logo

Security company hired a used car salesman to build a website, and it didn't end well

ID: fe8e54a4-061e-599a-ab9c-5828257cdec0

STIX ID: report--fe8e54a4-061e-599a-ab9c-5828257cdec0

Feed Name: The Register (Security)

Threat Score
30/100

Date Published: 2025-07-11

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

A company experienced a theft of giveaway iPads by an employee; during the aftermath a newly introduced mandatory background-check website—developed by an unvetted contractor—was found to be insecure (loaded over HTTP before redirecting to HTTPS, contained passwords in client-side code, and used predictable password patterns), allowing an employee to access colleagues' uploaded identity documents and credentials. The incident led to internal investigations, terminations, mandatory background checks, and employee distrust, highlighting severe operational security failures and insider risk but with no reported evidence of wider external compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.