Electronics Repair Firm TSC Breached via Website Vulnerability, Personal Data Stolen and Extortion Attempt
What Happened – A 23‑year‑old suspect exploited unpatched web‑application flaws on the TSC (electronics repair) website, gaining unauthorized access to customer databases. Personal data—including names, contact details, device passcodes, bank account numbers and building access codes – was extracted and the attacker demanded payment to keep the information private.
Why It Matters for Trust & Control Assurance
- Highlights the need for continuous vulnerability scanning and timely remediation as a core control‑assurance activity.
- Demonstrates how documented remediation evidence supports audit readiness across multiple frameworks.
- Shows the importance of maintaining a defensible incident‑response trail when data exfiltration and extortion occur.
Who Is Affected – Electronics repair service providers and their customers in Latvia, Lithuania and Estonia; the broader telecommunications group (LMT) that owns TSC.
Recommended Actions
- Perform a full web‑application security assessment and remediate identified flaws.
- Deploy continuous security‑monitoring tools that capture evidence of vulnerability management for audit purposes.
- Review and update incident‑response and extortion‑handling procedures, ensuring documentation is audit‑ready.
Source: The Record
Technical Notes – Attackers used automated scanning tools to locate website vulnerabilities (specific flaw not disclosed). Data exfiltrated included personal identifiers and security‑sensitive information. No evidence of further dissemination was found.
Source: The Record