Veeam mishandles Own Data, exposes 440M Customer E-mails
ID: 1082d519-32d6-5936-9993-46e12c8d8546
STIX ID: report--1082d519-32d6-5936-9993-46e12c8d8546
Feed Name: Security Ledger
Veeam left an Amazon-hosted MongoDB instance misconfigured and searchable for several days, exposing about 445 million records from 2013–2017 containing marketing/customer data (names, emails, recipient types, IPs, referrer URLs, user agents and organization size). The database appeared to be part of Veeam's marketing automation infrastructure and was secured after a security researcher notified the company; while the data is described as non-sensitive, it presents a large, structured dataset useful for spammers and phishers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
