Groupon India accidentally leaks entire user data base

email article email article print article print article tip @techmeme

The Indian subsidiary of online deals giant Groupon has accidentally published email addresses and passwords of its 300,00-strong subscriber database, reports and the company said.

Daniel Grzelak, founder of the Internet security website shouldichangemypassword.com, found the security breach of sosasta.com while running a Google search for publicly available databases.

The relative ease with which Grzelak was able to access the database is the most concerning aspect of this development. The approach he took is far removed from that of the dedicated hackers who recently gained access to the user databases of Sony’s PlayStation network and Sega’s Pass network. Indeed, the manner in which he conducted his search suggests that the information could have been attained by any web searcher with enough time and patience.

“A few hours and tweaks later, this database came up,” he told the Internet security site risky.biz, “I started scrolling, and scrolling, and I couldn’t get to the bottom of the file. Then I realised how big it actually was.”

Sosasta.com, an online discount portal offering deals in all major Indian cities was acquired by Groupon in January 2011. The subsidiary alerted its subscribers on Tuesday and posted a message on its Facebook page asking users to “change your Sosasta password immediately”.

“Over this weekend, we have been alerted to a security issue potentially affecting subscribers of Sosasta. We wanted to let you know that the issue has been brought under control and your accounts are secure,” the message said.

Grzelak’s website shouldichangemypassword.com holds a database of 1.3 million compromised email addresses, allowing users to check if their own email address is among those deemed unsafe.

“There are thousands of these databases indexed by Google,” he told Risky.biz. “This just happened to be by far the biggest I found.”
Groupon said it would review Sosasta’s security procedures and put in place “measures designed to prevent this kind of issue from recurring,” risky.biz reported.

“Groupon takes security and privacy very seriously. Our users’ trust is of paramount importance to us and we deeply regret this incident,” it quoted the firm as saying. “This issue does not affect data from any other country or region.”

Groupon, based in Chicago, announced plans to go public earlier this month, after turning down a $6 billion takeover offer from Google last year. It currently has 83.1 million subscribers and operates in 43 countries.
The company operates on the principle of collective buying, negotiating with businesses to offer discounted purchases which come into effect when a minimum number of subscribers agree to pay for the same deal.–(AFP)

email article email article print article print article

Related Articles on the Web

Related articles

Topics for this article

[ advertising enquiries ]

Share
  • BURN MEDIA TV

    WATCH THE LATEST EPISODE NOW
    Latest Episode
    Review of Facebook Group app

MORE HEADLINES

news

VIEW MORE

interviews

VIEW MORE

future trends

VIEW MORE

entrepreneurship

VIEW MORE

social media

VIEW MORE

facebook

VIEW MORE

twitter

VIEW MORE

google

VIEW MORE

advertising & marketing

VIEW MORE

online media

VIEW MORE

design

VIEW MORE

mobile

VIEW MORE

More in News

Twitter co-founder steps back for new venture

Read More »