Nextgov Staff | Nextgov | March 6, 2017 | 0 Comments

Slack and Teddy Bears Leak Your Secrets; Boeing Employee Sends Personnel Data to His Wife

Kidsada Manchinda/

In case you missed our coverage this week in ThreatWatchNextgov’s regularly updated index of cyber breaches:

Slack Quickly Patches Bug That Allowed Access to Chats

Slack, a team messaging app, in five hours patched a bug that allowed a hacker access to a user’s communications.

That includes all the private messages where users may be less likely to talk strictly work.

Detectify Labs security researcher Frans Rosén determined he could steal users' private tokens—which allow access to the user’s communications—by tricking them with a malicious web page.

According to Rosén, Slack responded to his first notification 33 minutes after he sent it and resolved the issue within five hours. The company also paid him $3,000 for reporting the bug.

Internet-Connected Teddy Bear Don't Keep Secrets

A high-tech toy teddy bear exposed more than 2 million voice messages from children and parents by using poor security practices, according to a security researcher.

Spiral Toys’ CloudPets brand of internet toys reads like a list of security don’ts. The company stored customer credentials in a publicly available online database that didn’t require a password and wasn’t behind a firewall while it put audio messages in an Amazon-hosted service that didn’t require authorization, according to a Feb. 27 blog by Troy Hunt, who maintains Have I Been Pwned? breach notification service.

The company hashed customers’ credentials, but it didn’t establish any password strength requirements so capable hackers would be able to crack large chunks of the more than 800,000 credentials, Hunt wrote. Some passwords, for example, were a single letter or commonly used passwords like “password,” “123456” and “cloudpets.”

The data was exposed from Christmas to sometime in January, and Motherboard reports it was also accessed and held for ransom multiple times in a wave of attacks on MongoDB databases.

Hunt says the company was alerted several times about the breach, but never responded. Mark Myers, Spiral Toys CEO, told Network World no voice recordings were stolen.

“Circling back to the parents' position for a moment, you must assume data like this will end up in other peoples' [sic] hands,” Hunt wrote. “Whether it's the Cayla doll, the Barbie, the VTech tablets or the CloudPets, assume breach. It only takes one little mistake on behalf of the data custodian—such as misconfiguring the database security—and every single piece of data they hold on you and your family can be in the public domain in mere minutes.”

Boeing Employee Emails 36,000 Coworkers' Personal Info to Spouse

Boeing has started notifying the 36,000 employees whose personal information was mistakenly leaked via email, according to Threatpost.

A Boeing employee had a problem formatting a spreadsheet and emailed it to his spouse for help, wrote Boeing Deputy Chief Privacy Officer Marie Olson in a letter to the Washington State attorney general notifying the state of the data breach.

The spreadsheet contained names, birthdates, Social Security numbers, and other accounting code and employee identification information—but tucked away in “hidden” columns. The employee sent the email Nov. 21, though it wasn’t discovered until January.

Boeing is offering employees two years of identity protection services.


Thank you for subscribing to newsletters from
We think these reports might interest you:

  • It’s Time for the Federal Government to Embrace Wireless and Mobility

    The United States has turned a corner on the adoption of mobile phones, tablets and other smart devices, outpacing traditional desktop and laptop sales by a wide margin. This issue brief discusses the state of wireless and mobility in federal government and outlines why now is the time to embrace these technologies in government.

  • Featured Content from RSA Conference: Dissed by NIST

    Learn more about the latest draft of the U.S. National Institute of Standards and Technology guidance document on authentication and lifecycle management.

  • A New Security Architecture for Federal Networks

    Federal government networks are under constant attack, and the number of those attacks is increasing. This issue brief discusses today's threats and a new model for the future.

  • Going Agile:Revolutionizing Federal Digital Services Delivery

    Here’s one indication that times have changed: Harriet Tubman is going to be the next face of the twenty dollar bill. Another sign of change? The way in which the federal government arrived at that decision.

  • Software-Defined Networking

    So many demands are being placed on federal information technology networks, which must handle vast amounts of data, accommodate voice and video, and cope with a multitude of highly connected devices while keeping government information secure from cyber threats. This issue brief discusses the state of SDN in the federal government and the path forward.

  • The New IP: Moving Government Agencies Toward the Network of The Future

    Federal IT managers are looking to modernize legacy network infrastructures that are taxed by growing demands from mobile devices, video, vast amounts of data, and more. This issue brief discusses the federal government network landscape, as well as market, financial force drivers for network modernization.


When you download a report, your information may be shared with the underwriters of that document.