Ferrari Done the dirty on me

Ferrari Done the dirty on me

Author
Discussion

craig511

Original Poster:

403 posts

110 months

Tuesday 21st March 2023
quotequote all
So woke up to this email today.

Does this mean some Russian gang knows where I live and I should expect to be robbed any day now for my car.
Bright side, no cards details taken though.

Dear Ferrarista,

We regret to inform you of a cyber incident at Ferrari, where a threat actor was able to access a limited number of systems in our IT environment. As part of this incident, certain data relating to our clients was exposed including names, addresses, email addresses and telephone numbers. Your data may have been included as part of this incident. However, based on our investigation, no payment details and/or bank account numbers and/or other sensitive payment information, nor details of Ferrari cars owned or ordered have been stolen.

We were recently contacted by a threat actor with a ransom demand related to such customer data. As a policy, Ferrari will not be held to ransom as paying such demands continues to fund criminal activity and enables threat actors to perpetuate their attacks. Moreover, it does not fundamentally change the data exposure.

Upon receipt of the ransom demand, we started an investigation in collaboration with a leading global third-party forensics firm and have confirmed the data’s authenticity. In addition, we informed the relevant authorities and are confident they will investigate to the full extent of the law.

We have worked with third party experts to further reinforce our systems and are confident in their resilience. We can also confirm the breach has had no impact on the operational functions of our company.

We take the confidentiality of our clients seriously and understand the significance of this incident and for this reason we have notified you promptly.

If you would like to contact Ferrari for additional information, please email us at customerservice@owners.ferrari.com or privacy@ferrari.com where a team will be able to assist you.

We would like to take this opportunity to apologise sincerely for this event and rest assured we will do everything in our power to regain your trust.

Yours sincerely,

Benedetto Vigna
Chief Executive Officer
Ferrari S.p.A.

davek_964

8,803 posts

175 months

Tuesday 21st March 2023
quotequote all
I got the same. I was actually a bit surprised Ferrari even had my details - maybe from when I registered for their owners breakdown cover I guess.

DeejRC

5,772 posts

82 months

Tuesday 21st March 2023
quotequote all
Isn’t Vigna the much trumpeted comp sci tech guy who will lead Ferrari into an all things digital and electronic future…??

Soleith

466 posts

89 months

Tuesday 21st March 2023
quotequote all
Got the same, seems unlikely although if I worked in insurance and was aware of this, anyone with a large collection of cars might see their premium go up (as if that didn't happen every year anyway rolleyes )

willy wombat

912 posts

148 months

Tuesday 21st March 2023
quotequote all
Yes, I got it too. Wasn’t sure at first whether it was real or a scam. I don’t think Maranello will have up to date bank/credit card details for me. Could be a bit of a worry if the hack extends to their UK dealers.

Taffy66

5,964 posts

102 months

Tuesday 21st March 2023
quotequote all
Same here. Did at one point think it was a scam but apparantly not.

TBCTBC

1,492 posts

89 months

Tuesday 21st March 2023
quotequote all
DeejRC said:
Isn’t Vigna the much trumpeted comp sci tech guy who will lead Ferrari into an all things digital and electronic future…??
Car tech and cyber security are very different things.

Amazed such a high-profile company have been hit by a ransomware attack in this modern age.

robemcdonald

8,759 posts

196 months

Tuesday 21st March 2023
quotequote all
They won’t have retained any information of value unless they have breached GDPR.

Ask them to clarify what data of yours they have lost.

andrew

9,967 posts

192 months

Tuesday 21st March 2023
quotequote all
same here

i look forwards to emails from ferrari regarding gdpr data retention, the right to be forgotten, holding data for legitimate purposes etc

r o n n i e

365 posts

176 months

Tuesday 21st March 2023
quotequote all
Pretty meek comm from Ferrari, I hope they get a massive fine to make them aware they should take data privacy and cyber more seriously.

The types of clients they have, physical addresses, emails, phone numbers - pretty much golden dataset from any hackers point of view.

TheDeadPrussian

854 posts

217 months

Tuesday 21st March 2023
quotequote all
Same email. Disappointing - I expect all sorts of 'spam' to arrive imminently...

craig511

Original Poster:

403 posts

110 months

Tuesday 21st March 2023
quotequote all
I have sent them this email.

Good Morning,

I was very concerned to read your email this morning about the data breach.
I am concerned that criminals now know my address and that I have a Ferrari.

Can you confirm exactly what details you hold on me and which of those are now in the hands of the "hackers".

Regards,
Craig Dow

johnnyreggae

2,935 posts

160 months

Tuesday 21st March 2023
quotequote all
Someone far more intelligent and witty than I pointed there has to be a little irony in one of their major sponsors being Kaspersky...

Bo_apex

2,524 posts

218 months

Tuesday 21st March 2023
quotequote all
Verdi ?


SteveStrange

3,786 posts

213 months

Tuesday 21st March 2023
quotequote all
craig511 said:
I have sent them this email.

Good Morning,

I was very concerned to read your email this morning about the data breach.
I am concerned that criminals now know my address and that I have a Ferrari.

Can you confirm exactly what details you hold on me and which of those are now in the hands of the "hackers".

Regards,
Craig
What's the betting...

"We are very sorry but due to GDPR regulations we are not at liberty to disclose that information."

Edited by SteveStrange on Tuesday 21st March 17:25

cgt2

7,099 posts

188 months

Tuesday 21st March 2023
quotequote all
johnnyreggae said:
Someone far more intelligent and witty than I pointed there has to be a little irony in one of their major sponsors being Kaspersky...
They were for a decade until Ferrari dumped them a year ago. The head of Kaspersky is apparently a close Putin crony.

WCZ

10,513 posts

194 months

Wednesday 22nd March 2023
quotequote all
had this too, given the nature of most ferraris owners financial profile I think this is quite bad and should expect to be bombarded with investment scams etc

it's hard to realise the scope of what people can do with this information (depending on what it is) until a lot further down the line

footsoldier

2,258 posts

192 months

Wednesday 22nd March 2023
quotequote all
Yes, I’m very pissed off about it, particularly as don’t currently have any Ferraris!
Not good at all that personal addresses have been leaked.

TBCTBC

1,492 posts

89 months

Wednesday 22nd March 2023
quotequote all
SteveStrange said:
craig511 said:
I have sent them this email.

Good Morning,

I was very concerned to read your email this morning about the data breach.
I am concerned that criminals now know my address and that I have a Ferrari.

Can you confirm exactly what details you hold on me and which of those are now in the hands of the "hackers".

Regards,
Craig
What's the betting...

"We are very sorry but due to GDPR regulations we are not at liberty to disclose that information."

Edited by SteveStrange on Tuesday 21st March 17:25
I would hope not as it's against Data Protection for companies not to tell you what data they hold about you.

Maybe all those affected should submit a Subject Access Request (SAR) to Ferrari at the same time and see what results they get back? Usually, complying with a SAR request can take some time and effort for businesses...

silentbrown

8,818 posts

116 months

Wednesday 22nd March 2023
quotequote all
craig511 said:
I was very concerned to read your email this morning about the data breach.
I am concerned that criminals now know my address and that I have a Ferrari.
Seriously? Your "garage" is public on Pistonheads, you've just published your real name, yet you're concerned about Ferrari's breach which is probably mostly just people that have just bought merchandise online,