Information leak in Brazilian company Natura&Co
Natura&Co, one of the main online retail business groups in Brazil, dedicated specifically to the sale of cosmetics, suffered an information leak that affected 250,000 clients of the multinational, plus another 40,000 related to a third-party company, Wirecard.
The Safety Detectives security team, currently led by Anurag Sen, discovered the data leak, which includes personal information, on a 272 GB Amazon-hosted server located in the United States. After being informed of this, Natura & Co secured its server and removed all private data from public access.
The database contained 192 million records, including PII (Personally Identifiable Information), and other data such as full name, date of birth, nationality, credentials, email, and phone number.
- 19/05/2020 safetydetectives.com Quarter of a million customers exposed as Brazilian cosmetics brand suffers data leak
- 19/05/2020 hackread.com Brazil’s cosmetic giant Natura leaked 192 million records with payment data
- 20/05/2020 welivesecurity.com Datos personales de 250.000 clientes de Natura expuestos en Internet
- 20/05/2020 noticiasseguridad.com THE BODY SHOP, AVON Y NATURA, EMPRESAS CON CERTIFICACIÓN ISO 27001, FILTRARON DATOS DE 250 MIL CLIENTES