Durex India spilled customers’ private order data

Date:

Share post:


Durex India, the Indian subsidiary of the British condom and personal lubricants brand, has exposed its customers’ personal information, including their full names and order details.

Security researcher Sourajeet Majumder contacted TechCrunch this week about the issue of exposing sensitive customer data on the condom maker’s website.

The brand’s website spilled customer names, phone numbers, email addresses, shipping addresses, the products ordered and the amount paid. The exact number of affected customers is not known. However, the researcher found evidence that hundreds of people had information exposed because of a lack of proper authentication on its order confirmation page.

“For a brand dealing with intimate products, ensuring privacy is crucial,” Majumder told TechCrunch.

TechCrunch verified Majumder’s findings, and found that customer order details were still accessible online at the time of writing. As such, TechCrunch is withholding certain details about the exposure as to not aid malicious actors.

When reached by TechCrunch prior to publication about the exposed customer information, Ravi Bhatnagar, a spokesperson for Durex parent company Reckitt, declined to comment or say if the company plans to secure its customers’ information.

The researcher told TechCrunch that the data could be exploited for identity theft, and contact details may result in unwanted harassment. Majumder said that he also contacted India’s Computer Emergency Response Team (CERT-In) about the security lapse, which acknowledged his email.

“Affected customers can also become victims of social harassment or moral policing because of this leak,” the researcher said.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Trump pardons Silk Road creator Ross Ulbricht

President Trump on Tuesday pardoned Ross Ulbricht, the creator of the infamous dark web exchange Silk Road,...

MrBeast is reportedly now among those trying to buy TikTok

Jesse Tinsley, CEO of a workforce management company, Employer.com, is conducting what could become the year’s wildest...

Meta COO Sheryl Sandberg sanctioned by judge for allegedly deleting emails

A Delaware judge has sanctioned Sheryl Sandberg, Meta’s former COO and board member, for allegedly deleting emails...

Microsoft is no longer OpenAI’s exclusive cloud provider

Microsoft was once the exclusive provider of data center infrastructure for OpenAI to train and run its...

OpenAI teams up with SoftBank and Oracle on $500B data center project

OpenAI says that it will team up with Japanese conglomerate SoftBank and with Oracle, along with others,...

Scale AI’s Alexandr Wang has published an open letter lobbying Trump to invest in AI

Alexandr Wang, the CEO of Scale AI, has taken out a full-page ad in The Washington Post...

Amperesand targets data centers as the next big customer for its solid-state transformers

With data centers expected to consume as much as 12% of electricity in the U.S. by 2028,...

Perplexity launches Sonar, an API for AI search

Perplexity on Tuesday launched an API service called Sonar, allowing enterprises and developers to build the startup’s...