Durex India, the Indian subsidiary of the British condom and private lubricants model, has uncovered its prospects’ private data, together with their full names and order particulars.
Safety researcher Sourajeet Majumder contacted TechCrunch this week concerning the situation of exposing delicate buyer knowledge on the condom maker’s web site.
The model’s web site spilled buyer names, cellphone numbers, electronic mail addresses, transport addresses, the merchandise ordered and the quantity paid. The precise variety of affected prospects shouldn’t be identified. Nonetheless, the researcher discovered proof that tons of of individuals had data uncovered due to a scarcity of correct authentication on its order affirmation web page.
“For a model coping with intimate merchandise, guaranteeing privateness is essential,” Majumder informed TechCrunch.
TechCrunch verified Majumder’s findings, and located that buyer order particulars have been nonetheless accessible on-line on the time of writing. As such, TechCrunch is withholding sure particulars concerning the publicity as to not support malicious actors.
When reached by TechCrunch previous to publication concerning the uncovered buyer data, Ravi Bhatnagar, a spokesperson for Durex dad or mum firm Reckitt, declined to remark or say if the corporate plans to safe its prospects’ data.
The researcher informed TechCrunch that the info might be exploited for id theft, and speak to particulars might end in undesirable harassment. Majumder stated that he additionally contacted India’s Pc Emergency Response Staff (CERT-In) concerning the safety lapse, which acknowledged his electronic mail.
“Affected prospects also can turn into victims of social harassment or ethical policing due to this leak,” the researcher stated.