Home/Incidents/Bunnings Warehouse

Bunnings Warehouse

6 Feb 2019 · National · Retail & E-Commerce
Data Leak / Misconfiguration MEDIUM ✓ Verified

What happened

An individual store manager inadvertently created an insecure, public-facing custom MySQL database on a home environment to handle regional marketing events, exposing plain-text developer credentials, staff IDs, and customer phone logs.

Incident details

Organisation
Bunnings Warehouse
Date
6 Feb 2019
Attack type
Data Leak / Misconfiguration
Severity
MEDIUM
Sector
Retail & E-Commerce
State
National
Records affected
1194
Threat actor
Human Error

Source

itnews.com.au ↗
← Back to all incidents