Cyber Crime
Appointment Booker ‘FlexBooker’ Hit By Second Data Leak: 19 Million Customers Data Exposed
NEW DELHI: A major data breach involving over 172 GB of data and an estimated 19 million users has been discovered. According to the researchers, the victims are largely consumers of the online appointment service FlexBooker.
FlexBooker is a provider of online scheduling software for websites and online businesses that allows them to take appointments for meetings, classes, and other events both online and in person. The software handles calendar synchronisation, appointment changes and cancellations, and payment processing.
ALSO READ: Massive Data Leak Of Major Insurance Companies Led To 50 Cr Fraud, UP STF Arrest 9
According to vpnMentor researchers, the compromise found in January 2022 is FlexBooker’s second Amazon Web Services (AWS) cloud infrastructure leak in two months. On December 23, 2021, hackers successfully launched a DDOS attack against the company’s AWS servers, causing widespread network outages and allowing hackers to steal data from 3.7 million users, including significant Personally Identifiable Information, IDs, hashed passwords, and partial credit card numbers .
“Our team found this additional misconfiguration during a routine scan of potential vulnerabilities across the whole internet, without prior knowledge of FlexBooker’s previous breach. Only upon further research did we learn about the first breach,” said vpnMentor.
The two breaches don’t appear to be connected, and this time, FlexBooker has potentially exposed even more people to fraud, online attacks, and much more. Up to 19 million, in fact.
If hostile or criminal hackers had discovered FlexBooker’s AWS account before it was secured, the exposed data may have been exploited in a variety of methods.
For starters, the exposed data would have been sufficient for competent hackers to perpetrate several of the most frequent types of fraud against anyone using a FlexBooker-enabled website, including identity theft, financial swindles and many more.
Follow The420.in on
Telegram | Facebook | Twitter | LinkedIn | Instagram | YouTube