Tuesday, September 15th 2020
Razer Leaks Personal Information of Over 100,000 Gamers
Security researcher Volodymyr Diachenko has discovered a security breach over at hardware peripheral manufacturer Razer. Reportedly, Mr. Volodymyr found a badly configured Elasticsearch cluster filled with over 100,000 data entries of Razer customers. That means that anywhere from customer email, physical address and phone number have been exposed to the public, making this leak potentially dangerous. What is even more dangerous is that the Elasticsearch cluster was not only exposed to the internet, however, it was also indexed by a search engine, making the data more easily searchable and discoverable. This is a pure admin fail, no hacking was required, they just left the front door open. Razer issued an official response to the incident below:
Source:
Ars Technica
RazerWe were made aware by Mr. Volodymyr of a server misconfiguration that potentially exposed order details, customer and shipping information. No other sensitive data such as credit card numbers or passwords was exposed.Above you can see example of indexed customer information. Razer has also said that concerned customers can reach out to the DPO@razer.com email address and get help form Razer's employees.
The server misconfiguration has been fixed on 9 Sept, prior to the lapse being made public.
We would like to thank you, sincerely apologize for the lapse and have taken all necessary steps to fix the issue as well as conduct a thorough review of our IT security and systems. We remain committed to ensure the digital safety and security of all our customers.
19 Comments on Razer Leaks Personal Information of Over 100,000 Gamers
If you are an EU citizen... immediately file an officlal GDPR complaint. Nail those fuckers down. Its time to start defending your personal data no matter who keeps it for you.
Unless companies are hit in the only place that matters to them (bank balance), they will never fix their shit. "Misconfigured server" is simply lawyer-speak for "didn't bother to do due diligence".
shit products made by a shit-4-brains company that has shit-4-brains people working in their data centers...
I've always said login peripherals is just dumb. Only to be greeted with "it's not so bad" or "but the software is nice". I went with a mouse and keyboard that have on-board memory instead, so that after you configure them you can forget about custom software altogether.
Not gonna get cut by this razer.. I got claws!!!
WTF are you even on about?!
And yes, mandatory login for Nvidia et al is just as bad, I dont recall ever saying otherwise? Small difference though, neither MS or Nvidia habe had data leaks like this. And they do this a whole lot longer especially MS.
Find someone else to bother with your naiviety
and yeah i always try something that need login especially when related to personal data since if they make a little fault there it will be a big problem