06-01-2015 12:49 via feeds.theguardian.com

Personal details of all MoonPig customers exposed by security bug

The mobile apps for greetings card maker MoonPig have been closed to protect users from a vulnerability that lay unfixed for almost a year and a halfGreetings card website Moonpig has shut down its mobile apps after a security bug exposed personal details of 3 million customers.The flaw, described by one observer as “the worst security I’ve ever seen from a large company”, let any attacker access the personal details of every single customer on the website, as well as view past orders and
Read more »