vulnerability

Stories From An IT Security Professional

Leaking Your Customer Names and Tracking Numbers

Well, this seems like a big and “major f*ckup”!

A recent Kickstarter campaign has leaked all the names of backer (users that have financially supported the campaign) and all the tracking numbers. The data resides in a public Excel file on MediaFire and has over 1404 entries.

They tried to identify backers that have not yet send in their address and sent out an email to everybody:

Dear all backers,
Thanks for all backers again,have a nice day!

Until now,in addition to the customer did not give us the address,almost all parcels have been sent out,please click the link below to download all information and then queries the back name corresponds to your tracking number.

https://www.mediafire.com/folder/1s[CUT FOR REASONS]8f/Documents

If you can not find your name,please send an email to tell us your backer number or backer UID(sale020@mileseey.com) , we will check it for you.

The link was not working on Sunday, a quick look on the comments shows that other users are having issues with dTape leaking that data:

kickstarter_002

And there is also a link to the Excel sheet:

kickstarter_001 kickstarter_03

With the tracking numbers you can identify the city the package was sent to, once it is delivered (mine currently is stuck at the customs in Zurich :-))

kickstarter_005

The campaign owners have not yet responded to critics and neither has Kickstarter.

Leave a Reply

Your email address will not be published. Required fields are marked *