Summary
API testing firm APIsec confirms exposure of internal database containing customer data. Data includes names, email addresses, and security details of customers' APIs. Exposure was due to human mistake, not malicious incident.
Key Points
The exposed database contained records dating back to 2018, including names, email addresses, and security details of APIsec's corporate customers.
The data included information about the attack surfaces of APIsec's customers, such as whether multi-factor authentication was enabled on a customer's account.
APIsec claims it quickly secured the database after being notified by UpGuard, but some personal information of its customers' employees and users remained accessible
A former employee's AWS keys and Slack/GitHub credentials were also found in the dataset
Why It Matters
This data breach highlights the importance of securing sensitive customer data and emphasizes the need for proactive measures to prevent such incidents.
Author
Zack Whittaker