Menu
Browse

Cyber Incident Victim: LaCie

Date:

Mar 2013

Location:

France

Summary

LaCie experienced a significant security breach affecting nearly all customers who made purchases on its website over a year-long period, attributed to malware exploiting vulnerabilities in Adobe's ColdFusion software. The attackers accessed sensitive customer data including names, addresses, email addresses, payment card details, and account credentials. The company was alerted by the FBI and subsequently required password resets, initiated customer notifications, engaged a forensic firm for investigation, and temporarily closed its online store to implement enhanced security measures. The breach was linked to broader compromises targeting multiple online retailers through the same Adobe software flaws.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

LaCie, a French hardware company in the process of merging with Seagate, disclosed a significant security breach on April 15, 2014, following an FBI notification on March 19, 2014. The company confirmed that malware had infiltrated its website, compromising transactions processed between March 27, 2013, and March 10, 2014, placing virtually all customers who shopped online during this period at risk. Security researcher Brian Krebs linked the breach to attackers exploiting vulnerabilities in Adobe’s ColdFusion software, a vector previously used in intrusions targeting dozens of online retailers. This connection referenced Adobe’s own 2013 breach, which initially impacted 3 million accounts but was later revised to 38 million, exposing source code for ColdFusion and other products; Adobe had patched these vulnerabilities prior to LaCie’s disclosure. The attackers accessed customer names, physical addresses, email addresses, payment card numbers, card expiration dates, usernames, and passwords through the compromised web storefront.

Cyber Incident Image

LaCie initiated customer notifications via mailed letters starting April 11, 2014, and mandated password resets for affected accounts. The company collaborated with the FBI and an unnamed forensic investigation firm to analyze the breach and implement enhanced security measures. As an immediate containment action, LaCie shut down its online store indefinitely to secure its payment infrastructure. No specific number of impacted customers was disclosed, but the company emphasized the broad scope, acknowledging all transactions during the 11.5-month window were potentially exposed. The breach highlighted systemic risks associated with third-party software vulnerabilities, particularly given the attackers’ use of previously identified ColdFusion exploits to infiltrate multiple e-commerce platforms. LaCie’s public acknowledgment followed Krebs’ earlier reporting on the intrusion, underscoring the prolonged duration between initial compromise and detection.

Sources
Sources available to members
2 sources