Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Disney Menu Debacle Can Teach Your Business a Lesson About Access Control

The Disney Menu Debacle Can Teach Your Business a Lesson About Access Control

The Disney brand centralizes its efforts on magic and wonder, but its parks’ food is one aspect that has recently been subject to concerning developments. A former Disney employee managed to access a menu-planning app and make changes to prices, add foul language, and change menu information. Since we live in a world with food allergies, you can already see where this is going.

The Federal Bureau of Investigation has issued this statement on the matter:

“The threat actor manipulated the allergen information on menus by adding information to some allergen notifications that indicated certain menu items were safe for individuals with peanut allergies, when in fact they could be deadly to those with peanut allergies.”

Thankfully, Disney nipped the issue in the bud before the menus were distributed, and there is no evidence that customers ever saw them. Additionally, there is no indication that these events are related to a prior event in 2023 when a death occurred at a Disney-owned restaurant due to allergens.

These Changes Could Have Been Prevented

This problem stems from a simple issue with network security: someone had permission when they shouldn’t have.

The FBI has reported that the accused individual, a former Disney employee and menu production manager named Michael Schuer, used his Disney credentials to access the menu-planning app to make changes. He was also able to use his old logins to access the app developer’s server. It’s a real case of a former employee doing despicable things with old login credentials.

What gave the “hack” away was the use of the Wingdings font. This is when Disney employees caught the issue and pulled the app. Before this, though, many employee accounts had been locked because the accused used scripts to automate logins. More than a dozen accounts exceeded their allowed login attempts, which made logging in difficult.

The complete criminal complaint offers more details about this event and the inciting attacks.

Pay Attention to User Permissions and Access Logs for Suspicious Activity

It might be a bit blunt of us to say, but this entire situation could (and should) have been prevented.

When an employee leaves your business or organization, you take away their login credentials right as they walk out the door. This is a standard and accepted best practice. It’s a part of ensuring proper access control for your business.

It’s easy to overlook a user’s profile when they leave your business, but you never know what baggage they’re leaving with—baggage that might cause them to lash out in unanticipated ways. We recommend that you practice the Principle of Least Privilege, where you only grant access as needed. There’s no reason that anyone who leaves your business should retain access to data, anyway, and the fewer entry points to your system for hackers (and other potential threats), the better.

To shore up your defenses and control access to your business, give Voyage Technology a call at 800.618.9844.

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Efficiency Hardware Network Security User Tips Internet IT Services Malware IT Support Privacy Workplace Tips Phishing Google Email Computer Workplace Strategy Collaboration Hosted Solutions Small Business Backup Users Managed Service Ransomware Mobile Device Productivity Microsoft Passwords Quick Tips AI Saving Money Communication Cybersecurity Smartphone Data Backup Disaster Recovery Data Recovery Android VoIP Upgrade Business Management Smartphones communications Mobile Devices Windows Social Media Browser Microsoft Office Managed IT Services Current Events Network Tech Term Internet of Things Remote Information Facebook Holiday Miscellaneous Automation Artificial Intelligence Compliance Cloud Computing Covid-19 Training Gadgets Outsourced IT Server Managed Service Provider Remote Work IT Support Encryption Employee/Employer Relationship Spam Office Windows 10 Business Continuity Government Data Management Bandwidth Blockchain Windows 10 Wi-Fi Virtualization Business Technology Managed Services Mobile Office Data Security Vendor Two-factor Authentication Apps Budget Voice over Internet Protocol Apple Networking App Mobile Device Management Gmail BYOD WiFi Employer-Employee Relationship Tip of the week Chrome Conferencing Hacker Avoiding Downtime Managed IT Services How To Marketing BDR HIPAA Computing Physical Security Applications Information Technology Access Control Office 365 Retail Storage Computers Healthcare Password Bring Your Own Device Website Operating System Router Virtual Private Network Risk Management Big Data 2FA Health Help Desk Analytics Office Tips Augmented Reality Customer Service Remote Workers Managed IT Service Telephone Scam Data loss Cooperation Free Resource Project Management Windows 7 Going Green Patch Management Save Money Microsoft 365 Remote Monitoring Firewall Vulnerability End of Support Vendor Management Solutions Cybercrime The Internet of Things Display Printer Windows 11 Paperless Office Social Infrastructure Monitoring Excel Document Management Hacking Presentation Maintenance Sports Downloads Antivirus Mouse iPhone Wireless Technology Licensing Data Privacy Entertainment Administration Vulnerabilities Images 101 Word Telephone System Multi-Factor Authentication Robot Mobility Cost Management Settings Printing Wireless Content Filtering IT Management Safety VPN Employees YouTube Meetings Integration Cryptocurrency User Tip Modem Processor Computer Repair Mobile Security Virtual Desktop Holidays Data storage Supply Chain LiFi Data Storage Smart Technology Outlook Video Conferencing Machine Learning Managed Services Provider Customer Relationship Management Money Saving Time Virtual Machines Professional Services Humor Scary Stories Private Cloud Identity Evernote Technology Care Hacks Server Management Regulations Compliance Superfish Bookmark Business Communications Identity Theft Smart Tech Memes Fun Scams Deep Learning Download Net Neutrality Twitter Alerts SQL Server User Error History Hybrid Work Financial Data Browsers Smartwatch Human Resources Education Connectivity IT Social Engineering Break Fix Cables Upload Procurement Remote Computing Azure Cyber security Multi-Factor Security Tech IP Address Mobile Computing Social Network Telework CES Google Apps Tablet IoT Communitications Search Dark Web IT Maintenance Best Practice Trends Supply Chain Management Alert Managed IT Customer Resource management FinTech Recovery Buisness File Sharing Regulations Dark Data Google Calendar Term Business Intelligence Legal Data Analysis Hard Drives Shortcuts IT solutions Star Wars IT Assessment How To Microsoft Excel Notifications Staff Value Domains Ransmoware Business Growth Gamification Flexibility Organization Travel Social Networking Legislation Vendors Techology Fileless Malware Digital Security Cameras Refrigeration Be Proactive Google Maps Smart Devices Cortana Wearable Technology Memory Public Speaking Workforce Alt Codes Content Remote Working Threats Health IT Downtime Unified Threat Management Motherboard Data Breach Comparison Google Play Lithium-ion battery Unified Threat Management Directions Videos Workplace Strategies Hosted Solution Assessment Electronic Health Records Entrepreneur Permissions Wasting Time Meta Typing Amazon Trend Micro Network Congestion Specifications Security Cameras Google Drive User Error Microchip Undo Internet Exlporer Software as a Service Knowledge Fraud Managing Costs Outsource IT Username Environment Media Point of Sale eCommerce 5G Black Friday SSID Google Docs Unified Communications Database Surveillance Experience Virtual Assistant Running Cable Tech Support IT Technicians Virtual Machine Small Businesses Bitcoin Network Management Displays Google Wallet Proxy Server Reviews Application Cookies Monitors Cyber Monday Medical IT Tactics Development Hotspot Transportation Laptop Websites Mirgation Hypervisor IBM Outsourcing Windows 8 Drones Shopping Nanotechnology Optimization PowerPoint SharePoint Workplace Addiction Electronic Medical Records Language Employer/Employee Relationships Halloween Chatbots Navigation Hiring/Firing Management PCI DSS Lenovo Gig Economy Paperless Screen Reader Writing Distributed Denial of Service Competition Co-managed IT Service Level Agreement Internet Service Provider Virtual Reality Computing Infrastructure Teamwork

Blog Archive