• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Amazon Web Services Misconfiguration Exposes Half a Million Cosmetics Customers

You are here: Home / General Cyber Security News / Amazon Web Services Misconfiguration Exposes Half a Million Cosmetics Customers
June 17, 2021

Hundreds of hundreds of retail consumers had their personal knowledge exposed thanks to a misconfigured cloud storage account, Infosecurity has figured out.

A investigate group at opinions web-site WizCase traced the leaky Amazon S3 bucket to popular Turkish beauty solutions firm Cosmolog Kozmetik.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The 20GB trove contained all over 9500 data files, which includes hundreds of Excel data files which exposed the own data of 567,000 distinctive consumers who bought merchandise from the service provider throughout several e-commerce platforms.

Although the investigation workforce discovered no payment info, they did discover customers’ full names, physical addresses and buy information among the leaked orders. In some scenarios, phone numbers and e-mails were also uncovered.

The oldest orders dated again to 2019, and they went proper up to the existing working day. This signifies that the database is continually up to date.

WizCase warned that numerous of these whose aspects ended up uncovered may well be unaware of the leak, as e-commerce market consumers frequently really don’t look at the names of sellers.

Cosmolog Kozmetik, which also sells under the identify “Marketlog,” is commonly uncovered on significant Turkish e-commerce platforms Trendyol, Hepsiburada, and Unishop.

WizCase warned that if menace actors managed to locate and duplicate the uncovered data, it may well put these consumers at risk of adhere to-on phishing and fraud, which include refund cons. They could even endure bodily theft of deals if attackers keep track of and steal shipments as they arrive at customers’ properties, it extra.

“Cyber-criminals are constantly making new techniques to exploit anybody vulnerable on the internet,” WizCase warned in a site post detailing the privacy snafu.

“For future functions, we advocate generally inputting the bare minimal of facts when earning a order or setting up an account on the internet. The considerably less data you give hackers to function with, the significantly less susceptible you are to attack.”

Despite the fact that WizCase contacted the Turkish CERT, Amazon and Cosmolog Kozmetik about the breach, none experienced replied at the time of writing.


Some pieces of this report are sourced from:
www.infosecurity-journal.com

Previous Post: «Cyber Security News US Warns Russia of Cyber-Attack No-Go List
Next Post: Weekly threat roundup: Microsoft Teams, iOS, Samsung Galaxy weekly threat roundup: microsoft teams, ios, samsung galaxy»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • OpenAI Unveils Aardvark: GPT-5 Agent That Finds and Fixes Code Flaws Automatically
  • Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack
  • China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats
  • China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems
  • The MSP Cybersecurity Readiness Guide: Turning Security into Growth
  • CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers
  • Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery
  • CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
  • A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do
  • Google’s Built-In AI Defenses on Android Now Block 10 Billion Scam Messages a Month

Copyright © TheCyberSecurity.News, All Rights Reserved.