2024 Internal site exposure — 270k employees
Data compromised
Email addresses, Names, Addresses, Phone numbers, Employee data, Internal documents
Technical writeup
Business-card ordering site (Intel India) had auth bypass. Researcher downloaded ~1GB of employee data: names, roles, managers, phones, emails, addresses. Additional sites had hardcoded creds.
Root cause
Improperly authenticated API; client-side auth bypass.