Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Zack Whittaker
Zack Whittaker
@zackwhittaker@mastodon.social  ·  activity timestamp 3 weeks ago

NEW: Petco has taken down parts of its Vetco website after we discovered a masive data leak exposing customers' personally identifiable information (and their pets!) to the open web.

After flagging the leak, Petco still took four days to respond. We estimate millions of customers may be affected.

More: https://techcrunch.com/2025/12/10/petco-takes-down-vetco-website-after-exposing-customers-personal-information/

  • Copy link
  • Flag this post
  • Block
Paco Hope is thankful
Paco Hope is thankful
@paco@infosec.exchange replied  ·  activity timestamp 3 weeks ago

@zackwhittaker This is terrible. My dog isn’t very good with #cybersecurity and uses her owner’s name as her #password. I tried giving her a password wallet but she just buried it in the back yard.

  • Copy link
  • Flag this comment
  • Block
Tim Hergert
Tim Hergert
@cjust@infosec.exchange replied  ·  activity timestamp 3 weeks ago

@zackwhittaker I think that the most shocking thing to some pet owners would be finding out that their pet has a better credit score than they do.

  • Copy link
  • Flag this comment
  • Block
Zack Whittaker
Zack Whittaker
@zackwhittaker@mastodon.social replied  ·  activity timestamp 3 weeks ago

We found the bug in how Vetco generates PDF documents for its customers. Its PDF page was public and was indexed by Google, which is how we found it. Worse, an IDOR bug in the URL meant it was possible for anyone to obtain customer data by changing the customer's unique ID by a single digit. 🤦

https://techcrunch.com/2025/12/10/petco-takes-down-vetco-website-after-exposing-customers-personal-information/

TechCrunch

Exclusive: Petco takes down Vetco website after exposing customers' personal information

TechCrunch found Petco's veterinary clinics were spilling customers' personal information and medical histories of their pets to the open web.
  • Copy link
  • Flag this comment
  • Block
GreyPuma
GreyPuma
@GreyPuma@cyberplace.social replied  ·  activity timestamp 3 weeks ago

@zackwhittaker Enumeration - gee that was hard.. wonder if they messaged customers saying "we take the security of your data seriously"

  • Copy link
  • Flag this comment
  • Block
Frank Heijkamp
Frank Heijkamp
@alterelefant@mastodontech.de replied  ·  activity timestamp 3 weeks ago

@zackwhittaker That is a very bad design. I hope they will get fined for this by the privacy authorities.

  • Copy link
  • Flag this comment
  • Block
Jan Wildeboer 😷:krulorange:
Jan Wildeboer 😷:krulorange:
@jwildeboer@social.wildeboer.net replied  ·  activity timestamp 3 weeks ago

@zackwhittaker #WhereIsMySurprisedFace

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.44 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct