Computerhersteller Zotac veröffentlicht RMA-Informationen von Kunden in der Google-Suche

Teilen:

Computer hardware maker Zotac has exposed return merchandise authorization (RMA) requests and related documents online for an unknown period, exposing sensitive customer information.

Zotac, known for its range of compact and mini PCs, high-performance graphics cards, motherboards, and computer accessories, has misconfigured the web folders that hold RMA data, resulting in them being indexed by search engines.

This is typically the result of inadequate permissions that restrict access to authorized users only, aka Zotac’s employees, and the lack of tags or a ‘robots.txt’ file that would instruct crawlers to exclude the sensitive folders.

As a result, Google Search queries containing people’s or company names along with the ‘zotacusa.com’ site parameter revealed personal information such as invoices, addresses, request details, and contact information.

The lapse, which impacts an unknown number of Zotac customers, was discovered by a viewer of the YouTube tech channel GamersNexus. The channel reported the leak late last week on X without naming the hardware vendor.

Meanwhile, GamersNexus informed some of Zotac’s largest partners to raise awareness about the sensitive data exposure, and remediation efforts are underway.

The YouTube channel revealed the culprit was Zotac USA via a video published yesterday after receiving a response from the firm.

Most of the data has now been secured, though they still appear in Google Search. That said, most of the private documents are no longer publicly accessible.

GamersNexus eventually reached a spokesperson from Zotac, who told them that they had disabled the document upload button on their RMA portal and now ask customers to email files accompanying their requests.

If you have used Zotac’s RMA service at any point, you should consider your personal information exposed and take precautions as needed to mitigate the risk. Since the duration of the exposure is currently unknown, there are no “safe” RMA dates.

BleepingComputer has contacted Zotac to learn more about the data exposure, but a statement wasn’t immediately available.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:06 pm, Jan. 19, 2025
Wetter-Symbol 3°C
L: 2° | H: 4°
overcast clouds
Luftfeuchtigkeit: 84 %
Druck: 1020 mb
Wind: 6 mph ESE
Windböe: 8 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:55 am
Sonnenuntergang: 4:26 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
2° | 4°°C 0 mm 0% 2 mph 78 % 1019 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 7°°C 0 mm 0% 6 mph 88 % 1019 mb 0 mm/h
Di. Jan. 21 9:00 pm
Wetter-Symbol
2° | 7°°C 0 mm 0% 4 mph 95 % 1017 mb 0 mm/h
Mi. Jan. 22 9:00 pm
Wetter-Symbol
4° | 6°°C 1 mm 100% 6 mph 99 % 1009 mb 0 mm/h
Do. Jan. 23 9:00 pm
Wetter-Symbol
4° | 8°°C 1 mm 100% 14 mph 89 % 1006 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
3° | 4°°C 0 mm 0% 2 mph 78 % 1019 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 2 mph 74 % 1019 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 2 mph 70 % 1019 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 1 mph 71 % 1019 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 72 % 1019 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 5 mph 70 % 1019 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
7° | 7°°C 0 mm 0% 6 mph 76 % 1017 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 82 % 1018 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€102,155.81
0.73%
Ethereum(ETH)
€3,331.17
4.74%
XRP(XRP)
€3.08
-0.56%
Fesseln(USDT)
€0.97
-0.05%
Solana(SOL)
€265.15
7.03%
Dogecoin(DOGE)
€0.381833
0.46%
USDC(USDC)
€0.97
0.01%
Shiba Inu(SHIB)
€0.000021
-3.63%
Pepe(PEPE)
€0.000018
-2.88%
Peanut das Eichhörnchen(PNUT)
€0.473811
-4.80%
Nach oben scrollen