Kickstarter sensation exposes over 500,000 records containing clients’ data

Published:

spot_img

Peak Design Exposes Over Half a Million Records in Data Leak Incident

Over half a million records with clients’ data and a decade’s worth of support tickets have been publicly exposed and likely accessed by threat actors after a US accessories maker forgot to set a password.

Peak Design, a California-based manufacturer and retailer of bags and accessories for travelers and photographers, exposed its clients’ private data to anyone on the internet. The company, known for its successful crowdfunding campaigns and strong Kickstarter community, raised nearly $36 million to fund the creation of its award-winning product designs.

The leaked data included customer email addresses, home addresses, order information, shipment tracking codes, and customer support inquiries. The Cybernews research team identified the leak on April 25th, with the leaked support tickets spanning nearly a decade from June 2014 to May 2023, magnifying the scope of the leak.

The data leak was caused by a publicly accessible Elasticsearch instance, an open-source search engine for analyzing large amounts of data. Access to Elasticsearch servers should never be exposed to the public web without proper authentication, as they are common targets for threat actors.

Cybernews researchers found a ransom note on Peak Design’s systems, indicating that the threat actor likely accessed the data at least once. The ransom note demanded around $3940 in Bitcoin to prevent the public release and deletion of customer data.

Although the leaked data was not updated in real-time, the exposure of customers’ personal information remains a significant concern. The company has since secured access to the data, but an official response has yet to be received. The potential misuse of the leaked data by gray market marketing agencies, data brokers, spammers, and for phishing or doxxing attacks is a cause for alarm.

spot_img

Related articles

Recent articles

Middle East Tensions Accelerate Cyber Threats to Critical Infrastructure in Asia-Pacific

Middle East Tensions Accelerate Cyber Threats to Critical Infrastructure in Asia-Pacific As geopolitical tensions escalate, a notable increase in cyber threats targeting operational technology (OT)...

Europe Faces AI Skills Gap Threat as Experts Project 2040 Workforce Scenarios

Europe Faces AI Skills Gap Threat as Experts Project 2040 Workforce Scenarios A recent report from the European Labour Authority and the European Commission’s Directorate-General...

OpenAI Advances Cybersecurity with Daybreak Initiative Amid Growing AI Competition

OpenAI Advances cybersecurity with Daybreak Initiative Amid Growing AI Competition OpenAI has officially launched OpenAI Daybreak, marking its entry into the competitive landscape of AI-driven...

UAE Launches Sovereign AI-Driven Cyber Factory to Strengthen National Cybersecurity Amid 800,000 Daily Attacks

UAE Launches Sovereign AI-Driven Cyber Factory to Strengthen National Cybersecurity Amid 800,000 Daily Attacks The United Arab Emirates (UAE) Cyber Security Council has unveiled a...