← Change.org

2015 Search vulnerability — email addresses exposed

2015 100 records affected Share on X

Data compromised

Email addresses

Technical writeup

Bug in Change.org's system disclosed private email addresses through the site's search function. GET request tokens meant for authenticated users were incorrectly added to unauthenticated links. Unsubscribe links pasted on public pages were indexed by Google and Bing. Approximately 100 email addresses ultimately exposed; 40,000–65,000 search results returned. Search disabled during investigation.

Root cause

Authentication token bug; unintended disclosure.

References