Slickwraps Appears to Have Suffered a Massive Data Breach
Ummm, if you are a Slickwraps customer, you might see an email arrive this morning that claims the company has been hacked. The email might not be lying to you either, as this does not appear to be a promotion or some sort of fun exercise. This may be related to a massive security breach.
An email titled “ATTN: ALL SLICKWRAPS CUSTOMERS” is showing up in inboxes with the word “Slickwraps” changed to “SLICKHACKED.” The email then goes on to say something close to the following:
if you’re reading this it’s too late. we have your data.
here’s where you live:
PERSON NAME
ADDRESShow do we have this data? we read this: https://ift.tt/39VQLJo
what are we doing with your data? not much (that’s good!)
we’re just using 377428 emails from their customer database to send this mass email (that’s bad!)
because right now, ANYBODY can do what we just did, and they might do something really shitty with the same data we took
The email goes on from there to suggest you should contact Slickwraps to let them know about the breach and possibly contact your local authorities. They suggest you do that second part because of the story linked in that Medium article, where the @Lynx0x00, who discovered the vulnerability, claims to have given Slickwraps proper notification and received little in response.
Here’s what you need to know.
- Slickwraps apparently has (or had) at least one really horrible security vulnerability. There may be even more. However, this single vulnerability allowed @Lynx0x00 to access almost every single detail about the company (revenue, taxes, all of your data, payment APIs, and their Zendesk support account). It gave them so much access, they claim that they could have deleted the entire company’s existence if they wanted to. That’s the level of access they gained.
- Because Slickwraps failed to respond to them, blocked them, and tried to allegedly cover the tracks of this breach without notifying anyone, @Lynx0x00 has posted the entire situation to that Medium post above. You should read it here.
- At this time, we don’t know who else has accessed this data or if Slickwraps has buttoned things up. According to email screenshots flooding Twitter, this appears to be really bad.
- I’m in shock at how bad this is.
We tried to reach out to Slickwraps for comment, but they apparently offer zero way to contact them or removed all ways after this story broke on Twitter. We’ll do our best to update this.
// Medium
Slickwraps Appears to Have Suffered a Massive Data Breach is a post from: Droid Life
from Droid Life https://ift.tt/2SLuV5S

No comments: