A flaw in an AT&T web application exposed the email addresses of around 114,000 owners of Apple’s new iPad 3G. The weakness was found by a group calling itself Goatse Security, whose members harvested the addresses by sending the site SIM card identifiers.
What happened
- The group used a script that submitted ICC-IDs (SIM identifiers) with a spoofed iPad user agent, and the site returned the matching email address.
- Those exposed reportedly included media chief executives, technology executives, and staff at NASA, the FAA, and US military agencies.
- AT&T said it had disabled the feature that returned the addresses and notified affected customers.
- Two people linked to the group were later charged in the US; one conviction was overturned on appeal in 2014.
Why it mattered
The incident showed how a simple enumeration flaw in a web service could expose data about high-profile users of a flagship product, and it fuelled debate about how researchers should disclose vulnerabilities.
Lessons for organisations
Test web applications and APIs for insecure direct object references and enumeration before launch, and rate-limit lookups. A clear vulnerability disclosure policy makes it easier for researchers to report issues responsibly.
Source: Engadget
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.