2014 BrowserStack — Shellshock (CVE-2014-6271); EC2 compromise; customer email outreach
Data compromised
User account–oriented contact and credential-hash descriptions in 2014 press; exact categories per BrowserStack’s incident communications
Technical writeup
In November 2014, cross-browser testing vendor BrowserStack attributed a production intrusion to exploitation of the Shellshock bash flaw on an inadequately patched machine, with contemporaneous reporting describing access to infrastructure including AWS-oriented material and follow-on abuse that included emailing portions of its user base. Public statements and security press framed exposure around account-related metadata (e.g., email and password-hash narratives in news coverage) rather than a single regulator-normalized victim tally.
Root cause
Unpatched bash / Shellshock-exploitable service exposed to network attack path