Security News > 2021 > November > California Pizza Kitchen Serves Up Employee SSNs in Data Breach
California Pizza Kitchen served up more than tasty meals recently after a data breach exposed the names and Social Security numbers of more than 100,000 current and former employees.
The "External system breach" occurred on Sept. 15 at the popular U.S. pizza chain and affected 103,767 people, according to a Data Breach Notification posted on the website of the Maine Attorney General.
The company is currently reviewing existing security policies and has implemented additional measures - including safeguards and employee training - to help prevent similar incidents going forward, according to the notice.
One security professional noted that employee training is a key element of helping to avoid breaches like this, which are all too common at organizations that have sensitive data on their networks but typically employ people without specific knowledge of how security breaches can occur.
"Every business like California Pizza Kitchen possesses valuable PII data which makes them a prime target for attackers," Al-Khalidi, co-founder and co-CEO of security firm Axiad, wrote in an email to Threatpost.
Employee training can't replace a solid technology-based security posture that errs on the side of paranoia in preventing cyber-attacks, Lopez told Threatpost via email.
News URL
https://threatpost.com/california-pizza-kitchen-employee-ssns-data-breach/176478/
Related news
- Rhode Island confirms data breach after Brain Cipher ransomware attack (source)
- Texas Tech University System data breach impacts 1.4 million patients (source)
- Ireland fines Meta $264 million over 2018 Facebook data breach (source)
- New fake Ledger data breach emails try to steal crypto wallets (source)
- Meta Fined €251 Million for 2018 Data Breach Impacting 29 Million Accounts (source)
- 46% of financial institutions had a data breach in the past 24 months (source)
- UN aviation agency investigating possible data breach (source)
- Washington state sues T-Mobile over 2021 data breach security failures (source)
- Largest US addiction treatment provider notifies patients of data breach (source)
- STIIIZY data breach exposes cannabis buyers’ IDs and purchases (source)