Cybersecurity researcher Jeremiah Fowler has uncovered a non-password-protected database containing over 240,000 records belonging to Willow Pays, a financial technology company specialized in AI-driven bill management solutions.
The database, accessible to the public, housed sensitive customer information, including names, email addresses, phone numbers, credit limits, and other internal data. Some of the exposed folders were also labeled as bills, repayment schedules, mailing lists, or included screenshots.
“One single spreadsheet document contained the details of 56,864 individuals, indicating if they were prospects, active customers, or blocked accounts,” Fowler noted.
Although the database was promptly secured after a responsible disclosure notice, it remains unclear how long the database was publicly accessible, whether it was directly managed by Willow Pays or a third-party contractor, and whether threat actors accessed it before it was secured.
Exposed databases like this one offer criminals opportunities to conduct fraud, identity theft, and social engineering schemes. For instance, knowledge of billing details, account statuses, and payment histories can be weaponized to create convincing phishing attacks and steal sensitive data such as credit card information and account passwords from users.
If you suspect your information has been compromised or you want to strengthen your cybersecurity posture, consider the following steps:
Check out plans and additional information here.
tags
Alina is a history buff passionate about cybersecurity and anything sci-fi, advocating Bitdefender technologies and solutions. She spends most of her time between her two feline friends and traveling.
View all postsDecember 24, 2024
December 19, 2024
November 14, 2024