
Vulnerabilities in WiFi in the company's Manhattan building that exposed sensitive company data were discovered by a tenant in the same building who wanted to make sure his organization's data hadn't been leaked.
What happened?
Temmu Airamo, a tenant at WeWork, shares the building with about 200 companies.
In 2015, his organization was working with sensitive documents. To ensure there were no security, he ran a network scan and found financial records and devices belonging to other companies.
Airamo systematically scans WiFi networks and says nothing has changed in four years, despite multiple attempts to contact WeWork management.
The vulnerability was first reported by Fast Company.
It was also discovered that many WeWork-owned workspaces use the same password for WiFi networks. These passwords were also easy to guess.
More details
The building houses many financial and legal firms that handle a lot of sensitive data. This vulnerability has also been found to affect companies that don't have offices in any of WeWork's workspaces, but work with an organization in the building.
Data belonging to two loan companies was found online .These companies do not have offices in California or New York, where WeWork's workspaces are located.
An insurance company, Axa XL, was also affected by this vulnerability. The leak in this case is believed to be due to its collaboration with a start-up housed in WeWork’s workspace.
Airamo started using VPNafter discovering security vulnerabilities in the WiFi network.
