Thread Starter
#1
Micromax Goofs Up! Reveals Sensitive Data Of Canvas 4 Pre-Order Customers
Ok, it's official now. The much hyped "India's largest smartphone pre-booking" has gone horribly wrong for a bunch of Canvas 4 pre-order customers. We were wondering how so many of them who didn't get their pre-ordered Canvas 4 phones on time, were able to find each other and organize a mailing list. Gizmodo India now has the answer - the company itself gave it to them on a platter!
We have confirmation that many pre-order customers received an email (on the Canvas 4 launch date) confirming that the balance amount of Rs 13,000 (the initial 5k was deducted at time of pre-order itself) had been deducted from their credit cards. This email (which was forwarded to us with an authentic header file) shockingly contained the order receipts of nearly 130 other customers! And get this - it INCLUDED their shipping and billing addresses, phone numbers, email addresses and even the pre-order site's login and password for every customer!!! We've got to say that this is a mind-boggling level of carelessness on display.
"It is a high security threat as it was having details of customers' mobile numbers, login details with passwords to verify the order at the MMX website. And after login, one can change (shipping) address in their profile. What if such data would have gone in email of a person having destructive mind?" says one of these customers over email.
Well, customers thankfully did something constructive instead and alerted each other about the privacy breach. Eventually they began sharing updates on their attempts to contact the company and of course a Facebook group followed.
We forwarded the original offending mail from Micromax customer support back to the company more than 24 hours ago but are yet to hear from them. Here's what one of the receipts contained in that email looks like, minus the sensitive info which we've blurred out:
image http://www.gizmodo.in/photo/21368839.cms
source Micromax Goofs Up! Reveals Sensitive Data Of Canvas 4 Pre-Order Customers | Gizmodo India
Ok, it's official now. The much hyped "India's largest smartphone pre-booking" has gone horribly wrong for a bunch of Canvas 4 pre-order customers. We were wondering how so many of them who didn't get their pre-ordered Canvas 4 phones on time, were able to find each other and organize a mailing list. Gizmodo India now has the answer - the company itself gave it to them on a platter!
We have confirmation that many pre-order customers received an email (on the Canvas 4 launch date) confirming that the balance amount of Rs 13,000 (the initial 5k was deducted at time of pre-order itself) had been deducted from their credit cards. This email (which was forwarded to us with an authentic header file) shockingly contained the order receipts of nearly 130 other customers! And get this - it INCLUDED their shipping and billing addresses, phone numbers, email addresses and even the pre-order site's login and password for every customer!!! We've got to say that this is a mind-boggling level of carelessness on display.
"It is a high security threat as it was having details of customers' mobile numbers, login details with passwords to verify the order at the MMX website. And after login, one can change (shipping) address in their profile. What if such data would have gone in email of a person having destructive mind?" says one of these customers over email.
Well, customers thankfully did something constructive instead and alerted each other about the privacy breach. Eventually they began sharing updates on their attempts to contact the company and of course a Facebook group followed.
We forwarded the original offending mail from Micromax customer support back to the company more than 24 hours ago but are yet to hear from them. Here's what one of the receipts contained in that email looks like, minus the sensitive info which we've blurred out:
image http://www.gizmodo.in/photo/21368839.cms
source Micromax Goofs Up! Reveals Sensitive Data Of Canvas 4 Pre-Order Customers | Gizmodo India