Supply chain ⛓ Supply Chain

Keepnet Third-Party Breach (June 2020)

📅 2020-06-01 🏢 Not disclosed
Primary Source ↗

Incident Details

Keepnet Labs confirms contractor exposed ‘data breach database’ of 5 billion records. Keepnet Labs has confirmed that a contractor temporarily exposed a database containing five billion records collated from previous data breaches. A UK-based cybersecurity firm that threatened legal action against a security blogger has confirmed that a contractor temporarily exposed a database containing five billion email addresses and passwords collated from previous data breaches. Keepnet Labs collects historic breach data from “online public resources” so that it can notify its customers if their business domain has been compromised. This is a common and entirely legal method used by threat intelligence services.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Not disclosed
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2020-06-01 Breach occurred
  2. 2020-06-09 Publicly disclosed