Supply chain β›“ Supply Chain

Wyze customer Third-Party Breach (December 2019)

πŸ“… 2019-12-01 🏒 Wyze
Primary Source β†—

Incident Details

IoT vendor Wyze confirms server leak. Details for 2.4 million users were exposed online for 22 days. Wyze, a company that sells smart devices like security cameras, smart plugs, smart lightbulbs, and smart door locks, confirmed today a server leak that exposed the details of roughly 2.4 million customers. The leak occurred after an internal database was accidentally exposed online, Wyze co-founder Dongsheng Song said in a forum post published over Christmas. Third-party company: Wyze.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Wyze
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2019-12-01 Breach occurred
  2. 2020-02-14 Publicly disclosed