Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

Zero‑Day hack exposes Lego Certified Stores SA customer data

The incident exposed customer email addresses and mobile numbers.

Zero‑Day hack exposes Lego Certified Stores SA customer data

Lego Certified Stores South Africa has fallen victim to a data breach after cybercriminals exploited a zero-day vulnerability in Metabase, a third-party reporting tool. The incident, believed to have occurred on August 5, 2026, exposed the email addresses and mobile numbers of customers, though financial information and passwords remained secure.

Lego Certified Stores sent notification emails to affected customers on August 14, advising them to be cautious of phishing attempts, as they might receive an influx of unsolicited, scam or phishing emails and text messages.

The breach exposed the risks associated with third-party software vulnerabilities, highlighting the potential for attackers to exploit flaws before patches are widely deployed. Lego Certified Stores stated that they are reviewing security and access controls with service providers to enhance protections. Marsello confirmed that no further unauthorized access has been detected since the patch was applied and believes the likelihood of further breaches is "highly unlikely."

In light of the incident, customers are advised to avoid clicking suspicious links, signing into unfamiliar websites, or sharing sensitive information via email or SMS. The retailer emphasized the importance of verifying official communications directly with stores. This breach underscores the critical need for robust cybersecurity measures in retail operations, particularly when relying on external providers for customer engagement and loyalty platforms.

Meanwhile, Outa, an organization known for its anti-corruption campaigns, has been hit by a cyberattack that compromised their Meta advertising account, disrupting their promotional efforts on Facebook. The Organisation Undoing Tax Abuse CEO Wayne Duvenage stated that while the breach had limited losses, it did not impact customer names, as the attack targeted their advertising account with Meta Platforms.

Written by urgent.news from The Citizen's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at citizen.co.za →

More in Tech

IDF Unit 8200 Alumni Association uses network to drive Israeli innovation, start-ups

The event comes as artificial intelligence and other emerging technologies are reshaping the technology sector and forcing companies and professionals to adapt to new realities.

  • Over 1,200 Unit 8200 alumni to attend annual conference in Tel Aviv
  • Association focuses on innovation, adapting to new technologies
  • Companies like Zafran, Zenity, and Bank Hapoalim expected to participate

Bipartisan 'Uprising' Against Flock Cameras: a Larger Fight Against Big Tech and Surveillance?

Politico notes that over 20 local jurisdictions in America "either stopped using Flock cameras or began the process of doing so in July, according to a tracker maintained by DeFlock, an activist group…

  • Over 20 American cities halt or plan to discontinue Flock cameras in July.
  • Local officials criticize Flock cameras for not enhancing public safety.
  • Backlash against Flock cameras reflects distrust of tech giants and surveillance concerns.

More from Monday 17 August →