ADVERTISEMENT

Over a million exposed as Slovenian retailer leaks data

Slovenian retailer DFVU, known for brands like S-mania, Layoners, Mazzaci, and RedLynx, left its customers' private data open, exposing 1.1 million individuals and company administrators.

DFVU

Image by Cybernews.

Ernestas Naprys
Ernestas Naprys Senior Journalist
January 19, 2024 Updated: January 19, 2024 2 min read
  • Personal information, such as names, addresses, email addresses, and phone numbers, belonging to 1,142,019 unique individuals.
  • Credentials of 67 Administrator accounts. Passwords were hashed with MD5, an outdated and insecure algorithm. The information included the endpoints where credentials were used to authenticate. Cracked credentials, therefore, could be used to access specific resources.
  • Operational information, such as addresses of warehouses or the providers that DFVU uses for facilitating deliveries.
  • Credentials for multiple other resources on their network (host, username, password(SHA-1/SHA-128), user permissions).
DFVU open directory
ADVERTISEMENT

Bonanza for malicious hackers

DFVU data leak
ADVERTISEMENT