logo

A leaky database spilled 2FA codes for the world’s tech giants

ID: 76280381-655a-53a8-a4be-09a24274009c

STIX ID: report--76280381-655a-53a8-a4be-09a24274009c

Feed Name: TechCrunch Security News

Threat Score
70/100

Date Published: 2024-02-29

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

YX International left an internal, unauthenticated database publicly accessible that contained SMS one-time passcodes, password reset links for major platforms (Facebook, Google, TikTok, WhatsApp), and internal employee credentials. A security researcher discovered and reported the exposure to TechCrunch and the company, which took the server offline and said it had "sealed this vulnerability," but YX would not confirm duration of exposure and reported the server lacked access logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.