2015 Search vulnerability — email addresses exposed
Data compromised
Email addresses
Technical writeup
Bug in Change.org's system disclosed private email addresses through the site's search function. GET request tokens meant for authenticated users were incorrectly added to unauthenticated links. Unsubscribe links pasted on public pages were indexed by Google and Bing. Approximately 100 email addresses ultimately exposed; 40,000–65,000 search results returned. Search disabled during investigation.
Root cause
Authentication token bug; unintended disclosure.