Adam Bannister reports: Covve, the popular address book app, has been identified as the source of a data breach that exposed the details of nearly 23 million individuals. Troy Hunt, founder of Have I Been Pwned?, tweeted on Saturday (May 16) that the app had been pinpointed as the source of a publicly accessible database that he had been…
Category: Exposure
RU: Data of 9 million customers of the Russian courier service leaked, but whose leak is it?
E Hacking News reports: Data belonging to nine million customers of the CDEC Express transportation service was put up for sale on the Web for 70 thousand rubles ($950). This is the largest leak of personal data in Russian delivery services […] The CDEC claims that there was no data leak from the company. As…
UK: Over 190 Law Firms Affected by Advanced Data Leak That Exposed Over 10,000 Legal Documents
Alicia Hope: A leading UK software company exposed personal information belonging to over 190 law firms through an unsecured online database. TurgenSec security firm discovered the breach but could not immediately identify the owner of the online database and therefore contacted the National Cyber Security Centre (NCSC). Following the Responsible Disclosure Policy, the firm contacted…
RU: Payment portals leak the passport numbers of the tens of thousands of Muscovites ticketed for quarantine violations
Sourced from Kommersant, Meduza reports: Over the past two months, Moscow has issued tens of thousands of fines to local residents for violating the city’s coronavirus self-isolation restrictions. Thanks to weak cryptographic security, the personal data of those ticketed is now available online. The blog Nora Ezhika first drew attention to the data leak on May 12,…
Edison Mail rolls back update after iOS users reported they could see strangers’ emails
Kim Lyons reports: Edison Mail has rolled back a software update that apparently let some users of its iOS app see emails from strangers’ accounts. Several Edison users contacted The Verge to report seeing the glitch after they applied the update, which was meant to allow users to sync data across devices. Reader Matthew Grzybowski said after…
Data breach in new Illinois online unemployment system exposes private information
Jamie Munks reports: A glitch in a newly launched state system for processing unemployment claims for gig workers publicly exposed personal information, a spokeswoman for Democratic Gov. J.B. Pritzker said Sunday. The Illinois Department of Employment Security “is aware there was a glitch” in a new system for processing unemployment claims for independent contractors and…