Latest in Entertainment

Image credit:

MoviePass confirms breach that leaked credit card numbers

The data had been available for months until a TechCrunch report highlighted it.
Richard Lawler, @Rjcc
August 21, 2019
1 Shares
Share
Tweet
Share

Sponsored Links

Mike Segar / Reuters

On Tuesday TechCrunch reported that security researcher Mossab Hussein, with the firm SpiderSilk, found an exposed, unencrypted MoviePass database with millions of records. Some of those included numbers for its custom debit cards that are used when subscribers purchase tickets, while others listed customer's personal information including their credit card numbers, expiration dates and billing information. Another researcher had located the vulnerable information back in July and notified the company, but neither was able to get a response, while yet another found evidence the database had been public since May of this year.

MoviePass took the database offline yesterday after the report, and today finally publicly responded with a statement from a spokesperson.

MoviePass recently discovered a security vulnerability that may have exposed subscriber records. After discovering the vulnerability, we immediately secured our systems to prevent further exposure and to mitigate the potential impact of this incident. MoviePass takes this incident seriously and is dedicated to protecting our subscribers' information. We are working diligently to investigate the scope of this incident and its potential impact on our subscribers. Once we gain a full understanding of the incident, we will promptly notify any affected subscribers and the appropriate regulators or law enforcement.

The company put its services "on hold" in July while saying it was working on its app, but couldn't close this security hole -- despite apparent attempts at notifications before restoring access "to a substantial number of our current subscribers."

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Comment
Comments
Share
1 Shares
Share
Tweet
Share

Popular on Engadget

The 2020 Engadget Holiday Gift Guide

The 2020 Engadget Holiday Gift Guide

View
The best Cyber Week tech deals you can still get today

The best Cyber Week tech deals you can still get today

View
Amazon’s free news app on Fire TV now features local stations

Amazon’s free news app on Fire TV now features local stations

View
Razer Tomahawk modular gaming PC is now available for $2,400

Razer Tomahawk modular gaming PC is now available for $2,400

View
The first phone with an under-display camera goes on sale December 21st

The first phone with an under-display camera goes on sale December 21st

View

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr