Snapchat employee data lost in phishing attack
Social media service plans to intensify its staff training going forward

Snapchat employees current and former have had their details compromised, following a scam email against the social media company.
The company, known for its ephemeral video messaging service, published a public apology to its employees on its blog, explaining that one of its employees had fallen for a phishing attack and disclosed the payroll information of a number of employees, and former employees.
"Last Friday, Snapchat's payroll department was targeted by an isolated email phishing scam in which a scammer impersonated our chief executive officer and asked for employee payroll information," wrote Snapchat in its blog post.
"Unfortunately, the phishing email wasn't recognised for what it was a scam and payroll information about some current and former employees was disclosed externally."
Snapchat emphasised that its internal servers were not breached and no user data was affected by the cyber attack.
It would not be specific about what was included in the payroll information, but it likely includes personal details, such as employees names, addresses, bank details and pension plans.
When it identified that one of its employees had fallen for a scam, Snapchat moved quickly. It reported the incident to the FBI. It has also contacted the affected employees, both current and former, and offered them two years of identity theft insurance and monitoring.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"When something like this happens, all you can do is own up to your mistake, take care of the people affected, and learn from what went wrong," Snapchat added.
"To make good on that last point, we will redouble our already rigorous training programs around privacy and security in the coming weeks."
Snapchat has been in the news for security breaches on more than one occasion. Hackers exposed some 100,000 explicit pictures in 2014, that users presumed had been deleted by the temporary messaging service, which has become a haven for sexting.
A report in 2013 from Gibson Security also exposed security flaws in the service, and later that same year the service was hacked via a vulnerability in a third-party API.
In related news, the UK government is taking phishing attacks against businesses seriously and wants UK businesses to train its employees about the importance of cybersecurity. Earlier this month Ed Vaizey, minister for culture and the digital economy, launched a free e-learning course to teach HR staff the dangers of cyber attacks.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
Capita tells pension provider to 'assume' nearly 500,000 customers' data stolen
Capita told the pension provider to “work on the assumption” that data had been stolen
By Ross Kelly Published
-
Gumtree site code made personal data of users and sellers publicly accessible
News Anyone could scan the website's HTML code to reveal personal information belonging to users of the popular second-hand classified adverts website
By Connor Jones Published
-
Pizza chain exposed 100,000 employees' Social Security numbers
News Former and current staff at California Pizza Kitchen potentially burned by hackers
By Danny Bradbury Published
-
83% of critical infrastructure companies have experienced breaches in the last three years
News Survey finds security practices are weak if not non-existent in critical firms
By Rene Millman Published
-
Identity Automation launches credential breach monitoring service
News New monitoring solution adds to the firm’s flagship RapidIdentity platform
By Praharsha Anand Published
-
Neiman Marcus data breach hits 4.6 million customers
News The breach took place last year, but details have only now come to light
By Rene Millman Published
-
Indiana notifies 750,000 after COVID-19 tracing data accessed
News The state is following up to ensure no information was transferred to bad actors
By Rene Millman Published
-
Pearson fined $1 million for downplaying severity of 2018 breach
News The SEC found the London-based firm made “misleading statements and omissions” about the intrusion
By Rene Millman Published