Page 1 of 1

Member information was accessed by cyber attack last March

Posted: Fri Oct 14, 2022 5:58 am
by IHAQ
The Church of Jesus Christ of Latter-day Saints announced a cyber attack earlier this year was able to access the personal data of church members, employees and others.

In a release Thursday, church officials said the attack occurred in late March, but did not access donation history or banking information.

According to the church, law enforcement authorities believe there is a low possibility of the data breached during the attack could be used to harm individuals.

The church says it's working with federal authorities and third-party cybersecurity experts to determine the scope of the incident and "to mitigate possible impacts," the release said.

The attack was not announced until Thursday at the request of law enforcement.

Those impacted by the breach will be notified by church officials. Church members are being told to "remain vigilant" over their personal accounts and to change passwords.
https://www.fox13now.com/news/local-new ... -employees

Re: Member information was accessed by cyber attack last March

Posted: Fri Oct 14, 2022 6:20 am
by Everybody Wang Chung
The last time the Church had a breach this big was when DCP accessed the Church database to find private information about who was traveling to Israel with him.

viewtopic.php?t=128800

Re: Member information was accessed by cyber attack last March

Posted: Fri Oct 14, 2022 9:28 am
by IHAQ
According to a church statement on the "data incident," posted on its website today, the security breach happened in late March 2022. The breached systems contained LDS church members' basic contact information, but did not include banking history or other financial information associated with donations, we're told.

Depending on what personal information church members and others provided when they were hired or created an account, includes data such as usernames, membership record numbers, full names, gender, email addresses, birth dates, mailing addresses, phone numbers and preferred languages, according to the statement.

Also according to the church, citing federal law enforcement authorities, the break-in was part of a large-scale, state-sponsored scheme targeting organizations and governments worldwide, but "not intended to cause harm to individuals."
https://www.msn.com/en-us/news/us/mormo ... r-AA12Wujv

And from a Church statement on this incident:
At the request of these law enforcement authorities, we have not shared information about the incident as they have conducted their investigation until October 12, 2022.
We are now notifying those who may have been impacted, even where this is not legally required.
https://newsroom.churchofjesuschrist.or ... a-incident
The breached systems contain personal data, including basic contact information, of members of The Church of Jesus Christ of Latter-day Saints. The data accessed may include, if you provided it, your username, membership record number, full name, gender, email address(es), birthdate, mailing address, phone number(s), and preferred language. The affected data did not include donation history, or any banking information associated with online donations.
Can members sue the Church if the accessed data is subsequently used for identity theft?