Supply chain β›“ Supply Chain

Sitepoint, teespring Third-Party Breach (February 2021)

πŸ“… 2021-02-01 🏒 WayDev
Primary Source β†—

Incident Details

Hacker leaks data of millions of Teespring users. A hacker has leaked the details of millions of users registered on Teespring, a web portal that lets users create and sell custom-printed apparel. The user data was leaked last Sunday on a public forum dedicated to cybercrime and the sale of stolen databases. The Teespring data was made available as a 7zip archive that includes two SQL files. The first file contains a list of more than 8.2 million Teespring users’ email addresses and the date the email address was last updated. Third-party company: WayDev.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
WayDev
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2021-02-01 Breach occurred
  2. 2021-01-25 Publicly disclosed