Case studies – Real-world examples of API encryption attacks
In a real-world example of API encryption vulnerability, Beetle Eye, an online tool for streamlining email marketing campaigns, suffered a data breach due to a misconfigured AWS cloud storage bucket. Researchers from Website Planet discovered that the AWS S3 bucket was left exposed without password protection or encryption, compromising more than 6,000 files and over 1 GB of data.
The exposed records contained various forms of personally identifiable information (PII) related to leads or potential customers of companies using Beetle Eye’s marketing automation platform. The researchers found multiple folders within the open bucket, each containing data for one of the exposed clients. Three different datasets were uncovered: unnamed leads, GoldenIsles.com leads, and Colorado.com leads.
Notably, the breach exposed sensitive information in plaintext without any encryption, a practice deemed inexcusable by...