Security company hired a used car salesman to build a website, and it didn't end well
ID: fe8e54a4-061e-599a-ab9c-5828257cdec0
STIX ID: report--fe8e54a4-061e-599a-ab9c-5828257cdec0
Feed Name: The Register (Security)
A company experienced a theft of giveaway iPads by an employee; during the aftermath a newly introduced mandatory background-check website—developed by an unvetted contractor—was found to be insecure (loaded over HTTP before redirecting to HTTPS, contained passwords in client-side code, and used predictable password patterns), allowing an employee to access colleagues' uploaded identity documents and credentials. The incident led to internal investigations, terminations, mandatory background checks, and employee distrust, highlighting severe operational security failures and insider risk but with no reported evidence of wider external compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
