Supply chain
⛓ Supply Chain
Keepnet Third-Party Breach (June 2020)
Primary Source ↗Incident Details
Keepnet Labs confirms contractor exposed ‘data breach database’ of 5 billion records. Keepnet Labs has confirmed that a contractor temporarily exposed a database containing five billion records collated from previous data breaches. A UK-based cybersecurity firm that threatened legal action against a security blogger has confirmed that a contractor temporarily exposed a database containing five billion email addresses and passwords collated from previous data breaches. Keepnet Labs collects historic breach data from “online public resources” so that it can notify its customers if their business domain has been compromised. This is a common and entirely legal method used by threat intelligence services.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Not disclosed
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2020-06-01 Breach occurred
- 2020-06-09 Publicly disclosed