9 July 2024

Zotac exposes customers' RMA information on Google Search


Zotac exposes customers' RMA information on Google Search

Computer hardware manufacturer Zotac inadvertently exposed Return Merchandise Authorization (RMA) requests and related documents online, compromising sensitive customer information for an unknown duration.

The cause of the issue was the misconfiguration of the web folders containing RMA data, which led to search engines indexing affected folders, making them accessible through Google Search.

The exposure appears to stem from insufficient permissions restricting access to authorized users only, such as Zotac employees, and the absence of tags or a 'robots.txt' file to instruct web crawlers to exclude the sensitive folders, according to BleepingComputer.

Google Search queries using people's or company names alongside the 'zotacusa.com' site parameter could reveal personal information, including invoices, addresses, request details, and contact information.

The security lapse, affecting an unspecified number of Zotac customers, was initially discovered by a viewer of the YouTube tech channel GamersNexus. The channel reported the breach late last week on X (formerly Twitter), without initially naming Zotac.

GamersNexus informed several of Zotac’s major partners to raise awareness about the data exposure. Remedial actions are currently underway, with the majority of the private documents no longer publicly accessible.

GamersNexus eventually contacted a Zotac spokesperson, who confirmed that the company had disabled the document upload feature on their RMA portal. Customers are now instructed to email files accompanying their requests as an interim solution.


Back to the list

Latest Posts

Cyber Security Week in Review: October 4, 2024

Cyber Security Week in Review: October 4, 2024

In brief: the US disrupts FSB-linked ColdRiver hackers’ operations, Lockbit and EvilCorp members arrested, and more.
4 October 2024
Critical Ivanti EPM RCE flaw exploited in the wild

Critical Ivanti EPM RCE flaw exploited in the wild

The flaw is an SQL Injection issue that allows a remote attacker to execute arbitrary SQL queries in database.
3 October 2024
New China-aligned threat actor CeranaKeeper steals data from Southeast Asian entities

New China-aligned threat actor CeranaKeeper steals data from Southeast Asian entities

CeranaKeeper is notable for its evolving backdoor techniques, which allow it to evade detection and facilitate extensive data theft.
3 October 2024