HomeSecurityVirusTotal: Apologizes for the data leak of 5,600 customers

VirusTotal: Apologizes for Leaking 5,600 Customer Data

On Friday, VirusTotal apologized for leaking the information of more than 5,600 of its customers. The leak occurred when an employee accidentally uploaded a CSV file with the information to the platform last month.

See also: VirusTotal Code Insight: New AI-based malware analysis tool

VirusTotal

The data leak only affected customers with Premium accounts. The uploaded file contained their names and corporate email addresses. The online malware scanning service's head of product management, Emiliano Martines, assured affected customers that the incident was due to human error and not a cyberattack or a vulnerability in VirusTotal.

Additionally, the leaked file was only accessible to VirusTotal partners and cybersecurity analysts who have a premium account on the platform. If you are using anonymous or free accounts, you do not have access to the Premium platform and therefore, you cannot access the file.

On June 29, an employee accidentally uploaded a CSV file to the VirusTotal platform. This CSV file contained limited information about customers with Premium accounts, specifically the company names, associated VirusTotal group names, and the email addresses of the group administrators,” Martines said Friday.

We removed the file, which was only accessible to partners and corporate customers, from our platform within an hour of its posting.

See also: VirusTotal: What did the analysis of 80 million ransomware samples show?

While VirusTotal can be used for free by anyone who wants to check a specific file or URL via a web-based user interface, the paid version of the service is only available to companies and public sector organizations, allowing them to have more information about the uploaded samples. Uploaded files are also shared with security companies, professionals and researchers, VirusTotal customers or partners.

data leak

On Monday, German news agencies Der Spiegel and Der Standard first reported on the incident. As reported, the stolen 313 KB file contained details of accounts belonging to official United States agencies, including the White House, the Department of Justice, the FBI and the NSA.

Additionally, the file included accounts linked to government agencies in Germany, the Netherlands, Taiwan, and the United Kingdom.

"It is a list of 5,600 names, including employees of the American intelligence agency NSA and German intelligence services," Der Spiegel reported.

Twenty accounts alone lead to the US Cyber ​​Command, part of the US military and a hub for offensive and defensive hacking. Also affected: the US Department of Justice, the US Federal Bureau of Investigation (FBI) and the NSA.

The file also contained information about national authority officials in various countries, including the Netherlands, Taiwan and the United Kingdom, as well as German government agencies such as the Federal Intelligence Service, the Federal Police and the Military Counterintelligence Agency (MAD).

See also: VirusTotal: Adds new threat detection capabilities!

The leaked file contained information about dozens of employees at the Bundesbank, Deutsche Bahn, Allianz, BMW, Mercedes-Benz and Deutsche Telekom.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS