Property Abroad
Blog
Data leak: CRM provider Really Simple Systems has lost 3 million customer records.

Data leak: CRM provider Really Simple Systems has lost 3 million customer records.

Data leak: CRM provider Really Simple Systems has lost 3 million customer records.

Provider of customer relationship management (CRM) systems - Really Simple Systems experienced a data security issue that resulted in more than 3 million customer records being accessible to the public without password or authentication.

The information was stored in an unsecured database, which was discovered by cybersecurity researcher Jeremiah Fowler of vpnMentor. Fowler only had access to a limited sample of the data, but the sample was enough to establish that the leak affected documents from multiple organizations of various industries and sizes. Most of them are well-known high profile organizations in the EU, US, UK and''Australia.

Fowler noted that many of the leaks could be classified as "highly sensitive" because they exposed personally identifiable information (PII). This data was publicly available to anyone with an internet connection. Among the leaks were internal communications and invoices, as well as customer CRM files containing valuable user information such as names, phone numbers, addresses, email IDs and payment data.

Additional investigation revealed that the database also contained medical records, real estate contracts, identification documents, credit reports, disability applications, tax and legal documents, and non-disclosure agreements.

Recommended real estate
Buy in USA for 5259600€

Sale flat in New York 5 693 381,00 $

3 Bedrooms

4 Bathrooms

203 м²

Buy in USA for 17249300€

Sale penthouse in New York 18 671 922,00 $

3 Bedrooms

3 Bathrooms

3653 м²

Buy in USA for 9210300€

Sale townhouse in New York 9 969 912,00 $

7 Bedrooms

7 Bathrooms

694 м²

Buy in Italy for 1587900€

Sale house in Naples 1 718 860,00 $

3 Bedrooms

3 Bathrooms

212 м²

Buy in USA for 4573600€

Sale flat in New York 4 950 804,00 $

3 Bedrooms

3 Bathrooms

223 м²

Buy in Italy for 719000€

Sale flat in Naples 778 298,00 $

2 Bedrooms

2 Bathrooms

190 м²

Many of these documents''contained social security numbers and taxpayer identification numbers. A significant set of confidential child psychological evaluation files was discovered in one of the client's folders.

What's more, the database revealed numerous templates of internal documents belonging to Really Simple Systems that contained billing data, letters, invoices, service agreements, etc. One such template pertained to an educational platform offering school management services.

After discovering the database, Fowler sent a notice of responsible disclosure. At Fowler's request, the folder containing the educational platform information was removed from public access on the same day, in''notified of the incident and asked to monitor their credit reports and change their passwords.

Comment