18 July 2023

VirusTotal leak exposes data of over 5K registered users


VirusTotal leak exposes data of over 5K registered users

Google-owned malware-scanning platform VirusTotal has reportedly suffered a leak that exposed the names and email addresses of 5,600 of its registered users, including information about employees of US and German intelligence agencies.

As per Der Spiegel’s report, the exposed information includes twenty accounts from the US Cyber Command, the FBI, the US National Security Agency, German secret service, Dutch, Taiwanese, British, Austrian government employees.

The leak also includes data about employees of multiple German corporations such as Deutsche Bahn, the Bundesbank and various Dax giants such as Allianz, BMW, Mercedes-Benz and Deutsche Telekom.

The report notes that leaked data includes only account holders’ names and email addresses, other crucial information such as passwords appears to be not affected.

Google’s spokesperson told Der Spiegel that the cause of the leak was a VirusTotal employee who “unintentionally made a small part” of customer data available on the platform.

“We removed the list from the platform within an hour of uploading it,” the spokesperson said. “We are working on improving internal processes and technical controls to prevent this in the future.”

Back to the list

Latest Posts

What is Vulnerability Management? A Beginner's Guide

What is Vulnerability Management? A Beginner's Guide

In this article will try to cover basics of vulnerability management process and why it is important to every company.
11 September 2024
Cyber Security Week in Review: September 6, 2024

Cyber Security Week in Review: September 6, 2024

In brief: the US charges Russian GRU hackers for attacks on Ukraine, Apache, Cisco, Zyxel patch high-risk flaws, Google fixes Android zero-day, and more.
6 September 2024
Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Some of the documents appeared to be part of legitimate Red Team exercises, while other were intended for malicious purposes.
5 September 2024