Contact Us

Sophos warns customers of potential data leak


UK cyber security firm Sophos has notified customers that data has potentially been leaked online due to a misconfigured database.

The company said it was alerted to the misconfiguration by a security researcher, and that it fixed the issue immediately.

However, a “small subset” of the company’s customers were affected, with first and last names, email addresses and phone numbers thought to have been accessed. Earlier this week Sophos began emailing those customers thought to have been affected.

“On November 24, 2020, Sophos was advised of an access permission issue in a tool used to store information on customers who have contacted Sophos Support,” an email to customers read, as seen by ZDNet.

It added that additional safeguards had now been implemented to ensure access permission settings can’t be exploited in the future.

This is the second major security incident in 2020 for Sophos after cyber criminals exploited a zero-day vulnerability in the firms XG firewall in April. Attackers used this to deploy ransomware but were eventually foiled by the security firm.

“At Sophos, customer privacy and security are always our top priority. We are contacting all affected customers,” the company said. “Additionally, we are implementing additional measures to ensure access permission settings are continuously secure.”

While the breach may cause some embarrassment for Sophos, the incident will unlikely lead to any major consequences for its customers or regulatory action for the company itself, according to Ilia Kolochenko, founder & CEO of web security company ImmuniWeb.

“No highly sensitive information, such as banking, health or credit card data, was reportedly exposed,” Kolochenko told IT Pro. “Moreover, many users that approach support, commonly use central phone numbers or even fake emails that are of not much value to hackers. Sophos’s open reaction to the incident seems to be swift and professional, taking accountability for the incident with adequate mitigation.

“Compared to the countless data breaches with disastrous consequences in 2020, this minor incident will unlikely to attract the attention of law enforcement agencies or regulatory authorities.”

Privacy Settings
We use cookies to enhance your experience while using our website. If you are using our Services via a browser you can restrict, block or remove cookies through your web browser settings. We also use content and scripts from third parties that may use tracking technologies. You can selectively provide your consent below to allow such third party embeds. For complete information about the cookies we use, data we collect and how we process them, please check our Privacy Policy
Consent to display content from Youtube
Consent to display content from Vimeo
Google Maps
Consent to display content from Google
Consent to display content from Spotify
Sound Cloud
Consent to display content from Sound