Live data from Hacker News

OnePlus Hit by Data Breach

forums.oneplus.com

1–10 of 53 posts

Re: OnePlus Hit by Data Breach

#2
Ok, the breach shouldn't have been possible. But at least, when a breach does happen, this is a good example of how a company should communicate. First assessing who/what has been impacted, informing affected customers and a clear (could use some more detail) public statement. Of course, some laws like GDPR force them to do this, but in reality we still see enough big corporations handle this way worse on an almost daily basis.

Re: OnePlus Hit by Data Breach

#3
i get that use of the passive voice makes things more PR friendly, but the cynic in me feels that these should really be in the active voice:

- Intruders breached OnePlus systems

- On X date, unauthorized intruders accessed data in our systems

etc.

Re: OnePlus Hit by Data Breach

#4
When I opened the link, I was hit with a modal for a raffle. I understand that it's the site's normal behavior and there's no way to single out a single thread (probably), but readers of this thread probably don't want to hand over data for a raffle.

Re: OnePlus Hit by Data Breach

#6
My information got leaked by OnePlus last year and I got hit with some minor credit card fraud. At least I didn't get hit this time... One would think that companies would step up their security after a breach.

Re: OnePlus Hit by Data Breach

#7
> But certain users' name, contact number, email and shipping address may have been exposed. Impacted users may receive spam and phishing emails as a result of this incident.

Those are personally identifiable information that has been breached. So the attackers can identify me with my shipping address, email and my name.

Minus One Hundred Thousand from me.

Re: OnePlus Hit by Data Breach

#9
post #2

Ok, the breach shouldn't have been possible. But at least, when a breach does happen, this is a good example of how a company should communicate. First assessing who/what has been impacted, informing affected customers and a clear (could use some more detail) public statement. Of course, some laws like GDPR force them to do this, but in reality we still see enough big corporations handle this way worse on an almost d…

As an example of an initial notification, maybe. However, that has to be followed up with a full post mortem. I see zero information about what happened or what steps are being taken.
Post reply on HN