APIsec, a company specializing in API security testing, exposed sensitive customer data through an unprotected internet-connected database. Upon discovery by UpGuard, it was found that the database contained names, email addresses, and details pertaining to the API security of its clients, including the status of 2FA activation. Initially downplayed by APIsec as 'test data', evidence confirmed real-world customer information was included. The company later notified affected parties although the extent of the breach was not disclosed.
"id": "api1011040125",
"linkid": "apisec",
"type": "Breach",
"date": "4/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"