← Klarna

2021 Account mix-up — 9,500 users

2021 9.5K records affected Share on X

Data compromised

Postal addresses, purchase history, partial card details

Technical writeup

May 2021. Technical error caused users to be accidentally logged into other people's accounts for 31 minutes. Exposed: postal addresses, past purchases, partial card details. Initially reported up to 90,000 users; revised to max 9,500. CEO described as self-inflicted incident from human error.

Root cause

Human error; incorrect cache/session configuration.

References