Security News Someone hacked Johnson & Johnson's internal systems to teach it a lesson

lokamoka820

Level 48
Thread author
Verified
Top Poster
Well-known
Mar 1, 2024
3,700
3
12,855
4,669
Banana Republic
A cybersecurity researcher uncovered two authentication flaws in Johnson & Johnson web applications that exposed sensitive recruiter tools, employee records, and an internal audit management system.

Both vulnerabilities stemmed from improper backend authentication, allowing attackers to bypass Microsoft SSO by manipulating client-side code because the servers failed to verify user identity.

The flaws exposed highly sensitive data, including information on nearly 1,000 student applicants, approximately 13,600 employee records, and confidential audit data across about 20 J&J business units.

The researcher responsibly disclosed the vulnerabilities in October 2025, but while the recruiting platform was fixed quickly, the critical audit system remained vulnerable for six months until media involvement prompted remediation.