API testing firm APIsec exposed customer data during security lapse

APIsec Acknowledges Security Lapse That Exposed Customer Data
Photo: TechCrunch

APIsec Acknowledges Security Lapse That Exposed Customer Data

APIsec, a company specializing in API security testing, recently confirmed that it had secured an exposed internal database containing customer information. The database, which was publicly accessible for several days without a password, contained records dating back to 2018, including customer employees’ names, email addresses, and security posture details. The exposure was discovered by UpGuard, a security research firm, on March 5, and APIsec promptly secured the database after being notified.

Initially, APIsec’s founder, Faizel Lakhani, downplayed the incident, stating that the data was merely test data and not from the company’s production environment. However, evidence presented by UpGuard indicated that real customer data, including API vulnerability scans and personal information, had been exposed. Lakhani later admitted that the company re-evaluated the breach and notified affected customers.

Additionally, the leaked database contained private keys for AWS, as well as credentials for Slack and GitHub accounts, though APIsec claimed these belonged to a former employee and had been deactivated. APIsec did not confirm whether it had notified authorities as required by data breach laws. The incident underscores the importance of securing API-related data, given the potential risk of exploitation by malicious actors.

Leave a Reply

Your email address will not be published. Required fields are marked *