Menu
Browse

Cyber Incident Victim: Stone Refurb

Date:

Sep 2020

Location:

United Kingdom

Summary

A cyberattack targeting Stone Refurb, an IT company formerly known as Encore PC based in Staffordshire, compromised customer bank details, leading to unauthorized financial transactions and losses exceeding £2,300 for some individuals. The breach occurred over several months, with stolen information used to siphon funds from victims' accounts, prompting a police investigation into the data theft and associated fraudulent activities.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Stone Refurb, an IT company formerly known as Encore PC and based in Stafford, Staffordshire, experienced a cybersecurity incident between March and May 2020 where hackers compromised its website and stole customers' bank details. The breach enabled unauthorized parties to access sensitive financial information belonging to Stone Refurb's clientele. Attackers subsequently used the stolen banking credentials to initiate fraudulent transactions against affected customers during this three-month window. One confirmed victim reported losing over £2,300 through unauthorized payments made with their compromised bank details. Multiple customers came forward with similar reports of financial losses following the breach, though exact numbers of affected individuals weren't disclosed in available reports. The company's operational status during the attack period wasn't detailed, nor were technical specifics regarding the website compromise method provided in source documentation.

Cyber Incident Image

Staffordshire Police launched an investigation into the data breach and associated financial crimes following reports from defrauded customers. Stone Refurb's management acknowledged the incident but didn't publicly disclose remediation steps taken to secure their systems post-breach. The incident's financial impact appeared limited to customer losses rather than direct organizational costs, though reputational damage was implied through customer complaints reported in media. No threat actor attribution, ransom demands, or data extortion attempts were documented in available sources. The breach timeline concluded with police involvement by September 2020, when public reports emerged detailing customer financial losses stemming from the earlier compromise.

Sources
Sources available to members
1 source