Shark Tank contestant’s involvement in Google Cloud leak exposes 83,000 individuals

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Leaking Google Cloud Storage Bucket Exposes Personal Data of Over 83,000 Customers Linked to Alice’s Table

A leaking Google Cloud Storage bucket linked to Alice’s Table, a Shark Tank contestant offering virtual floral arrangement classes, has exposed the personal data of over 83,000 customers, Cybernews reports.

The misconfigured cloud bucket was discovered by the Cybernews research team on April 28th during a routine investigation using open-source intelligence methods. The bucket was traced back to Alice’s Table, a platform founded by Boston entrepreneur Alice Lewis in 2015 and now part of the 1-800-Flowers family of brands.

In addition to floral arrangements, Alice’s Table offers curated live streaming experiences, including culinary and cocktail workshops. The leaking Google cloud bucket contained tens of thousands of files with personally identifiable information (PII) such as emails and home addresses of the platform’s clients in the United States.

The exposed data included full names, email addresses, home addresses, and order details. While the leak primarily consisted of personal email addresses, a significant portion were professional email accounts affiliated with companies like BCG, Pfizer, PwC, Charles Schwab, and government employees.

Cybersecurity experts advise affected organizations to immediately revoke public access to the affected bucket, review access logs retrospectively, enable server-side encryption, and conduct regular security audits of all Google Cloud Storage to mitigate risks and ensure ongoing compliance with security standards.

Neither Alice’s Table nor 1-800-Flowers have responded to Cybernews’ request for comment at the time of publishing. The United States Computer Emergency Readiness Team (US-CERT) has been informed of the incident.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

U.S. Postal Service Finalizes Mail-in Ballot Regulations Amid Supreme Court Appeal

The U.S. Postal Service (USPS) has announced the finalization of new regulations that could grant the federal government significant control over mail-in ballots for...

Red Hat releases important libtiff security update for RHEL 8.6 users

Red Hat has announced an important security update for the libtiff library, specifically targeting users of Red Hat Enterprise Linux (RHEL) 8.6 Advanced Mission...

Cyber Security Centre warns of increasing complexity in cyber incidents and QR code scams

Cybersecurity incidents are evolving, becoming increasingly intricate and sophisticated, as highlighted in the National Cyber Security Centre's (NCSC) second-quarter report. The report, which focuses...

Core42 Enhances AI Infrastructure for Secure UAE Government Services Deployment

Core42 Enhances AI Infrastructure for Secure UAE Government Services Deployment Core42 is advancing the deployment of secure and scalable AI infrastructure for UAE government services,...