Supply chain
β Supply Chain
Amazon, Ebay, Shopify, Stripe, PayPal Third-Party Breach (March 2020)
Primary Source βIncident Details
8 million UK shopping records exposed on the web, customers’ personal info leaked - Comparitech. A 3rd-party app used by EU merchants on Amazon, Ebay, and other marketplaces exposed 8 million sales records containing customers’ personal data. A software vendor used by small retailers in the EU exposed a database of nearly 8 million sales records on the web without a password or any other authentication required to access it. The documents contained sales records including customer names, email addresses, shipping addresses, purchases, and the last four digits of credit card numbers , among other info. Anyone could find and access the data.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Not disclosed
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2020-03-01 Breach occurred
- 2020-03-10 Publicly disclosed