Home Improvement Platform Houzz Confirms Major User Data Breach

Houzz reveals that an unauthorized third party obtains a file containing user data, including scrambled passwords and profile details. The $4 billion startup actively investigates the incident while notifying affected users and European authorities.

Home improvement platform Houzz confirms that an unauthorized third party obtains a file containing some of its user data. The company, which recently achieves a $4 billion valuation and lays off ten percent of its staff, refuses to share specific details about when the breach occurs or if a hacker is to blame. Houzz states that it immediately launches an investigation with a leading forensics firm to handle containment and remediation efforts.

The stolen data includes publicly visible profile information such as names, locations, and profile descriptions, as well as internal system identifiers. Houzz also reports that usernames and scrambled passwords are taken in the breach. The company notes that the passwords utilize a one-way hashing algorithm with salt, but it does not specify the exact type of algorithm used to protect the credentials.

Despite the lack of specific hashing details, Houzz actively advises all users to change their passwords as a precaution. The company clarifies that no financial information is compromised in the incident. Furthermore, Houzz confirms that it notifies EU authorities within the statutory period required by the GDPR law, though it remains unclear if the startup faces regulatory penalties for the breach.

Read More at the original source →