Powered by MOMENTUM MEDIA
cyber daily logo
Breaking news and updates daily. Subscribe to our Newsletter

Durex India fails to use protection, leaks customer data online

Customers of condom and lubricant manufacturer Durex’s Indian subsidiary have had their data exposed online as the result of insufficient protection.

user icon Daniel Croft
Fri, 30 Aug 2024
Durex India fails to use protection, leaks customer data online
expand image

The Indian subsidiary of the condom maker reportedly leaked customer details on its website, including names, phone numbers, email addresses, product order history, shipping addresses and amount paid.

Speaking with TechCrunch, the security researcher who discovered the breach, Sourajeet Majumder, said that while the number affected by the breach is currently unknown, the data is still publicly accessible and that evidence of hundreds of people had been exposed. Details of the exposure have, therefore, been withheld by the media to prevent threat actors from using it.

“For a brand dealing with intimate products, ensuring privacy is crucial,” Majumder told TechCrunch.

============
============

The sensitive and personal nature of the data could be used by threat actors for extortion purposes, with scammers threatening to publicise data if they don’t receive payment. Additionally, other personal details could be used for future scams.

While Durex India is yet to comment on the incident, it does not appear that any financial or banking details other than the amount paid have been exposed.

TechCrunch reached out to Ravi Bhatnagar of Reckitt, Durex’s parent company, but received no comment.

It is unclear when Durex will fix the issue; however, Majumder said he had contacted India’s Computer Emergency Response Team (CERT-In) about the issue.

Cyber Daily has reached out to Durex for additional commentary.

Daniel Croft

Daniel Croft

Born in the heart of Western Sydney, Daniel Croft is a passionate journalist with an understanding for and experience writing in the technology space. Having studied at Macquarie University, he joined Momentum Media in 2022, writing across a number of publications including Australian Aviation, Cyber Security Connect and Defence Connect. Outside of writing, Daniel has a keen interest in music, and spends his time playing in bands around Sydney.

newsletter
cyber daily subscribe
Be the first to hear the latest developments in the cyber industry.