Select Page

Incident: Four’N Twenty owner Patties Foods reportedly targeted in ‘data breach’ | Mumbrella

Incident: Four’N Twenty owner Patties Foods reportedly targeted in ‘data breach’ | Mumbrella

Australian Food Manufacturing Data Breach, 6 June 2024

Four’N Twenty owner Patties Foods based in Victoria reportedly targeted in ‘data breach’

Cybersecurity researcher Jeremiah Fowler, discovered two separate database exposures that were publicly accessible and non-password protected.

Source: Four’N Twenty owner Patties Foods reportedly targeted in ‘data breach’ | Mumbrella

View more incidents relating to the Manufacturing sector and incidents from Victoria.

Patties Foods, the owner of popular servo pastry brand Four‘N Twenty, has been ‘targeted in a third-party data breach’. Founded in 1966, Patties Foods also operates Leggo’s, Lean Cuisine, Nanna’s, Chefs Pride, and Herbert Adams.

According to a Patties Foods spokesperson, this was not a data breach as such, but rather a case of data exposure on behalf of a third party – and one that has been quickly addressed at that.

Cybersecurity Researcher, Jeremiah Fowler, discovered and reported to WebsitePlanet about a non-password-protected database that contained 524k documents belonging to Patties Foods Limited, a leading provider of food services throughout Australia. The records included more than 25k invoices. The database also included evidence of ransomware.

This discovery pertained to two separate database exposures that were publicly accessible and non-password protected. The first was an exposed logging server that contained 496,296 records. These logs captured various types of information such as system errors, warnings, indexing operations, search queries, cluster health status, and other diagnostic data. They also exposed internal, customer, and vendor emails. Additionally, I identified a separate cloud storage database inside the logging records that contained 25,800 invoices and distribution records in .pdf and .xls formats. Upon further research, it was identified that the records belonged to Patties Foods Limited PFL. Patties Foods is an Australian food company known for producing a wide range of edible products. Founded in 1966, Patties is one of Australia’s leading manufacturers and suppliers of meat pies, sausage rolls, pastries, desserts, and frozen fruits.

However, documents indicate the IP address was managed by a company called Provenio.ai, a service provider which provides AI-powered productivity for the supply chain back-office to many well-known Australian companies.

Having discovered the exposed database, Fowler did what any self-respecting cyber security analyst would do and reported it to Provenio.ai, which said it was taking Fowler’s notification seriously.

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Trackbacks/Pingbacks

  1. Incident: Snow Brand Australia confirms SafePay ransomware attack | Cyberdaily.au – Canadian Cyber Watch - […] Incident: Four’N Twenty owner Patties Foods reportedly targeted in ‘data breach’ | Mumbrella […]

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

AFL clubs explore facial recognition as new ticketing method

Your face could be your next big ticket. With a scan of it, you could be granted entry to AFL games, concerts or even conferences. Facial recognition … [...]

Legacy technology is a national security threat hiding in plain sight | The Strategist

The problem with legacy technology is not that organisations do not know the risks. It is that no mechanism forces a decision. Ownership is … [...]

ASD to critical infrastructure ops: be ready to isolate systems for three months

The Australian Signals Directorate (ASD) has released detailed technical guidance instructing critical infrastructure operators on how to fully … [...]

Origin Energy believes 900,000 customers' data accessed in breach

Origin Energy believes the information of approximately 900,000 current and former customers was accessed during a recent data security breach. The … [...]

Facial recognition trial sparks privacy debate | 7NEWS

Western Australian police have begun trialling live facial recognition cameras that match faces in crowds to police databases in real time, raising privacy and human rights concerns. New South Wales [...]

SA Health staff investigated after AFL icon records breach | 7NEWS

The South Australian health system is accused of having a sticky beak culture with Tony Modra becoming the latest high-profile identity to have his privacy breached. 7NEWS can reveal the [...]

Australia will face a rogue AI attack, the question is when, says cyber expert | The Business

Chat GPT maker, Open AI says one of its most advanced AI models, an autonomous agent, went rogue and hacked into multi-billion-dollar tech startup Hugging Face during a laboratory test. [...]

Exclusive: Victorian heritage and restoration firm listed by The Gentlemen ransomware group

Highly active cyber extortion group claims hack of Australian HBS Group, data to be published within seven days. • Mon, 27 Jul 2026 • … [...]

Exclusive: Aussie unmanned systems firm CubePilot boss warns of ‘security incident’

The maker of unmanned guidance hardware supplied to Ukraine says some systems have been taken offline, and the incident is under investigation. • Mon, … [...]

Exclusive: Australian mining firm West African Resources suffers alleged data breach

The Deadlock ransomware gang is claiming to have stolen company data from an Aussie company with projects throughout the African nation of Burkina … [...]

Not just phishing: The scams to watch for if you're an Origin Energy customer

In brief As many as 4.8 million Origin Energy customers could be affected by a cyber attack that exposed personal data. • Experts have warned the fallout … [...]

AUSCERT Week in Review for 24th July 2026

Origin Energy has confirmed that unauthorised access to customer information has occurred, marking what is believed to be the largest publicly known … [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading