Sensitive personal and financial information of UPS Store customers was exposed in a phishing incident affecting roughly 100 local store locations between September 29, 2019, and January 13, 2020.
In a data breach notification letter to customers, The UPS Store has disclosed that an unauthorized party successfully devised a phishing scheme to gain entry into the email accounts of numerous store locations.
The breach exposed information contained within documents that customers emailed to stores for printing and related services, the San Diego-based subsidiary of UPS explained in its communication. In addition to names, this info included government-issued identification and financials, said Jenny Robinson, The UPS Store’s public relations and social media manager.
UPS did not specify in the letter precisely how many stores were involved, only saying that a “small percentage” was hit by the criminal act, which took place between approximately Sept. 29, 2019 and Jan. 13, 2020. However, Robinson clarified that the breach affected about 100 stores, less than two percent of The UPS Store’s U.S. locations.
The company said that since discovering the breach, it hired a third-party cyber firm to conduct an investigation, and it “has taken steps to further strengthen and enhance the security of systems in The UPS Store, Inc. network, including updating administrative and technical safeguards.”
The UPS Store claims there is no evidence of misuse of information, but it is nevertheless offering affected customers a 24-month membership of Experian’s IdentityWorks which provides them with credit monitoring and identity theft restoration services.
Barth, Bradley. (22 January 2020). Phishing campaign leads to UPS Store data breach. SC Media.