← Intel

2024 Internal site exposure — 270k employees

2024 270.0K records affected Share on X

Data compromised

Email addresses, Names, Addresses, Phone numbers, Employee data, Internal documents

Technical writeup

Business-card ordering site (Intel India) had auth bypass. Researcher downloaded ~1GB of employee data: names, roles, managers, phones, emails, addresses. Additional sites had hardcoded creds.

Root cause

Improperly authenticated API; client-side auth bypass.

References