logo

Insurance website's buggy API leaked Office 365 password and a giant email trove

ID: ef8f6caf-dd72-5db4-b54c-988c8e94b323

STIX ID: report--ef8f6caf-dd72-5db4-b54c-988c8e94b323

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-01-18

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

**Executive summary:** A misconfigured TTIBI API and server exposed ~657,000 emails (~25 GB) and a Base64-encoded Office365 account password for a noreply address, enabling full account access and potential exposure of customers' personal data and password-reset links; the flaw was reported and authentication was later added but the exposed account password remained unchanged for months, maintaining a high risk of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.