Important Update: Regarding a Recent Security Issue

Written by
Category
Important Update: Regarding a Recent Security Issue

INTERESTING ARCHITECTURE TRENDS

Lorem ipsum dolor sit amet consectetur adipiscing elit obortis arcu enim urna adipiscing praesent velit viverra. Sit semper lorem eu cursus vel hendrerit elementum orbi curabitur etiam nibh justo, lorem aliquet donec sed sit mi dignissim at ante massa mattis egestas.

  1. Neque sodales ut etiam sit amet nisl purus non tellus orci ac auctor.
  2. Adipiscing elit ut aliquam purus sit amet viverra suspendisse potenti.
  3. Mauris commodo quis imperdiet massa tincidunt nunc pulvinar.
  4. Adipiscing elit ut aliquam purus sit amet viverra suspendisse potenti.

WHY ARE THESE TRENDS COMING BACK AGAIN?

Vitae congue eu consequat ac felis lacerat vestibulum lectus mauris ultrices ursus sit amet dictum sit amet justo donec enim diam. Porttitor lacus luctus accumsan tortor posuere raesent tristique magna sit amet purus gravida quis blandit turpis.

Odio facilisis mauris sit amet massa vitae tortor.

WHAT TRENDS DO WE EXPECT TO START GROWING IN THE COMING FUTURE?

At risus viverra adipiscing at in tellus integer feugiat nisl pretium fusce id velit ut tortor sagittis orci a scelerisque purus semper eget at lectus urna duis convallis porta nibh venenatis cras sed felis eget. Neque laoreet suspendisse interdum consectetur libero id faucibus nisl donec pretium vulputate sapien nec sagittis aliquam nunc lobortis mattis aliquam faucibus purus in.

  • Neque sodales ut etiam sit amet nisl purus non tellus orci ac auctor.
  • Eleifend felis tristique luctus et quam massa posuere viverra elit facilisis condimentum.
  • Magna nec augue velit leo curabitur sodales in feugiat pellentesque eget senectus.
  • Adipiscing elit ut aliquam purus sit amet viverra suspendisse potenti .
WHY IS IMPORTANT TO STAY UP TO DATE WITH THE ARCHITECTURE TRENDS?

Dignissim adipiscing velit nam velit donec feugiat quis sociis. Fusce in vitae nibh lectus. Faucibus dictum ut in nec, convallis urna metus, gravida urna cum placerat non amet nam odio lacus mattis. Ultrices facilisis volutpat mi molestie at tempor etiam. Velit malesuada cursus a porttitor accumsan, sit scelerisque interdum tellus amet diam elementum, nunc consectetur diam aliquet ipsum ut lobortis cursus nisl lectus suspendisse ac facilisis feugiat leo pretium id rutrum urna auctor sit nunc turpis.

“Vestibulum pulvinar congue fermentum non purus morbi purus vel egestas vitae elementum viverra suspendisse placerat congue amet blandit ultrices dignissim nunc etiam proin nibh sed.”
WHAT IS YOUR NEW FAVORITE ARCHITECTURE TREND?

Eget lorem dolor sed viverra ipsum nunc aliquet bibendumelis donec et odio pellentesque diam volutpat commodo sed egestas liquam sem fringilla ut morbi tincidunt augue interdum velit euismod. Eu tincidunt tortor aliquam nulla facilisi enean sed adipiscing diam donec adipiscing ut lectus arcu bibendum at varius vel pharetra nibh venenatis cras sed felis eget.

Hi everyone,

I am following up on Friday's blog where we communicated Rave Build's recent data breach. I deeply regret and apologise for this breach. We take this incident very seriously, and we are doing everything we can to secure our systems including: engaging with third-party experts to assist, and providing you with the transparency you need to protect yourselves and your customers.

Types of data

The data that Rave collects can be broken into two categories. Uploaded files and Database data. 

Uploaded files are the PDFs, images, and documents that you upload to Rave. This could include:

  • Council consents,
  • Photos of projects
  • Contracts
  • Bills, invoices, and credit notes

Database data is all other data that can be entered into Rave. This could include:

  • Names, phone numbers, emails addresses & other client information
  • Addresses (home & postal)
  • Messages between builders, subcontractors & clients
  • Task dates & assignees
  • Checklists
  • Quote Requests, Purchase Orders, Bills & Invoices

    NOTE:  Our Rave Build website does not record credit card information 
     

What was affected

All uploaded files until February 2023 were exposed and may have been taken by attackers.

Approximately 19,000 or 3% of uploaded files have been deleted by attackers. We were able to restore over 14,000 of those files from backups, but around 5,000 files were unrecoverable. We will be reaching out to affected clients individually with a list of files that we could not recover.

Attackers also stole a historical backup database from August 2021 which was stored on the same system. This was a backup made before the Schedule Update on the 8th of August 2021. 
 

What you need to do

  • Change your Rave password. Although Rave only stores hashed and salted passwords, these hashes may have been exposed. Changing your password now is an important step that you can take to keep your data safe.
  • Consider your obligations under The Privacy Act after a data breachYou may need to notify your customers that their data has been exposed.
  • Be on the lookout for phishing scams that could be impersonating you, your suppliers, or customers by copying an invoice or bill.
     

What we have done, and are doing now to stop this from happening again

  1. As soon as we became aware of the breach, Rave replaced the stolen credentials that were used by attackers and deactivated them.
  2. Rave has further restricted the permissions of credentials used internally.
  3. We have set up additional security alerts to notify us of any future suspicious activity.
  4. We have identified internal systems running older versions of software. These systems are currently being upgraded.
  5. We are engaging with an external security company that will independently audit our systems. We will use these findings to further secure our systems against attacks like this.
  6. We have identified ways to further secure Rave, and are undertaking work that will ensure Rave remains security focused.

I am truly sorry that this incident has occurred, and want to assure you that we are committed to protecting your information at all times. We will keep our website blog updated with any relevant news. If you have any questions, please do not hesitate to contact the team at help@ravebuild.co.nz, submit a ticket via our support portal, or call the team at 07 210 2228.

Barry Ward

CEO Rave Build