2020 Sophos — customer support database misconfiguration exposed contact data
Data compromised
Names, email addresses, phone numbers (where collected for support)
Technical writeup
Sophos stated a security researcher reported an access-permission issue in an internal tool used to store information about customers who had contacted Sophos Support. The company described exposure limited to a small subset of customers, with fields such as first and last name, email address, and phone number where provided. Sophos characterized the issue as a misconfiguration, reported rapid remediation, and noted it was separate from the April 2020 XG Firewall zero-day intrusion campaign.
Root cause
Access-control / permission misconfiguration in a customer-support information store