Saturday, February 8, 2025
HomeData BreachTypeform Suffers Data Breach, More than 20,000 User's Personal Data Was Compromised

Typeform Suffers Data Breach, More than 20,000 User’s Personal Data Was Compromised

Published on

SIEM as a Service

Follow Us on Google News

Typeform Suffers Data Breach, hackers gained access to the company servers and downloaded users personal information. Typeform is a Barcelona-based company that specializes in building online forms, quizzes, and surveys.

The hack attack happened on June 27, 2018, attacker managed to download a backup file that contains customer sensitive data. The company managed to find the root cause of the issue and fixed the vulnerability in 30 minutes.

What Data Stolen?

According to the company statement “hackers accessed data from the partial backup dated May 3rd, 2018, data collected from May 3rd, 2018 are safe.

If you are a victim of the data breach, then you will be notified with an email from Typeform recommending users to check out for potential phishing scams, or spam emails. If you don’t get an email from Typeform than you are safe.

According to Monzo, the Stolen data contains personal data of about 20,000 User’s that includes the following details.

Typeform

What data not affected?

Payment info, password and the data collected since May 3rd are safe. “performing a full forensic investigation of the incident to be certain that this cannot happen again.” reads the company statement.

Typeform published a traditional statement “we’ve identified the vulnerability and implemented measures to prevent this type of attack.”

Third data breach in a row following the data breaches of Adidas, Exactis, and Ticketmaster.

Also Read

Honda Leaked Over 50,000 Users Personal Information of it’s Honda Connect App

Dixons Carphone Suffers Massive Data Breach, 5.9 Million Payment Cards & 1.2 Million Personal Data Exposed

Massive MyHeritage Data Breach – 92 Million Users Sensitive Data Leaked

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Autonomous LLMs Reshaping Pen Testing: Real-World AD Breaches and the Future of Cybersecurity

Large Language Models (LLMs) are transforming penetration testing (pen testing), leveraging their advanced reasoning...

Securing GAI-Driven Semantic Communications: A Novel Defense Against Backdoor Attacks

Semantic communication systems, powered by Generative AI (GAI), are transforming the way information is...

Cybercriminals Target IIS Servers to Spread BadIIS Malware

A recent wave of cyberattacks has revealed the exploitation of Microsoft Internet Information Services...

Hackers Leveraging Image & Video Attachments to Deliver Malware

Cybercriminals are increasingly exploiting image and video files to deliver malware, leveraging advanced techniques...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

OpenAI Data Breach – Threat Actor Allegedly Claims 20 Million Logins for Sale

Threat actors from dark web forums claim to have stolen and leaked 20 million...

Globe Life Ransomware Attack Exposes Personal and Health Data of 850,000+ Users

Globe Life Inc., a prominent insurance provider, has confirmed a major data breach that...

BeyondTrust Zero-Day Breach – 17 SaaS Customers API Key Compromised

BeyondTrust, a leading provider of identity and access management solutions, disclosed a zero-day breach...