logo

How Spoutible’s Leaky API Spurted out a Deluge of Personal Data

ID: f4e0f8df-e55a-56b4-bf67-b2255b33bfd0

STIX ID: report--f4e0f8df-e55a-56b4-bf67-b2255b33bfd0

Feed Name: Troy Hunt – Security Blog

Threat Score
85/100

Date Published: 2024-02-05

Date Updated: 2026-04-19

Author: Troy Hunt

...
...

A public Spoutible API improperly returned extensive user-sensitive fields (emails, IPs, phone numbers, bcrypt password hashes, 2FA secrets and backup codes, and password-reset tokens), allowing attackers to enumerate and scrape ~207,000 user records and facilitating easy account takeover; the issue was disclosed and remediated within hours, but the harvested data persists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.