Skip to content
This repository was archived by the owner on Apr 16, 2019. It is now read-only.
This repository was archived by the owner on Apr 16, 2019. It is now read-only.

Expected behavior w/ sites that have multiple breaches #20

@pdehaan

Description

@pdehaan

STR:

Search https://haveibeenpwned.com/PwnedWebsites for "Bell (", and you should get 2 results:

Bell (2014 breach)

In February 2014, Bell Canada suffered a data breach via the hacker collective known as NullCrew. The breach included data from multiple locations within Bell and exposed email addresses, usernames, user preferences and a number of unencrypted passwords and credit card data from 40,000 records containing just over 20,000 unique email addresses and usernames.

Breach date: 1 February 2014
Date added to HIBP: 1 February 2014
Compromised accounts: 20,902
Compromised data: Credit cards, Genders, Passwords, Usernames

Bell (2017 breach)

In May 2017, the Bell telecommunications company in Canada suffered a data breach resulting in the exposure of millions of customer records. The data was consequently leaked online with a message from the attacker stating that they were "releasing a significant portion of Bell.ca's data due to the fact that they have failed to cooperate with us" and included a threat to leak more. The impacted data included over 2 million unique email addresses and 153k survey results dating back to 2011 and 2012. There were also 162 Bell employee records with more comprehensive personal data including names, phone numbers and plain text "passcodes". Bell suffered another breach in 2014 which exposed 40k records.

Breach date: 15 May 2017
Date added to HIBP: 16 May 2017
Compromised accounts: 2,231,256
Compromised data: Email addresses, Geographic locations, IP addresses, Job titles, Names, Passwords, Phone numbers, Spoken languages, Survey results, Usernames

Both seem to be for https://www.bell.ca/

Navigate to https://www.bell.ca/ and you get notified of the most recent breach (but not the earlier breach).
Not sure if we need to build in some next/previous style navigation for sites w/ multiple breaches, or if that's just too awkward and confusing. Although the first breach only had 21k compromised accounts (versus the 2.2m compromised accounts in the 2017 breach), the first breach did include credit card numbers, so that may be valuable information to share with users. I only did a quick scan of breached domains, and I think that Bell.ca is the only one w/ multiple breaches.

bell-ca

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions