• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Tax Relief Biz Exposed Personal Info on 100,000 Clients

You are here: Home / General Cyber Security News / Tax Relief Biz Exposed Personal Info on 100,000 Clients

A UK company specializing in tax reduction for its purchasers has exposed the own particulars of above 100,000 of them by means of a misconfigured content material administration process (CMS).

Scientists at Site Earth advised Infosecurity exclusively about the privacy snafu, which they found out on Oct 13 and notified the business about the subsequent working day.

That corporation was Marriage Tax Refund, a Wolverhampton-primarily based firm whose enterprise design is to get well relationship tax allowance resources for UK customers.

✔ Approved Seller by TheCyberSecurity.News From Our Partners
Mcafee Total Protection 2021

Protect yourself against all threads using McAfee. Get McAfee Total Protection with 80% discount from our partner and an certified seller: SerialCart®.

➤ Activate Your Coupon Code


According to the investigation workforce, the company experienced misconfigured its WordPress CMS, leaving a directory listing of PDF documents out there for community perspective, with no password defense.

This intended everyone could theoretically have seen individually identifiable facts (PII) on Marriage Tax Refund customers, which include: applicants’ complete names, gender and household address, plus their partners’ entire names and gender, and the refund quantity they could request.

Web-site World approximated that in excessive of 100,000 purchasers who signed up to the plan due to the fact the company’s founding in Oct 2016 could have experienced their PII exposed in this way.

“A blend of complete title, handle and marital position are adequate for nefarious users to conduct id theft and fraud. In addition, personalized person facts could be used to perform fraud throughout other platforms with out the victim getting informed that these types of action is developing,” the scientists warned.

“Therefore, Marriage Tax Refund’s leak could probably be applied to deploy deeper and far more harming ripoffs by sending personalized info specifically to their target’s addresses, maybe disguised as conversation from Marriage Tax Refund, or, disguised as HMRC but referencing the customer’s organization with Relationship Tax Refund and thereby attaining the supposed target’s have confidence in.”

Following notifying both the UK CERT and privacy regulator the Facts Commissioner’s Office (ICO), Web-site Earth finally saw that the misconfiguration experienced been fixed by the business on November 6 this yr.


Some pieces of this report are sourced from:
www.infosecurity-magazine.com

Previous Post: «Facebook Tracks Apt32 Oceanlotus Hackers To It Company In Vietnam Facebook Tracks APT32 OceanLotus Hackers to IT Company in Vietnam
Next Post: Worldwide Flight Services Invests to Boost Cybersecurity Monitoring Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Recent Posts

  • Big Tech Bans Social Networking App
  • Lack of Funding Could Lead to “Lost Generation” of Cyber-Startups
  • Unveiled: SUNSPOT Malware Was Used to Inject SolarWinds Backdoor
  • ‘I’ll Teams you’: Employees assume security of links, file sharing via Microsoft comms platform
  • DarkSide decryptor unlocks systems without ransom payment – for now
  • Researchers see links between SolarWinds Sunburst malware and Russian Turla APT group
  • Millions of Social Profiles Leaked by Chinese Data-Scrapers
  • Feds will weigh whether cyber best practices were followed when assessing HIPAA fines
  • SolarWinds Hack Potentially Linked to Turla APT
  • 10 quick tips to identifying phishing emails

Copyright © TheCyberSecurity.News, All Rights Reserved.