← Whirlpool

2019 Whirlpool — internet-exposed smart-appliance scan database (tens of thousands of contact emails)

2019 48.0K records affected Share on X

Data compromised

Customer email, Smart Appliance IDs, and model/scan metadata per SecurityDiscovery reporting

Technical writeup

Security researchers notified Whirlpool of a publicly reachable Elasticsearch-style datastore holding smart-appliance connectivity metadata—customer email addresses, appliance identifiers, and model information tied to online scans—with Whirlpool quoted acknowledging on the order of forty-eight thousand email exposures and downplaying confidential-content risk while securing the bucket within about a day of researcher contact.

Root cause

Cloud datastore misconfiguration exposing appliance telemetry and user contact material to unauthenticated internet retrieval

References