HomeSecurityV Shred: Client and Coach Data Leak

V Shred: Client and trainer data leak

V Shred

Fitness brand V Shred has exposed the personal information of 99,000 clients and trainers. Most worryingly, however, it has yet to fix the database issue responsible for the data leak.

V Shred is a Las Vegas-based fitness company that offers fitness programs for women and men, with a focus on fast-paced workouts, nutrition programs , and nutritional supplements. The company says it has customers in 119 countries, 12 million unique visitors to its site (per month), and over 40,000 subscribers to its university program.

On Thursday, the vpnMentor research team revealed the V Shred data breach . According to the data, an unprotected AWS S3 bucket exposed the identities of at least 99,000 people.

The discovery of the exposed bucket occurred on May 14. Initially, it contained 1.3 million files (606 GB). The files contained names, home addresses, email addresses, dates of birth, social security numbers, details for social media accounts, usernames, passwords, age, gender, nationality and other.

Among the files, there were also three .CSV files. The most important of these was the one that was 180 MB in size and contained the identity details of tens of thousands of people.

Some sections of the database, which contained nutrition guides, training programs, and user photos, remained accessible even after the breach was disclosed.

Data leak

CSV files that appear to contain coach and client information remain exposed.

In addition, the database contains client photos that show “before and after,” that is, the clients’ physical condition before they started the fitness and nutrition program and after they started it.

Based on the information that was in the database, it was not difficult to verify that V Shred was the owner. Both V Shred and AWS were notified of the issue on May 18 and May 20, respectively.

V Shred responded to the research team through Amazon customer service on June 1. In communication with the researchers, a member of the V Shred team denied that there was a data leak issue.

Initially, it said that the database was used only for storing web assets, CSS and media files, adding that if these items were not public, members would not be able to download their nutritional and athletic program.

Additionally, V Shred said that in order for someone to gain access to such content, a link would have to be shared or a user login with credentials would have to be made.

However, the researchers explained that the database is also open to anonymous users.

On June 18, the main .CSV file, which contained identity information, was removed but the rest is still accessible.

“V Shred is a new company and appears to be run by a small team”, noted VPNmentor. “However, it remains responsible for protecting the people who use its products and for signing up for its services. Without this, V Shred puts the privacy and security of individuals at risk as well as the future of the company itself”.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS