SanrioTown.com Hacks my Take

The news was a buzz over the alleged breach of Sanrio Town  fan site.

“More than three million accounts of Hello Kitty fans were left vulnerable to theft by hackers, but there is no evidence any data has been stolen, the Hong Kong-based company hosting the data said on Tuesday.

A spokesman for Sanrio Digital, part-owned by Sanrio Co Ltd, the Japanese owner of the Hello Kitty brand, said it had fixed the hole after being notified by security researcher Chris Vickery that personal information of its users was accessible. “

A little perspective is needed; it is not as bad the media is making it.

I have a account on Sanrio town. Most any information a hacker  got from  me is general  location, name and birth date. While  is bad is not that all damming except trying  to access my characters on Hello Kitty MMORPG.  Speaking of  Hello Kitty MMORPG most of us have multiple accounts because the game was deployed regionally, for example we need to have a SEA account (i.e. hellokitty.sg) to play  the international servers.  The MMORPG has fallen  aside in popularity, many of the leaked accounts probably  are inactive  users.

While bad  I do not see it a catastrophic  problem unlike the  Target breach.  There is evidence of accounts that been compromised, mostly  spam  post on the forum but there no evidence   that finical data  fell into the hands of hackers or identity theft. Still there is  a big problem of old websites and forums  that have not been updated in years .

 

Sanrio official response