Ferrari Done the dirty on me

Ferrari Done the dirty on me

Author
Discussion

craig511

Original Poster:

430 posts

117 months

Tuesday 21st March 2023
quotequote all
So woke up to this email today.

Does this mean some Russian gang knows where I live and I should expect to be robbed any day now for my car.
Bright side, no cards details taken though.

Dear Ferrarista,

We regret to inform you of a cyber incident at Ferrari, where a threat actor was able to access a limited number of systems in our IT environment. As part of this incident, certain data relating to our clients was exposed including names, addresses, email addresses and telephone numbers. Your data may have been included as part of this incident. However, based on our investigation, no payment details and/or bank account numbers and/or other sensitive payment information, nor details of Ferrari cars owned or ordered have been stolen.

We were recently contacted by a threat actor with a ransom demand related to such customer data. As a policy, Ferrari will not be held to ransom as paying such demands continues to fund criminal activity and enables threat actors to perpetuate their attacks. Moreover, it does not fundamentally change the data exposure.

Upon receipt of the ransom demand, we started an investigation in collaboration with a leading global third-party forensics firm and have confirmed the data’s authenticity. In addition, we informed the relevant authorities and are confident they will investigate to the full extent of the law.

We have worked with third party experts to further reinforce our systems and are confident in their resilience. We can also confirm the breach has had no impact on the operational functions of our company.

We take the confidentiality of our clients seriously and understand the significance of this incident and for this reason we have notified you promptly.

If you would like to contact Ferrari for additional information, please email us at customerservice@owners.ferrari.com or privacy@ferrari.com where a team will be able to assist you.

We would like to take this opportunity to apologise sincerely for this event and rest assured we will do everything in our power to regain your trust.

Yours sincerely,

Benedetto Vigna
Chief Executive Officer
Ferrari S.p.A.

davek_964

9,295 posts

182 months

Tuesday 21st March 2023
quotequote all
I got the same. I was actually a bit surprised Ferrari even had my details - maybe from when I registered for their owners breakdown cover I guess.

DeejRC

6,470 posts

89 months

Tuesday 21st March 2023
quotequote all
Isn’t Vigna the much trumpeted comp sci tech guy who will lead Ferrari into an all things digital and electronic future…??

Soleith

527 posts

96 months

Tuesday 21st March 2023
quotequote all
Got the same, seems unlikely although if I worked in insurance and was aware of this, anyone with a large collection of cars might see their premium go up (as if that didn't happen every year anyway rolleyes )

willy wombat

966 posts

155 months

Tuesday 21st March 2023
quotequote all
Yes, I got it too. Wasn’t sure at first whether it was real or a scam. I don’t think Maranello will have up to date bank/credit card details for me. Could be a bit of a worry if the hack extends to their UK dealers.

Taffy66

5,964 posts

109 months

Tuesday 21st March 2023
quotequote all
Same here. Did at one point think it was a scam but apparantly not.

TBCTBC

1,536 posts

96 months

Tuesday 21st March 2023
quotequote all
DeejRC said:
Isn’t Vigna the much trumpeted comp sci tech guy who will lead Ferrari into an all things digital and electronic future…??
Car tech and cyber security are very different things.

Amazed such a high-profile company have been hit by a ransomware attack in this modern age.

robemcdonald

9,133 posts

203 months

Tuesday 21st March 2023
quotequote all
They won’t have retained any information of value unless they have breached GDPR.

Ask them to clarify what data of yours they have lost.

andrew

10,090 posts

199 months

Tuesday 21st March 2023
quotequote all
same here

i look forwards to emails from ferrari regarding gdpr data retention, the right to be forgotten, holding data for legitimate purposes etc

r o n n i e

382 posts

183 months

Tuesday 21st March 2023
quotequote all
Pretty meek comm from Ferrari, I hope they get a massive fine to make them aware they should take data privacy and cyber more seriously.

The types of clients they have, physical addresses, emails, phone numbers - pretty much golden dataset from any hackers point of view.

TheDeadPrussian

879 posts

224 months

Tuesday 21st March 2023
quotequote all
Same email. Disappointing - I expect all sorts of 'spam' to arrive imminently...

craig511

Original Poster:

430 posts

117 months

Tuesday 21st March 2023
quotequote all
I have sent them this email.

Good Morning,

I was very concerned to read your email this morning about the data breach.
I am concerned that criminals now know my address and that I have a Ferrari.

Can you confirm exactly what details you hold on me and which of those are now in the hands of the "hackers".

Regards,
Craig Dow

johnnyreggae

3,001 posts

167 months

Tuesday 21st March 2023
quotequote all
Someone far more intelligent and witty than I pointed there has to be a little irony in one of their major sponsors being Kaspersky...

Bo_apex

3,026 posts

225 months

Tuesday 21st March 2023
quotequote all
Verdi ?


SteveStrange

4,927 posts

220 months

Tuesday 21st March 2023
quotequote all
craig511 said:
I have sent them this email.

Good Morning,

I was very concerned to read your email this morning about the data breach.
I am concerned that criminals now know my address and that I have a Ferrari.

Can you confirm exactly what details you hold on me and which of those are now in the hands of the "hackers".

Regards,
Craig
What's the betting...

"We are very sorry but due to GDPR regulations we are not at liberty to disclose that information."

Edited by SteveStrange on Tuesday 21st March 17:25

cgt2

7,141 posts

195 months

Tuesday 21st March 2023
quotequote all
johnnyreggae said:
Someone far more intelligent and witty than I pointed there has to be a little irony in one of their major sponsors being Kaspersky...
They were for a decade until Ferrari dumped them a year ago. The head of Kaspersky is apparently a close Putin crony.

WCZ

10,810 posts

201 months

Wednesday 22nd March 2023
quotequote all
had this too, given the nature of most ferraris owners financial profile I think this is quite bad and should expect to be bombarded with investment scams etc

it's hard to realise the scope of what people can do with this information (depending on what it is) until a lot further down the line

footsoldier

2,272 posts

199 months

Wednesday 22nd March 2023
quotequote all
Yes, I’m very pissed off about it, particularly as don’t currently have any Ferraris!
Not good at all that personal addresses have been leaked.

TBCTBC

1,536 posts

96 months

Wednesday 22nd March 2023
quotequote all
SteveStrange said:
craig511 said:
I have sent them this email.

Good Morning,

I was very concerned to read your email this morning about the data breach.
I am concerned that criminals now know my address and that I have a Ferrari.

Can you confirm exactly what details you hold on me and which of those are now in the hands of the "hackers".

Regards,
Craig
What's the betting...

"We are very sorry but due to GDPR regulations we are not at liberty to disclose that information."

Edited by SteveStrange on Tuesday 21st March 17:25
I would hope not as it's against Data Protection for companies not to tell you what data they hold about you.

Maybe all those affected should submit a Subject Access Request (SAR) to Ferrari at the same time and see what results they get back? Usually, complying with a SAR request can take some time and effort for businesses...

silentbrown

9,354 posts

123 months

Wednesday 22nd March 2023
quotequote all
craig511 said:
I was very concerned to read your email this morning about the data breach.
I am concerned that criminals now know my address and that I have a Ferrari.
Seriously? Your "garage" is public on Pistonheads, you've just published your real name, yet you're concerned about Ferrari's breach which is probably mostly just people that have just bought merchandise online,