Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Breach - Regretsy: 1.6 Million Customer Files Exposed from Unprotected Cloud Storage
Data Breach Attacks Data Loss Prevention Data Protection News & Analysis Security

Regretsy: 1.6 Million Customer Files Exposed from Unprotected Cloud Storage

Kirsten DoyleBy Kirsten DoyleJune 2, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Million Customer Files Exposed
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Cybersecurity researchers from Cybernews have uncovered two misconfigured Azure Blob Storage containers containing more than 1.6 million files, primarily shipping email confirmations.  

The vast majority of the leaked data appears to belong to American customers, though some affected individuals are located in Canada and Australia. 

The emails were linked to purchases from Etsy, TikTok shops, Poshmark, and a vendor called Embroly. Most exposed files were HTML versions of shipping confirmations, containing sensitive customer information such as full names, home addresses, email addresses, and shipping order details. 

While it’s unclear who owns the storage buckets, metadata suggests the orders originated from custom embroidery services based in Vietnam, potentially a single operator running multiple storefronts across global e-commerce platforms. 

Serious Privacy Implications 

Etsy, in particular, is a prominent marketplace for millions of small businesses. According to researchers, this kind of data exposure has serious implications for the privacy and safety of its customers. 

This goes beyond privacy; it’s an opportunity for bad actors. With access to personal details like names, addresses, and order contents, malefactors could convincingly impersonate Etsy or a shipping provider to launch targeted phishing campaigns. 

Unfortunately, follow-up emails that include the exact product a customer ordered, their name, and address have a level of specificity that makes fraudulent messages look real. This increases the chances of a victim clicking a malicious link, confirming sensitive information, or even making a secondary payment. 

The researchers warned: “With access to personal information like full names and addresses, attackers could impersonate trusted shipping providers or Etsy itself, making fraudulent communications seem more credible and urging victims to take actions such as confirming personal details, making payment, or clicking malicious links.” 

Even more concerning is the potential for malware delivery. By crafting messages referencing recent orders, attackers could trick users into downloading harmful files or visiting malicious websites, turning a simple confirmation email into a threat vector. 

Ownership Unknown, But Patterns Emerge 

Although the exact owner of the misconfigured storage instance hasn’t been identified, its contents point to custom embroidery order processing, with several references to Vietnamese design services. This suggests a likely single seller operating across multiple platforms, with Etsy being the most affected. 

However, any identifying information about who owns or operates the exposed cloud instance is missing. That makes accountability and remediation tricky. 

How to Prevent Exposure 

The breach highlights how even small misconfigurations in cloud storage can result in large-scale data leaks.  

To prevent future incidents, researchers recommend a multi-layered approach to cloud security, including: 

  • Enforcing strict access controls to prevent unauthorized access to cloud resources 
  • Reviewing storage access logs for suspicious activity 
  • Enabling server-side encryption for data at rest 
  • Using Azure Key Vault for secure key management 
  • Ensuring secure transmission through SSL/TLS encryption 
  • Conducting routine audits and training staff on best practices for data protection 

Bottom line: E-commerce platforms like Etsy may feel like safe spaces, but third-party sellers and poor cloud hygiene can expose even the most careful customers.  

Inherent Risks in Online Shopping 

“The exposure of 1.6 million files containing shipping confirmation emails from major online marketplaces, highlights a critical cybersecurity vulnerability in e-commerce infrastructure, says Javvad Malik, Lead Security Awareness Advocate at KnowBe4. “This breach, affecting primarily U.S. customers, underscores the risks inherent in online shopping ecosystems despite their perceived security.” 
 
Malik says the leaked data, including personal details and order information, presents a significant threat for potential misuse in phishing, identity fraud, and financial scams.  

“It emphasises the urgent need for implementing and ongoing assurance for cloud storage security measures. While cloud security controls are available, organisations need a culture of security to ensure that every employee understands the role they have in securing data and the infrastructure to ensure incidents don’t occur. It underscores the crucial balance between technological solutions and human vigilance in maintaining effective cybersecurity postures, essential for preserving both data integrity and consumer trust.” 

Third-Party Blind Spots 

“Cybersecurity blind spots in third-party supply chain integrations occur daily when developers or unknowing users assume that either using obfuscation or hiding sensitive information is enough to secure cloud-connected services. It is not,” adds James McQuiggan, Security Awareness Advocate at KnowBe4.  

“When customer data is exchanged between platforms, especially in retail and e-commerce, sensitive information like names, home, and email addresses become soft targets if they are not properly secured. Security by obfuscation is not security at all. Every third-party connection is part of an organization’s attack surface. If those links to the supply chain aren’t continuously validated, monitored, and configured with the least privilege, then the risk is significant. Organisations must move beyond vendor security compliance on paper and treat every external connection as a live endpoint under threat,” McQuiggan ends. 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

7-Eleven Notifies Franchise Applicants After Breach Exposes Personal Data

May 19, 20262 Mins Read

Canvas cyberattack disrupts universities as ShinyHunters threatens massive data leak

May 12, 20267 Mins Read

Zara Owner Inditex Confirms Customer Data Breach Affecting Nearly 200,000 People

May 11, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}