Kickstarter sensation exposes over 500,000 records containing clients’ data

Published:

spot_img

Peak Design Exposes Over Half a Million Records in Data Leak Incident

Over half a million records with clients’ data and a decade’s worth of support tickets have been publicly exposed and likely accessed by threat actors after a US accessories maker forgot to set a password.

Peak Design, a California-based manufacturer and retailer of bags and accessories for travelers and photographers, exposed its clients’ private data to anyone on the internet. The company, known for its successful crowdfunding campaigns and strong Kickstarter community, raised nearly $36 million to fund the creation of its award-winning product designs.

The leaked data included customer email addresses, home addresses, order information, shipment tracking codes, and customer support inquiries. The Cybernews research team identified the leak on April 25th, with the leaked support tickets spanning nearly a decade from June 2014 to May 2023, magnifying the scope of the leak.

The data leak was caused by a publicly accessible Elasticsearch instance, an open-source search engine for analyzing large amounts of data. Access to Elasticsearch servers should never be exposed to the public web without proper authentication, as they are common targets for threat actors.

Cybernews researchers found a ransom note on Peak Design’s systems, indicating that the threat actor likely accessed the data at least once. The ransom note demanded around $3940 in Bitcoin to prevent the public release and deletion of customer data.

Although the leaked data was not updated in real-time, the exposure of customers’ personal information remains a significant concern. The company has since secured access to the data, but an official response has yet to be received. The potential misuse of the leaked data by gray market marketing agencies, data brokers, spammers, and for phishing or doxxing attacks is a cause for alarm.

spot_img

Related articles

Recent articles

Alert: CVE-2025-65998 Exposes Apache Syncope Password Vulnerabilities

A Serious Vulnerability Found in Apache Syncope A new security vulnerability has been identified in Apache Syncope, a popular open-source identity management system. This flaw...

Nemetschek Group Speeds Up Digital Transformation for Big 5 Global 2025

Transforming the Built Environment: The Nemetschek Group at Big 5 Global 2025 As digital tools increasingly shape the future of the construction industry, the Nemetschek...

Why Are Developers and Pen Testers Seeking Dark Web Opportunities?

The Rise of Cybercrime Careers: An In-Depth Look at the Dark Web Job Market Introduction to the Dark Web Job Surge Recent research by Kaspersky has...

Enhancing Data Security with AI Tools

25 Nov AI Tools and Data Security: A Closer Look Jack Fletcher, Senior Director at FTI Consulting, shares insights on AI's growing presence in workplaces...