• Latest
  • Trending
Adafruit discloses data leak from ex-employee’s GitHub repo

Adafruit discloses data leak from ex-employee’s GitHub repo

March 7, 2022
Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa

Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa

July 29, 2025
French Telco Orange Hit by Cyber-Attack

French Telco Orange Hit by Cyber-Attack

July 29, 2025
ATC Ghana supports Girls-In-ICT Program

ATC Ghana supports Girls-In-ICT Program

April 25, 2023
Vice President Dr. Bawumia inaugurates  ICT Hub

Vice President Dr. Bawumia inaugurates ICT Hub

April 2, 2023
Co-Creation Hub’s edtech accelerator puts $15M towards African startups

Co-Creation Hub’s edtech accelerator puts $15M towards African startups

February 20, 2023
Data Leak Hits Thousands of NHS Workers

Data Leak Hits Thousands of NHS Workers

February 20, 2023
EU Cybersecurity Agency Warns Against Chinese APTs

EU Cybersecurity Agency Warns Against Chinese APTs

February 20, 2023
How Your Storage System Will Still Be Viable in 5 Years’ Time?

How Your Storage System Will Still Be Viable in 5 Years’ Time?

February 20, 2023
The Broken Promises From Cybersecurity Vendors

Cloud Infrastructure Used By WIP26 For Espionage Attacks on Telcos

February 20, 2023
Instagram and Facebook to get paid-for verification

Instagram and Facebook to get paid-for verification

February 20, 2023
YouTube CEO Susan Wojcicki steps down after nine years

YouTube CEO Susan Wojcicki steps down after nine years

February 20, 2023
Inaugural AfCFTA Conference on Women and Youth in Trade

Inaugural AfCFTA Conference on Women and Youth in Trade

September 6, 2022
  • Consumer Watch
  • Kids Page
  • Directory
  • Events
  • Reviews
Sunday, 17 May, 2026
  • Login
itechnewsonline.com
  • Home
  • Tech
  • Africa Tech
  • InfoSEC
  • Data Science
  • Data Storage
  • Business
  • Opinion
Subscription
Advertise
No Result
View All Result
itechnewsonline.com
No Result
View All Result

Adafruit discloses data leak from ex-employee’s GitHub repo

by ITECHNEWS
March 7, 2022
in Infosec, Leading Stories
0 0
0
Adafruit discloses data leak from ex-employee’s GitHub repo

Adafruit has disclosed a data leak that occurred due to a publicly-viewable GitHub repository.

The company suspects this could have allowed “unauthorized access” to information about certain users on or before 2019.

YOU MAY ALSO LIKE

French Telco Orange Hit by Cyber-Attack

ATC Ghana supports Girls-In-ICT Program

Based in New York City, Adafruit is a producer of open-source hardware components since 2005. The company designs, manufactures, and sells electronics products, tools, and accessories.

 

Ex-employee’s GitHub repo had real customer data

On Friday, March 4th, Adafruit announced that a publicly-accessible GitHub repository contained a data set comprising information on some user accounts. This information included:

  • names
  • email addresses
  • shipping/billing addresses
  • order details
  • order placement status via payment processor or PayPal

The data set, according to Adafruit, did not contain any user passwords or financial information such as credit cards. However, the exposure of real user data, including order details, could be used by spammers and phishing actors to target Adafruit’s customers.

Interestingly, the data leak did not occur from Adafruit’s GitHub repository but that of a former employee. It appears that a former employee was using real customer information for training and data analysis operations in their GitHub repo.

“Within 15 minutes of being notified about the inadvertent disclosure, Adafruit worked with the former employee, deleted the relevant GitHub repository and the Adafruit team began the forensic process to determine what and if there was any access and what type of data was involved,” explained the company.

Users demand proper notifications

At this time, Adafruit is not aware of the exposed information being misused by an adversary and claims it’s disclosing the incident “for transparency and accountability.”

The company has, however, decided not to email every user about the incident.

Adafruit explains that although all security disclosures are published on the company’s blog and security pages, there is no action for the users to perform as no passwords or payment card information were exposed in the data analysis set.

“We evaluated the risk and consulted with our privacy lawyers and legal experts, and took the approach that we thought appropriately mitigated any issues while being open and transparent and did not believe emailing directly was helpful in this case,” state Adafruit’s Managing Director Phillip Torrone, and founder Limor “Ladyada” Fried.

But, not all Adafruit customers are convinced, with some demanding email notifications be sent out with regards to the incident:

A major concern among users is the presence of real customer information in a former team member’s GitHub repo, as opposed to using automatically-generated “fake” staging data. And, how this information could be misused by phishing actors:

It is worth noting, keeping real customer data in GitHub repositories, even private ones, is a risky decision.

Last year, e-commerce giant Mercari had suffered a data leak via their private GitHub repo exposing over 17,000 customer records including banking information. Rapid7 also suffered a data leak via private GitHub repo impacting a “small subset of customers.”

“We are additionally putting in place more protocols and access controls to avoid any possible future data exposure and limiting access for employee training use,” says Adafruit.

Users should remain vigilant for any phishing scams or communications they may receive impersonating Adafruit staff. The company especially cautions against bogus “password reset” alerts that may entice victims into giving away their passwords.

Adafruit requests that concerns related to any such suspicious emails or unauthorized access attempts by threat actors be directed to security@adafruit.com.

Source: Ax Sharma
Via: bleepingcomputer
Tags: Adafruit discloses data leak from GitHub repo
ShareTweet

Get real time update about this post categories directly on your device, subscribe now.

Unsubscribe

Search

No Result
View All Result

Recent News

Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa

Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa

July 29, 2025
French Telco Orange Hit by Cyber-Attack

French Telco Orange Hit by Cyber-Attack

July 29, 2025
ATC Ghana supports Girls-In-ICT Program

ATC Ghana supports Girls-In-ICT Program

April 25, 2023

About What We Do

itechnewsonline.com

We bring you the best Premium Tech News.

Recent News With Image

Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa

Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa

July 29, 2025
French Telco Orange Hit by Cyber-Attack

French Telco Orange Hit by Cyber-Attack

July 29, 2025

Recent News

  • Absa and Visa Extend Strategic Partnership to Advance Growth and Innovation Across Africa July 29, 2025
  • French Telco Orange Hit by Cyber-Attack July 29, 2025
  • ATC Ghana supports Girls-In-ICT Program April 25, 2023
  • Vice President Dr. Bawumia inaugurates ICT Hub April 2, 2023
  • Home
  • InfoSec
  • Opinion
  • Africa Tech
  • Data Storage

© Copyright 2026, All Rights Reserved | iTechNewsOnline.Com - Powered by BackUPDataSystems

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Tech
  • Africa Tech
  • InfoSEC
  • Data Science
  • Data Storage
  • Business
  • Opinion

© Copyright 2026, All Rights Reserved | iTechNewsOnline.Com - Powered by BackUPDataSystems

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
Go to mobile version