Smith System Driver Improvement Institute, Inc.

Smith System Driver Improvement Institute, Inc.

Suwaiz describes himself as being motivated by bug bounties when there’s no bounty to be had, he just gives information that he finds to companies to help them secure their data.

Suwaiz informed Smith system that they are exposing all the customer data , their billing address and Credit card detail.

But the Smith System didn't paid attention to his findings and apparently blocked him.

Source: https://www.databreaches.net/he-tried-to-tell-you-youre-leaking-data-even-after-you-stupidly-blocked-him/

TPRM report: https://scoringcyber.rankiteo.com/company/smith-system

"id": "smi16129622",
"linkid": "smith-system",
"type": "Vulnerability",
"date": "03/2018",
"severity": "60",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'name': 'Smith System', 'type': 'Company'}],
 'attack_vector': 'Information Disclosure',
 'data_breach': {'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Billing Address',
                                              'Credit Card Details']},
 'description': 'Suwaiz, a bug bounty hunter, found that Smith System was '
                'exposing customer data, including billing addresses and '
                'credit card details. Smith System did not respond to his '
                'findings and blocked him.',
 'impact': {'data_compromised': ['Billing Address', 'Credit Card Details'],
            'payment_information_risk': 'High'},
 'motivation': 'Bug Bounty',
 'threat_actor': 'Suwaiz',
 'title': 'Data Exposure Incident at Smith System',
 'type': 'Data Exposure',
 'vulnerability_exploited': 'Exposure of Customer Data'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.