logo

Carlsberg… probably not the best cybersecurity in the world

ID: 2ad07f84-c8a1-5c1e-bc87-53c83182f63b

STIX ID: report--2ad07f84-c8a1-5c1e-bc87-53c83182f63b

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2026-01-16

Date Updated: 2026-03-24

Author: Alex Wallace

...
...

A researcher discovered that Carlsberg’s exhibition wristbands used low-entropy IDs that could be brute-forced to access visitors’ media and full names, exposing PII; after reporting via Zerocopter and receiving minimal engagement and an ineffective rate-limiting mitigation, the issue remained exploitable, prompting public disclosure over 150 days later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.