logo
How a Cyberattack at a Company You've Never Heard of Nearly Derailed My Anniversary Carrot Cake

How a Cyberattack at a Company You've Never Heard of Nearly Derailed My Anniversary Carrot Cake

CNET2 days ago

Every year since we got married, my husband and I have celebrated our anniversary with a carrot cake. Some years it was from the amazing bakery in our old neighborhood, while others it was a questionably fresh effort picked up at a train station shop on the way home from the office, but often I would bake my own.
The funny thing is, neither of us really likes carrot cake. It just somehow ended up being the top layer of our wedding cake, so we have one every year. That's tradition for you.
This year, for our 20th anniversary, I had my mind set on baking. Throwing together a three-layer cake in the middle of a busy work day may sound daunting, but it's well within my skill set. And I was armed with a new recipe and a giant bag of carrots. I just needed a few key ingredients.
Always the procrastinator, I started filling my online shopping cart the night before. I also needed the makings for a fairly fancy dinner, as well as my regular groceries for the week. But to my surprise, the virtual shelves of my NYC-area Whole Foods were uncharacteristically bare. It brought back memories of the pandemic. Basic store-brand items that I buy every week like tortillas, pizza sauce and cheese were out of stock. And so were the raisins and cream cheese I needed for my cake.
Slightly panicked at that point, I remembered the news of a cyberattack at one of Whole Foods' major suppliers a few days before that forced it to take its systems offline. Some experts had speculated that it could affect store supplies, but I hadn't expected the impact to be so quick and so significant.
Cybercriminals have long-targeted retail companies, along with those that supply them, for both their money and data. They know that if they're successful in breaching those systems, retailers will likely pay to make the problem go away.
That said, this year has been particularly bad for cyberattacks on retailers, says Max Vetter, vice president of cyber at Immersive, which specializes in training companies for how to deal with online threats.
So far this year, retailers including Adidas, Marks & Spencer, Harrods, Cartier, Victoria's Secret and North Face have all sustained cyberattacks that affected their operations. And while Whole Foods' supplier, United Natural Foods, isn't technically a retailer, the impact of the attack on it continues to be felt by consumers.
"This is not normal," says Vetter, who worked in British law enforcement and as an intelligence analyst before joining Immersive. "We haven't seen this in retail and food any other year that I can remember."
For companies, that can mean millions in lost sales and unexpected costs related to dealing with attacks. In the case of United Natural Foods, its stock price tumbled on the news, dropping about 20% over the past week.
For most consumers, it means aggravation more than anything. In my case, I was able to find my raisins and cream cheese at a brick-and-mortar store, but I paid more than I wanted to and it took time I didn't have out of my day.
But for some shoppers, the consequence can be more dire. If the only store in a remote town can't restock its shelves, that can mean no food for people without the means to get to another one.
"That's something definitely to be aware of and I don't think we've thought enough about this," Vetter said.
Why attackers attack
When online attackers go after retailers, they're looking for two things: money and data.
If they're able to lock a company's system up with ransomware, it's likely that the company will pay up to get its systems back up and running. The longer they're down, the more money the company will lose. On top of that, blank websites just aren't a great look for retailers. Shoppers who fear for their data may choose to shop somewhere else.
And the attackers are after their data. Credit card numbers and online account credentials can obviously be sold in bulk to fraudsters, but so can less obvious customer data like names, emails, mailing addresses and phone numbers.
Rewards points tied to loyalty programs run by food and restaurant companies are also as good as cash to cybercriminals, says Rob Ainscough, Silverfort's chief identity security advisor for Europe, the Middle East and Africa.
Double extortion attempts, where attackers lock a company's system down with ransomware and then steal and threaten to release a company's customer data, have also become common, he says.
"So if they don't get paid on the ransom, they're going to try to get paid on the data," said Ainscough, who spent a decade heading online security for a large multinational retailer before joining Silverfort.
Arguably, that's what attackers are going for when they target any kind of company, so it remains unclear why they seem so fond of retailers this year.
Vetter says it could be because retailers are seen as easy targets. While banks and other financial institutions have long boasted strong online security practices, and industrial companies have also boosted their defenses in recent years in the wake of high-profile attacks such as the 2021 ransoming of Colonial Pipeline, retailers have been slower to do the same.
It can be tough, he says, for security officials at companies that aren't particularly tech-focused to get the resources they need from executives who may just see cybersecurity as a cost. Unlike other kinds of flashier technology, when cyberdefenses work, they go largely unnoticed.
"I think retail is one of those areas that probably just didn't think it was much of a problem," Vetter said, referring to the possibility of cyberattacks. "Obviously, I think they do now."
Supply chain dangers
It's one thing if a cyberattack keeps you from ordering some new clothes or jewelry. It's another when it keeps you from putting food on your table.
The attack on United Natural Foods and the subsequent shortages at many Whole Foods stores brought to light exactly how fragile the food supply chain can be. But Whole Foods, with its affluent customer base and locations in big cities and suburban areas, isn't the only store its customers have to shop at.
That's not true for many of the members of the Co-Operative Group. It's a UK-based chain of stores that are owned by its members and serve more than 17 million people in the UK, many of them retirees who live in remote areas and may not be able to drive.
For some, they're the only stores in places like small villages on islands off the coast of Scotland where people might need to get on a ferry to shop somewhere else, Vetter says. So when Co-op got hit with a cyberattack last month, it had a lot of people panicking.
After detecting the breach, Co-op quickly took its systems offline, possibly preventing them from becoming infected with ransomware. But the disruptions to its supply chain and logistics operations had a huge effect on deliveries to stores, whose shelves were quickly left bare.
Co-op was left scrambling to prioritize and figure out what stores absolutely needed to be resupplied, despite the group's limited operations.
"There's a real human risk there of starvation," Vetter said. "You don't think of a relatively small store as critical to national infrastructure, but for some people it is."

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Go green and grab a refurbished MacBook Pro for under $500
Go green and grab a refurbished MacBook Pro for under $500

Yahoo

time5 minutes ago

  • Yahoo

Go green and grab a refurbished MacBook Pro for under $500

The following content is brought to you by Mashable partners. If you buy a product featured here, we may earn an affiliate commission or other compensation. TL;DR: Upgrade your laptop with a refurbished Apple MacBook Pro (i5 2GHz, 16GB RAM, 512GB SSD) for just $449.99 (reg. $1,799) while supplies last. Opens in a new window Credit: Apple Refurbished Apple MacBook Pro (i5 2GHz, 16GB RAM, 512GB SSD) $449.99 $1,799 Save $1,349.01 Get Deal Is your current laptop slowing you down? This refurbished MacBook Pro is ready to get you back up to speed, offering a powerful refresh with 10 hours of battery life. And right now, you can bring it home for just $449.99 (reg. $1,799). If you've been holding off on purchasing a MacBook Pro due to budget restraints, this model is $1,350 off and ready to upgrade your summer. This dependable device is powered by a 10th gen Intel Core i5 processor with a 2GHz base speed and 16GB of RAM, so it's ready to keep up with all of your multitasking. Despite having all this power and a 13.3-inch display, this MacBook Pro weighs in at just 3.1 pounds, making it easy to take on the go. That display includes Apple's True Tone Technology, which automatically adjusts your screen to help reduce eye strain. It also features a 512 GB SSD, allowing you to store important files locally. With 10 hours of battery life, you won't have to be tethered to an electrical outlet. You can take advantage of features like the Magic Keyboard, a Touch Bar with convenient shortcuts, and four Thunderbolt 3 ports for your charging and connectivity needs. Wondering why you're getting such a big discount? This device has a grade A refurbished rating, which means it will arrive in near-mint condition with virtually no signs of prior use, while you save $1,350. Bring home your own MacBook Pro for just $449.99 (reg. $1,799) while supplies last. StackSocial prices subject to change.

Shopify (SHOP) Stock Slides as Market Rises: Facts to Know Before You Trade
Shopify (SHOP) Stock Slides as Market Rises: Facts to Know Before You Trade

Yahoo

time6 minutes ago

  • Yahoo

Shopify (SHOP) Stock Slides as Market Rises: Facts to Know Before You Trade

Shopify (SHOP) closed the most recent trading day at $109.21, moving -4.31% from the previous trading session. The stock fell short of the S&P 500, which registered a gain of 0.38% for the day. Elsewhere, the Dow saw an upswing of 0.24%, while the tech-heavy Nasdaq appreciated by 0.24%. Shares of the cloud-based commerce company witnessed a gain of 2.4% over the previous month, trailing the performance of the Computer and Technology sector with its gain of 11.61%, and the S&P 500's gain of 6.6%. Market participants will be closely following the financial results of Shopify in its upcoming release. The company's upcoming EPS is projected at $0.28, signifying a 7.69% increase compared to the same quarter of the previous year. Our most recent consensus estimate is calling for quarterly revenue of $2.54 billion, up 24.29% from the year-ago period. For the entire fiscal year, the Zacks Consensus Estimates are projecting earnings of $1.4 per share and a revenue of $10.85 billion, representing changes of +7.69% and +22.24%, respectively, from the prior year. It is also important to note the recent changes to analyst estimates for Shopify. Such recent modifications usually signify the changing landscape of near-term business trends. As such, positive estimate revisions reflect analyst optimism about the business and profitability. Research indicates that these estimate revisions are directly correlated with near-term share price momentum. We developed the Zacks Rank to capitalize on this phenomenon. Our system takes these estimate changes into account and delivers a clear, actionable rating model. The Zacks Rank system, stretching from #1 (Strong Buy) to #5 (Strong Sell), has a noteworthy track record of outperforming, validated by third-party audits, with stocks rated #1 producing an average annual return of +25% since the year 1988. Over the past month, the Zacks Consensus EPS estimate remained stagnant. Shopify currently has a Zacks Rank of #3 (Hold). Looking at valuation, Shopify is presently trading at a Forward P/E ratio of 81.67. This represents a premium compared to its industry average Forward P/E of 18.8. It is also worth noting that SHOP currently has a PEG ratio of 4.22. This metric is used similarly to the famous P/E ratio, but the PEG ratio also takes into account the stock's expected earnings growth rate. The Internet - Services industry had an average PEG ratio of 1.38 as trading concluded yesterday. The Internet - Services industry is part of the Computer and Technology sector. With its current Zacks Industry Rank of 140, this industry ranks in the bottom 44% of all industries, numbering over 250. The Zacks Industry Rank evaluates the power of our distinct industry groups by determining the average Zacks Rank of the individual stocks forming the groups. Our research shows that the top 50% rated industries outperform the bottom half by a factor of 2 to 1. Be sure to use to monitor all these stock-influencing metrics, and more, throughout the forthcoming trading sessions. Want the latest recommendations from Zacks Investment Research? Today, you can download 7 Best Stocks for the Next 30 Days. Click to get this free report Shopify Inc. (SHOP) : Free Stock Analysis Report This article originally published on Zacks Investment Research ( Zacks Investment Research

Prince Harry & Meghan Markle Lose 4 Staffers Amid Latest Shuffle
Prince Harry & Meghan Markle Lose 4 Staffers Amid Latest Shuffle

Yahoo

time8 minutes ago

  • Yahoo

Prince Harry & Meghan Markle Lose 4 Staffers Amid Latest Shuffle

Prince Harry and Meghan Markle are undergoing another internal shuffle within their team. Four of the Duke and Duchess of Sussex's employees have recently parted ways with the royal couple after Meredith Maines (Google, Hulu, American Idol) came on as their first chief communications officer earlier this year, Deadline can confirm. More from Deadline Meghan Markle Recruits Bill Gates' Ex-Assistant As Chief Of Staff To Oversee 'Dynamic Period Of Growth' Kyle Boulia Named Deputy Press Secretary For Duke & Duchess Of Sussex Following UTA Exit Prince Harry Videoed On Doorbell Camera "Looking For Friend At Wrong House" During UK Visit Among the departed staffers are LA-based deputy press secretary Kyle Boulia and UK press officer Charlie Gipson, both of whom were hired last March. These four are the most recent exits from their team. Since stepping back from royal duties, reports suggest at least 22 people have left their team, with six in the last two months. Harry and Meghan previously took on Emily Robinson (Netflix) as their director of communications, along with a team from Method Communications. Markle also hired Bill Gates' former assistant Sarah Fosmo as her first chief of staff last month. Last year, their global press secretary and head of communications Ashley Hansen departed to launch her own firm, bringing Harry and Meghan on as clients. Meanwhile, the Duke of Sussex's chief of staff Josh Kettler also exited following a trial period. Best of Deadline 2025 TV Series Renewals: Photo Gallery 2025 TV Cancellations: Photo Gallery 2025-26 Awards Season Calendar: Dates For Tonys, Emmys, Oscars & More

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store