluded with police involvement by September 2020, when public reports emerged detailing customer financial losses stemming from the earlier compromise.
