Live Chat Widgets Leak Employee Details From High-Profile Companies

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
At least two live chat widgets used on hundreds of high-profile sites are leaking the personal details of company employees.
The vulnerable widgets are used on sites managed by Google, Verizon, Spring, Bank of America, PayPal, Orange, Sony, Tesla, Bitdefender, Kaspersky Lab, Disney, and many others.

The leak occurs when an attacker engages in a live chat session with a support staffer. According to Project Insecurity researchers Cody Zacharias and Kane Gamble, the widgets leak information on the support staffer, such as his real name, company email address, employee ID, support center name, location, supervisor name, supervisor ID, or software used by the employee.

Not all companies leak support staffer data

These details vary from company to company, depending on how each business has set up its support widgets, and for some, no information may leak.
Bleeping Computer was able to confirm the leak on several sites, albeit not all we tested were exposing employee data. We will not name the sites where the live chat widgets leaked employee data, for security reasons.
.....
.........
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top