Fairphone data leak

Just got this email:

Dear Participants,

We are reaching out to inform you of an issue regarding a form you completed on Fairphone forum between March 3rd and March 4th . This form was part of our beta testing survey, titled “Beta Tester Application.” Due to a misconfiguration, participants who completed the questionnaire were able to view responses from others. We identified this issue on March 4th at 4:00 PM and immediately took action to close access and secure the data.

This issue affected 24 participants, including you. No one outside this group had access. The information that was exposed includes:

  • your name (if provided)
  • forum username (if provided)
  • email address
  • home address
  • phone ownership status
  • telecom operator
  • and IMEI number (if provided).

Upon discovery, we promptly:

  • Restricted access to the form responses
  • Corrected the misconfiguration
  • Conducted a review of the incident
  • Implemented additional security measures to prevent recurrence

At this time, we have no indication that any data has been misused. However, as a precaution, we advise you to remain vigilant for any unsolicited emails and messages requesting personal information, suspicious links, or other unusual activity.

If you have any questions or concerns, please reach out to us at privacy@fairphone.com. We sincerely apologize for this incident and deeply appreciate your understanding. We are truly sorry for having failed to meet your expectations and for any breach of trust that may have occurred. We view this as a priceless lesson and are determined to learn from it. Moving forward, we will strive to regain your trust through more prudent and careful data collection practices.

Protecting your data remains our utmost priority, and we are fully committed to strengthening our security measures to ensure that such incidents do not recur. Thank you for your continued support and patience as we work to improve.

Best regards,

Fairphone Privacy Team

8 Likes

Fairphone also used reply to all so now every person that this email was sent to now have everyone else email address too :man_facepalming:

13 Likes

So … 2 data leaks.

9 Likes

Doesn’t seem like 2 data leaks

2 Likes

how they can make rookie mistake like this??

1 Like

Too may people working on marketing (rebranding, new logo, …) - too few people working on development, IT infrastructure, …

Example: Applying filter in the shop didn’t worked for weeks since the rebranding.

2 Likes

The first leak is the misconfiguration, which could lead to anybody affected viewing the e-mail address of others. Not necessarily, and I would assume most probably, not everybody affected got the e-mail addresses of everybody affected this way.

The second leak is the handing out of the e-mail addresses of everybody affected to everybody affected for good.

2 most probably different levels of exposure, but 2 clearly different wrongdoings.

7 Likes

“anybody affected” being limited to… only 24 participants.

1 Like

and none of them gave an explicit permission to share their email addresses with the others, as far as I know. still a leak.

4 Likes

What’s the threshold from which on it isn’t “only”, and who decides this threshold?

2 Likes

I find it much less harmful to leak my datas to “only” 24 persons, beta testers as me.