HomeSecurityIntel vulnerabilities allowed employee data breach

Intel vulnerabilities allowed employee data breach

Critical vulnerabilities in multiple internal Intel websites reportedly allowed the company's global employee database to be extracted and confidential supplier information to be accessed (data breach).

Intel vulnerabilities Data breach

The security flaws exposed the personal information of more than 270,000 Intel employees. The investigation by Eaton Works revealed that at least four separate internal web applications contained serious vulnerabilities (client-side authentication bypasses, hardcoded credentials, and a lack of server-side validation).

See also: Workday reveals it suffered a data breach

Intel data breach: Four 'doors' for the attacker

An unauthorized user could exploit the vulnerabilities in four different ways to download the entire employee database:

  • Business Card Website (India): With a simple JavaScript modification, the Microsoft Azure login prompt was bypassed, exposing an unprotected API that provided a valid access token. This token could then be used to query a “worker” API. By removing search filters from the API request, the researcher extracted a 1GB JSON file containing employee details: names, roles, phones, and emails.
  • “Product Hierarchy” System: It contained hardcoded credentials for its backend services. Although the password was encrypted, the AES key used was the extremely weak '1234567890123456', allowing easy decryption and access to the same database.
  • “Product Ingestion” portal: A platform associated with the public ARK product base contained a “treasure trove” of hardcoded secrets, such as multiple API keys and even a personal token for GitHub.
  • SEIMS (Supplier EHS Intellectual Property Management): The supplier collaboration portal had the most concerning vulnerability. The researcher bypassed the login by modifying the code that checked for a valid token. From there, he gained administrator access and was able to view confidential supplier data, including details of non-disclosure agreements (NDAs).
Intel vulnerabilities Data breach

Shockingly, the backend APIs even accepted crafted tokens with a value of "Not Authorized"—a simple typo that revealed a complete failure of authorization checks.

See also: US: Chinese hackers breached up to 115 million payment cards

The researcher responsibly disclosed all findings to Intel by October 14, 2024. The company's bug bounty program policy excludes web infrastructure from monetary rewards. The researcher received an automated response and no direct communication, but confirmed that Intel had fixed all reported vulnerabilities before the standard 90-day disclosure period expired.

The company maintained that no data such as social security numbers or salaries, but the leak of personal employee information and confidential partner data remains a major security failure for a tech giant of Intel's size.

What this case means for corporate security

This particular case highlights several critical issues:

  • Inadequate application security: The existence of hardcoded codes, weak keys, and incomplete API checks shows that basic DevSecOps practices are being neglected.
  • Separation of bug bounty and web security: The fact that Intel does not reward web vulnerabilities through bug bounty reduces the incentive for researchers to report problems, increasing the risk of exploitation.
  • Human errors with huge consequences: A simple typo in the token (“Not Authorized”) demonstrated how a small slip can ruin an entire access control policy.

See also: IBM: Cost of data breach in the US is rising

Intel vulnerabilities allowed employee data breach
Intel vulnerabilities: Employee data breach

Protection suggestions for businesses

  1. Secure coding & code review: Automated tests to detect hardcoded credentials and incorrect checks.
  2. API security: Use gateway and validation layers to control tokens and requests.
  3. Zero Trust approach: No trust in endpoints without multiple layers of verification.
  4. Secrets management: Store keys and tokens in vaults, never in code.
  5. Transparency & bug bounty: Expanding reward programs to cover web applications, strengthening the culture of responsible disclosure.

The Intel case is not just another “data leak.” It’s a reminder that application security cannot be an afterthought. In a world where supply chains are complex and APIs are interconnected, such omissions can be an entry point for widespread cyberattacks.

Source: cybersecuritynews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS