Get the latest tech news

Employees of Failed Startups Are at Special Risk of Stolen Personal Data Through Old Google Logins


Hackers could steal sensitive personal data from former startup employees by exploiting abandoned company domains and Google login systems, security researcher Dylan Ayrey revealed at ShmooCon conference. The vulnerability particularly affects startups that relied on "Sign in with Google" features f...

Hackers could steal sensitive personal data from former startup employees by exploiting abandoned company domains and Google login systems, security researcher Dylan Ayrey revealed at ShmooCon conference. The vulnerability particularly affects startups that relied on "Sign in with Google" features for their business software.Ayrey, CEO of Truffle Security, demonstrated the flaw by purchasing one failed startup's domain and accessing ChatGPT, Slack, Notion, Zoom and an HR system containing Social Security numbers. The company initially dismissed Ayrey's finding as a fraud issue before reversing course and awarding him a $1,337 bounty.

Get the Android app

Or read this on Slashdot

Read more on:

Photo of employees

employees

Photo of failed startups

failed startups

Photo of stolen personal data

stolen personal data

Related news:

News photo

Employees Enter Sensitive Data Into GenAI Prompts Far Too Often

News photo

Employees of failed startups are at special risk of stolen personal data through old Google logins

News photo

Employees are spending the equivalent of a month’s groceries on the return-to-office—and growing more resentful than ever, survey finds