← Sophos

2020 Sophos — incident exposing customer contact and device metadata stored in a cloud portal

2020 Unknown records affected Share on X

Data compromised

Customer names, emails, and limited device/housekeeping fields described by Sophos

Technical writeup

Sophos disclosed a data access incident where a misused API key exposed information for a subset of customers to an unauthorized third party; Sophos published indicators, scope, and corrective actions.

Root cause

Misuse of cloud API credential exposing support portal exports (per Sophos disclosure)

References