Blog Layout

Cosmetics Giant Avon Leaks 19 Million Records

Leo Daniels • Aug 04, 2020

This is a subtitle for your new post

A misconfigured cloud server at global cosmetics brand Avon was recently discovered leaking 19 million records including personal information and technical logs.

Researchers at SafetyDetectives led by Anurag Sen told Infosecurity that they found the Elasticsearch database on an Azure server publicly exposed with no password protection or encryption.

“The vulnerability effectively means that anyone possessing the server’s IP address could access the company’s open database,” it explained in a subsequent report.

The London-headquartered firm, which boasts over $5.5bn in annual worldwide sales, was apparently exposing the 7GB database for nine days before it was discovered on June 12.

It contained personally identifiable information (PII) on customers and potentially employees, including full names, phone numbers, dates of birth, email and home addresses, and GPS coordinates. Also included in the haul were 40,000+ security tokens, OAuth tokens, internal logs, account settings and technical server information.

While the PII could have been leveraged to commit a wide range of identity fraud and follow-on phishing scams, the exposed technical details also posed a risk to Avon, according to SafetyDetectives.

“Given the type and amount of sensitive information made available, hackers would be able to establish full server control and conduct severely damaging actions that permanently damage the Avon brand; namely, ransomware attacks and paralyzing the company’s payments infrastructure,” it argued.

Interestingly, a June 9 filing with the Securities and Exchange Commission revealed the firm had suffered a “cyber-incident in its information technology environment which has interrupted some systems and partially affected operations.”

A second filing on June 12 claimed that the firm was planning a restart of its systems.

“Avon is continuing the investigation to determine the extent of the incident, including potential compromised personal data,” it continued. “Nevertheless, at this point it does not anticipate that credit card details were likely affected, as its main e-commerce website does not store that information.”

It’s unclear whether the incident was linked to this exposed cloud server or not.

 

We’re 1-fix, we can help you secure your business

At 1-fix, we take a realistic approach to technology – ensuring our client’s systems are best protected.

If you have any concerns, questions or simply want to explore how to better secure your business, please do get in touch with the team for a FREE demonstration, consultation to explore how exposed your business might be and identify actions to take.


Join Our Mailing List

All sign-ups are handled inline with our privacy policy and can unsubscribe at any time.

IT Support Services
Cybersecurity Deep-Dive
IT Cloud Migration Service

Recent Blogs

By Craig Atkins 22 Apr, 2024
Are you tired of juggling IT issues while trying to focus on growing your business? It may be time to consider outsourcing your IT support. We've put together 5 reasons why outsourcing your IT can be beneficial for you...
By Grant Davis 03 Apr, 2024
In today’s fast-paced digital landscape, having an intelligent assistant by your side can make all the difference. Enter Microsoft Copilot, a powerful AI companion designed to boost productivity, spark creativity, and simplify complex tasks. Let’s dive into what makes Copilot a game-changer for individuals and businesses alike.
By Craig Atkins 27 Mar, 2024
We've finalists for not one, but two Network Group Awards 2024!
By Craig Atkins 22 Mar, 2024
World Backup Day is just around the corner so we thought we'd share a few reasons why backing up your computers regularly is so important.
By Craig Atkins 15 Mar, 2024
John Clark, from Solutions Shared joined us on a webinar to discuss what Microsoft Power Apps are and how they can be used in your business.
By Lee Dugdale 13 Mar, 2024
This blog answers FAQs about Cyber Essentials such as 'What is Cyber Essentials?', 'Why do I need Cyber Essentials?' and 'Do all businesses need Cyber Essentials'
Show More
Share by: