Cosmetics Giant Avon Leaks 19 Million Records

Leo Daniels • August 4, 2020

This is a subtitle for your new post

A misconfigured cloud server at global cosmetics brand Avon was recently discovered leaking 19 million records including personal information and technical logs.

Researchers at SafetyDetectives led by Anurag Sen told Infosecurity that they found the Elasticsearch database on an Azure server publicly exposed with no password protection or encryption.

“The vulnerability effectively means that anyone possessing the server’s IP address could access the company’s open database,” it explained in a subsequent report.

The London-headquartered firm, which boasts over $5.5bn in annual worldwide sales, was apparently exposing the 7GB database for nine days before it was discovered on June 12.

It contained personally identifiable information (PII) on customers and potentially employees, including full names, phone numbers, dates of birth, email and home addresses, and GPS coordinates. Also included in the haul were 40,000+ security tokens, OAuth tokens, internal logs, account settings and technical server information.

While the PII could have been leveraged to commit a wide range of identity fraud and follow-on phishing scams, the exposed technical details also posed a risk to Avon, according to SafetyDetectives.

“Given the type and amount of sensitive information made available, hackers would be able to establish full server control and conduct severely damaging actions that permanently damage the Avon brand; namely, ransomware attacks and paralyzing the company’s payments infrastructure,” it argued.

Interestingly, a June 9 filing with the Securities and Exchange Commission revealed the firm had suffered a “cyber-incident in its information technology environment which has interrupted some systems and partially affected operations.”

A second filing on June 12 claimed that the firm was planning a restart of its systems.

“Avon is continuing the investigation to determine the extent of the incident, including potential compromised personal data,” it continued. “Nevertheless, at this point it does not anticipate that credit card details were likely affected, as its main e-commerce website does not store that information.”

It’s unclear whether the incident was linked to this exposed cloud server or not.

 

We’re 1-fix, we can help you secure your business

At 1-fix, we take a realistic approach to technology – ensuring our client’s systems are best protected.

If you have any concerns, questions or simply want to explore how to better secure your business, please do get in touch with the team for a FREE demonstration, consultation to explore how exposed your business might be and identify actions to take.


Join Our Mailing List

All sign-ups are handled inline with our privacy policy and can unsubscribe at any time.

IT Support Services
Cybersecurity Deep-Dive
IT Cloud Migration Service

Recent Blogs

AI image of colleagues working on laptops with cloud icons in the background
By Craig Atkins July 24, 2025
Planning to move to the cloud? Discover what to expect, key benefits, and how 1-Fix IT support ensures a smooth, secure migration for your business.
AI image of workers in an open office on computers.
By Grant Taylor-Davis July 21, 2025
Cut costs and reduce your carbon footprint with cloud migration. Discover how 1-Fix IT support helps businesses save and go green with managed IT services.
AI image of colleagues on laptops that are connected to the cloud
By Lee DS July 15, 2025
Discover why summer is the perfect time to move to the cloud. Learn how cloud migration boosts flexibility, security & cost-efficiency with 1-Fix IT support.
AI image of people sat round a desk discussing cybersecurity in business.
By Craig Atkins July 7, 2025
Protect your business with expert IT support. Learn why cybersecurity is vital for reputation, compliance, and long-term success.
AI image of someone using a laptop with the Microsoft Office 365 app logos on
By Callum Hurst July 4, 2025
Avoid the risks of using Office 365 Home at work. Learn why Office 365 for business is the right choice for security, scalability, and compliance.
AI image of a team of people working on a computer
By Craig Atkins July 1, 2025
Discover the key benefits of outsourced IT support, from enhanced cybersecurity and 24/7 monitoring to cost savings and regulatory compliance.
Show More