Supply chain β›“ Supply Chain

CenturyLink Third-Party Breach (October 2019)

πŸ“… 2019-10-01 🏒 not disclosed
Primary Source β†—

Incident Details

CenturyLink customers may have had data exposed in ‘security incident’. The company says the incident involving a third party vendor may have exposed contact information. GOLDEN VALLEY, Minn. β€” Some CenturyLink customers are receiving notifications about a recent “security incident” that may have compromised customers’ contact information. An email sent to customers states the “information security incident” involves a third-party vendor; as a result, customer information was “inadvertently made publicly accessible online,” possibly including names, addresses, phone numbers, email addresses and CenturyLink account numbers.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
not disclosed
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2019-10-01 Breach occurred
  2. 2019-10-01 Publicly disclosed