Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Disney Menu Debacle Can Teach Your Business a Lesson About Access Control

The Disney Menu Debacle Can Teach Your Business a Lesson About Access Control

The Disney brand centralizes its efforts on magic and wonder, but its parks’ food is one aspect that has recently been subject to concerning developments. A former Disney employee managed to access a menu-planning app and make changes to prices, add foul language, and change menu information. Since we live in a world with food allergies, you can already see where this is going.

The Federal Bureau of Investigation has issued this statement on the matter:

“The threat actor manipulated the allergen information on menus by adding information to some allergen notifications that indicated certain menu items were safe for individuals with peanut allergies, when in fact they could be deadly to those with peanut allergies.”

Thankfully, Disney nipped the issue in the bud before the menus were distributed, and there is no evidence that customers ever saw them. Additionally, there is no indication that these events are related to a prior event in 2023 when a death occurred at a Disney-owned restaurant due to allergens.

These Changes Could Have Been Prevented

This problem stems from a simple issue with network security: someone had permission when they shouldn’t have.

The FBI has reported that the accused individual, a former Disney employee and menu production manager named Michael Schuer, used his Disney credentials to access the menu-planning app to make changes. He was also able to use his old logins to access the app developer’s server. It’s a real case of a former employee doing despicable things with old login credentials.

What gave the “hack” away was the use of the Wingdings font. This is when Disney employees caught the issue and pulled the app. Before this, though, many employee accounts had been locked because the accused used scripts to automate logins. More than a dozen accounts exceeded their allowed login attempts, which made logging in difficult.

The complete criminal complaint offers more details about this event and the inciting attacks.

Pay Attention to User Permissions and Access Logs for Suspicious Activity

It might be a bit blunt of us to say, but this entire situation could (and should) have been prevented.

When an employee leaves your business or organization, you take away their login credentials right as they walk out the door. This is a standard and accepted best practice. It’s a part of ensuring proper access control for your business.

It’s easy to overlook a user’s profile when they leave your business, but you never know what baggage they’re leaving with—baggage that might cause them to lash out in unanticipated ways. We recommend that you practice the Principle of Least Privilege, where you only grant access as needed. There’s no reason that anyone who leaves your business should retain access to data, anyway, and the fewer entry points to your system for hackers (and other potential threats), the better.

To shore up your defenses and control access to your business, give Voyage Technology a call at 800.618.9844.

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Hackers Cloud Efficiency Hardware Network Security User Tips Internet IT Services Malware Phishing IT Support Workplace Tips Privacy Google Email Computer Workplace Strategy Hosted Solutions Collaboration Backup Small Business Users Ransomware AI Managed Service Mobile Device Productivity Microsoft Passwords Quick Tips Saving Money Communication Cybersecurity Smartphone Data Backup Data Recovery Disaster Recovery Android VoIP Upgrade Smartphones Business Management Mobile Devices communications Windows Social Media Browser Managed IT Services Microsoft Office Current Events Network Tech Term Remote Internet of Things Miscellaneous Information Holiday Artificial Intelligence Facebook Automation Gadgets Compliance Cloud Computing Covid-19 Training Outsourced IT Server Managed Service Provider IT Support Remote Work Encryption Spam Employee/Employer Relationship Office Windows 10 Government Data Management Business Continuity Wi-Fi Blockchain Vendor Windows 10 Bandwidth Business Technology Virtualization Managed Services Apps Data Security Two-factor Authentication Mobile Office Voice over Internet Protocol App Employer-Employee Relationship Networking BYOD Mobile Device Management Chrome Gmail Budget WiFi Tip of the week Apple Conferencing Managed IT Services How To Computing Hacker BDR Information Technology Avoiding Downtime Marketing Office 365 HIPAA Physical Security Applications Access Control Password Retail Healthcare Operating System Computers Risk Management Website Router Analytics Office Tips Augmented Reality Virtual Private Network Storage Health 2FA Help Desk Bring Your Own Device Big Data Document Management Social Remote Workers Managed IT Service Going Green Telephone Scam Data loss Customer Service Cybercrime Cooperation Free Resource Project Management Windows 7 Patch Management Save Money Microsoft 365 Remote Monitoring End of Support Vulnerability Vendor Management Solutions Firewall Display Printer Paperless Office Windows 11 Infrastructure Monitoring The Internet of Things Excel Saving Time Virtual Machines Professional Services Maintenance Customer Relationship Management Downloads Antivirus iPhone Settings Wireless Printing Licensing Content Filtering Entertainment Hacking Vulnerabilities YouTube Presentation Data Privacy Images 101 Cryptocurrency Wireless Technology Multi-Factor Authentication Robot Mobility Telephone System Cost Management Virtual Desktop Data storage LiFi Word IT Management Outlook Meetings VPN Employees Integration Money Humor Modem User Tip Processor Computer Repair Mobile Security Safety Holidays Sports Data Storage Mouse Smart Technology Supply Chain Video Conferencing Machine Learning Managed Services Provider Administration Lenovo Gig Economy Screen Reader Application Best Practice Writing Distributed Denial of Service Workplace Service Level Agreement Internet Service Provider Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Buisness Private Cloud Identity IT solutions Evernote Paperless Server Management Regulations Compliance IBM Legal Superfish Bookmark Identity Theft Smart Tech Memes Business Growth Co-managed IT Download Net Neutrality Twitter Alerts SQL Server Technology Care Error History Business Communications Cortana Financial Data Browsers Smartwatch Connectivity IT Alt Codes Social Engineering Break Fix Scams Downtime Upload Procurement Competition Remote Computing Azure Hybrid Work Cyber security Hosted Solution Multi-Factor Security Tech Human Resources Social Network Telework CES Tablet IoT Communitications Typing Dark Web Cables Trends Supply Chain Management Alert Google Drive File Sharing Regulations User Dark Data Google Calendar Term Google Apps Knowledge Managed IT Customer Resource management FinTech Data Analysis Star Wars IT Assessment How To Microsoft Excel IT Maintenance 5G Gamification Flexibility Notifications Staff Value Business Intelligence IP Address Google Docs Travel Social Networking Unified Communications Legislation Shortcuts Experience Organization Techology Fileless Malware Digital Security Cameras Google Maps Smart Devices Bitcoin Ransmoware Running Cable Content Remote Working Google Wallet Wearable Technology Memory Vendors Unified Threat Management Motherboard Data Breach Recovery Comparison Google Play Be Proactive Health IT Unified Threat Management Directions Videos Assessment Electronic Health Records Hard Drives Windows 8 Permissions Workforce Laptop Domains Drones Wasting Time Threats Trend Micro Network Congestion Specifications Security Cameras Workplace Strategies User Error Microchip Internet Exlporer Software as a Service Refrigeration Fraud Meta Halloween Username Public Speaking Managing Costs Amazon Lithium-ion battery Point of Sale eCommerce Black Friday SSID Database Surveillance Hacks Virtual Assistant Outsource IT Entrepreneur Scary Stories Media Fun Network Management Tech Support IT Technicians Virtual Machine Environment Cookies Deep Learning Monitors Cyber Monday Medical IT Proxy Server Reviews Tactics Development Undo Hotspot Transportation Small Businesses Education Websites Mirgation Hypervisor Displays Shopping Nanotechnology Optimization PowerPoint SharePoint Addiction Mobile Computing Electronic Medical Records Language Employer/Employee Relationships Outsourcing Chatbots Navigation Search Management PCI DSS

Blog Archive