Cisco Says Vegas Conference Attendees' Information Was Leaked
Julie188 writes "Thousands of people got a nasty e-mail this morning from Cisco. The company was warning people that its attendee registration database for its Cisco Live 2010 event was hacked. Cisco Live 2010 is the company's annual user conference, held last week in Las Vegas with an estimated 18,000 in attendance. If it's not embarrassing enough for a company that sells security gear to get hacked, the e-mail also went out to people who didn't register and didn't attend the event. That raises questions about exactly what database was pried open and how bad the damage is. Cisco's e-mail said the hole was quickly closed and only business-card type information was exposed."
the e-mail also went out to people who didn't register and didn't attend the event.
That's even more embarassing than a security breach -- it's a routing error. From Cisco.
#fuckbeta #iamslashdot #dicemustdie
We hope you have returned home safely and are back into your normal routine after a busy week at Cisco Live 2010.
We are contacting you because on the final afternoon of Cisco Live, one of our vendors identified an unexpected attempt to access attendee information through ciscolive2010.com. The ability to access this information was quickly removed, but not before some conference listings were accessed.
Cisco Live takes the security of attendee information very seriously and immediately elevated this matter to our chief security officer. His team completed a thorough review and as a result we believe your registration information – specifically your Cisco Live badge number, name, title, company address and email address– was accessed. No other information was available or accessed.
Although these details are commonly accessed by our World of Solutions partners and often freely provided by Cisco Live attendees, we felt it was our responsibility to inform you as quickly as possible. As we cannot yet confirm the information was accessed by an authorized Cisco Live partner, we encourage you to consider the appropriate precautions to protect against any unwanted email.
Please accept our apologies for any inconvenience that may result and feel free to contact us directly at support@ciscolive2010.com if you have any additional questions or information.
We hope you enjoyed your Cisco Live experience and we look forward to welcoming you to Las Vegas in 2011.
Regards,
They could stay quiet about it.
Can someone paste the header to see if the email from "Cisco" is legit or fraudulent? I attended Cisco Live and received no such email, and people who didn't attend received the mail, the Cisco Live team has a database of everyone who registered for the event so if the email was legit I would have expected to see it get sent to the correct audience?
Losing credit card numbers or bank account numbers for large groups is bad; losing email addresses is not.
Losing email addresses is not AS BAD as losing more sensitive information, but it is still not good. I, for one, wouldn't be happy about that information being exposed.
Cisco collected that information so they and their "partners" could spam you: "... we believe your registration information - specifically your Cisco Live badge number, name, title, company address and email address- was accessed. No other information was available or accessed. Although these details are commonly accessed by our World of Solutions partners".... Their "partner locator" finds 16601 partners in the United States, 3241 in China, 998 in Russia, 427 in Romania. 330 in Nigeria, and 12 in Afghanistan. So just about anybody who wants that data could get it.
They're just irked that someone who didn't pay for their mailing list might spam you.
I agree. I can't even imagine what would happen if anyone found out I had attended a Cisco conference. I would be a social pariah. My children wouldn't be able to look me in the eye. My wife would leave me. The dog would run away. Even my cats would look at me even more disdainfully than they usually do.