Data Security, Breach, Privacy

VTEX database exposing customer info remains unsecured

A stock illustration that represents the concept of e-commerce phishing in pastel orange and cobalt blue, incorporating fake shopping carts and conceptual metaphors of stolen data and false security for an engaging and intuitive understanding of the concept. Utilize soft gradients and layered shadows to create a hint of spatial complexity and priority. --ar 16:9 --v 6.1 Job ID: b12556c8-93ea-4d94-91b3-9ca3f4a58a7b

VTEX a global e-commerce platform for over 3,500 online stores, including those of Nestle, Coca-Cola, Sony, Walmart, Mazda, and Samsung has inadvertently leaked the data of six million shoppers, according to Cybernews.

Cybernews researchers discovered the exposure at the end of February, after finding an unauthenticated cloud container containing Parquet files with customer details such as email and residential addresses, phone numbers, order details, and purchase histories. Despite repeated contact attempts and the involvement of Brazil's national computer emergency response team, VTEX has not secured the database or issued a statement.

Researchers warned that the leaked data could be exploited by threat actors to conduct phishing or fraud campaigns by impersonating well-known retailers. They emphasized that the breach poses significant risks, particularly as the global shopping season approaches. The leak also raises privacy and safety concerns, as the data includes information that could be used for harassment, targeted scams, or stalking.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds