Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Disney Menu Debacle Can Teach Your Business a Lesson About Access Control

The Disney Menu Debacle Can Teach Your Business a Lesson About Access Control

The Disney brand centralizes its efforts on magic and wonder, but its parks’ food is one aspect that has recently been subject to concerning developments. A former Disney employee managed to access a menu-planning app and make changes to prices, add foul language, and change menu information. Since we live in a world with food allergies, you can already see where this is going.

The Federal Bureau of Investigation has issued this statement on the matter:

“The threat actor manipulated the allergen information on menus by adding information to some allergen notifications that indicated certain menu items were safe for individuals with peanut allergies, when in fact they could be deadly to those with peanut allergies.”

Thankfully, Disney nipped the issue in the bud before the menus were distributed, and there is no evidence that customers ever saw them. Additionally, there is no indication that these events are related to a prior event in 2023 when a death occurred at a Disney-owned restaurant due to allergens.

These Changes Could Have Been Prevented

This problem stems from a simple issue with network security: someone had permission when they shouldn’t have.

The FBI has reported that the accused individual, a former Disney employee and menu production manager named Michael Schuer, used his Disney credentials to access the menu-planning app to make changes. He was also able to use his old logins to access the app developer’s server. It’s a real case of a former employee doing despicable things with old login credentials.

What gave the “hack” away was the use of the Wingdings font. This is when Disney employees caught the issue and pulled the app. Before this, though, many employee accounts had been locked because the accused used scripts to automate logins. More than a dozen accounts exceeded their allowed login attempts, which made logging in difficult.

The complete criminal complaint offers more details about this event and the inciting attacks.

Pay Attention to User Permissions and Access Logs for Suspicious Activity

It might be a bit blunt of us to say, but this entire situation could (and should) have been prevented.

When an employee leaves your business or organization, you take away their login credentials right as they walk out the door. This is a standard and accepted best practice. It’s a part of ensuring proper access control for your business.

It’s easy to overlook a user’s profile when they leave your business, but you never know what baggage they’re leaving with—baggage that might cause them to lash out in unanticipated ways. We recommend that you practice the Principle of Least Privilege, where you only grant access as needed. There’s no reason that anyone who leaves your business should retain access to data, anyway, and the fewer entry points to your system for hackers (and other potential threats), the better.

To shore up your defenses and control access to your business, give Voyage Technology a call at 800.618.9844.

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security User Tips Efficiency Hardware Internet IT Support Malware Privacy Google Email Computer Workplace Tips Phishing IT Services Hosted Solutions Users Collaboration Mobile Device Ransomware Workplace Strategy Quick Tips Small Business Microsoft Backup Cybersecurity Passwords Communication Saving Money Data Backup Smartphone Managed Service Android VoIP Business Management Smartphones Upgrade Mobile Devices communications Disaster Recovery Data Recovery Browser Social Media Productivity Windows Microsoft Office Managed IT Services AI Current Events Remote Network Tech Term Internet of Things Artificial Intelligence Facebook Automation Cloud Computing Covid-19 Holiday Gadgets Server Managed Service Provider Information Remote Work Training Miscellaneous Outsourced IT Employee/Employer Relationship Encryption Spam Compliance Office Windows 10 Government Business Continuity Data Management Blockchain IT Support Bandwidth Windows 10 Virtualization Business Technology Wi-Fi Two-factor Authentication Data Security Mobile Office Vendor Apps Chrome Mobile Device Management BYOD Budget Gmail Apple App Employer-Employee Relationship Managed Services Voice over Internet Protocol Networking How To Avoiding Downtime BDR Office 365 Marketing HIPAA Applications WiFi Access Control Tip of the week Conferencing Computing Information Technology Hacker Analytics Website Office Tips Augmented Reality Router Storage Password Bring Your Own Device Virtual Private Network Health Big Data Help Desk Operating System Retail Healthcare Risk Management Computers Managed IT Services Cooperation Free Resource Project Management Windows 7 Patch Management Save Money Microsoft 365 Remote Monitoring End of Support Vulnerability Vendor Management Solutions Firewall Physical Security Display Printer Windows 11 The Internet of Things Paperless Office Infrastructure Monitoring 2FA Going Green Social Excel Document Management Cybercrime Remote Workers Telephone Customer Service Scam Data loss Data Privacy Virtual Desktop LiFi Wireless Technology Data storage Images 101 Telephone System Multi-Factor Authentication Outlook Robot Mobility Cost Management Money Word Humor IT Management VPN Employees Meetings Integration Sports Mouse User Tip Modem Computer Repair Mobile Security Safety Processor Administration Holidays Data Storage Smart Technology Supply Chain Video Conferencing Machine Learning Managed Services Provider Professional Services Settings Saving Time Virtual Machines Printing Wireless Content Filtering Managed IT Service Customer Relationship Management Maintenance YouTube Antivirus Downloads iPhone Cryptocurrency Licensing Hacking Presentation Vulnerabilities Entertainment Trends Supply Chain Management Alert Google Wallet Managed IT Customer Resource management FinTech File Sharing Regulations Dark Data Google Calendar Term Google Apps How To Microsoft Excel IT Maintenance Windows 8 IP Address Laptop Data Analysis Star Wars IT Assessment Gamification Flexibility Notifications Staff Value Business Intelligence Drones Organization Travel Social Networking Legislation Shortcuts Google Maps Smart Devices Ransmoware Halloween Recovery Techology Fileless Malware Digital Security Cameras Content Remote Working Wearable Technology Memory Vendors Hard Drives Comparison Google Play Be Proactive Domains Health IT Unified Threat Management Motherboard Data Breach Assessment Electronic Health Records Permissions Workforce Hacks Scary Stories Unified Threat Management Directions Videos Fun Wasting Time Threats Refrigeration Network Congestion Specifications Security Cameras Workplace Strategies Deep Learning Public Speaking Trend Micro Internet Exlporer Software as a Service Fraud Meta Lithium-ion battery User Error Microchip Entrepreneur Username Managing Costs Amazon Education Black Friday SSID Point of Sale eCommerce Database Surveillance Virtual Assistant Outsource IT Mobile Computing Search Network Management Tech Support IT Technicians Virtual Machine Environment Media Undo Monitors Cyber Monday Medical IT Best Practice Proxy Server Reviews Cookies Tactics Development Hotspot Transportation Small Businesses Buisness Websites Mirgation Hypervisor Displays Legal IT solutions PowerPoint Business Growth Shopping Nanotechnology Optimization Addiction Electronic Medical Records Language Employer/Employee Relationships Outsourcing Application SharePoint Cortana Management PCI DSS Chatbots Navigation Writing Distributed Denial of Service Workplace Alt Codes IBM Lenovo Gig Economy Screen Reader Service Level Agreement Internet Service Provider Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Downtime Server Management Regulations Compliance Private Cloud Identity Evernote Paperless Hosted Solution Co-managed IT Typing Superfish Bookmark Identity Theft Smart Tech Memes Download Net Neutrality Twitter Alerts SQL Server Technology Care Competition Knowledge Financial Data Error History Google Drive Business Communications Social Engineering Break Fix Scams Browsers Smartwatch Connectivity IT Upload Procurement Remote Computing Azure Hybrid Work 5G Unified Communications Experience Social Network Telework Cyber security Google Docs Multi-Factor Security Tech Human Resources Dark Web Cables Bitcoin Running Cable User CES Tablet IoT Communitications

Blog Archive