Oh boy. A simple #enumeration #attack could be used to read credit offers at #CHECK24 and #verivox, two big German portal offering a lot of things around comparing credit offers, insurance contracts and other things.
This is such a trivial mistake, it nearly feels deliberate. This should never ever happend. And for sure this should have be a red flag in any #securityaudit. I wonder how they can state "No indications of miss use.". #cybersecurity
Article in German:
https://correctiv.org/aktuelles/datenschutz/2024/09/17/kreditvermittlung-bei-check24-und-verivox-kritische-datenlecks-entdeckt/
And just to be very clear: this is not single developers, or single teams making a mistake. This looks like a problem in the organizations.
Such attacks are well known and must be included in any basic training for #softwaredeveloper, especially #webdeveloper. Such #enumeration #attacks are one of the first things a #securityaudit should test, find and report. If #check24 and #verivox claim to have done some, either they did not act on the findings or executed them very badly. #cybersecurity