Gorilla data leak

According to the IT collective that uncovered the security vulnerability, all customer data from the Berlin start-up Gorillas was accessible. The gap has been closed and customers and authorities have been informed, Gorillas reports.
At Gorillas, more than one million order details of over 200,000 customers were accessible in the meantime. The vulnerability was discovered by members of the IT collective "Zerforschung". They reported the vulnerability to the German Federal Office for Information Security (BSI) and contacted NDR and RBB. According to information provided to the Tagesschau Gorillas reported the security vulnerability to the relevant authorities. It is mandatory for companies to report to the BSI within 72 hours of discovering such vulnerabilities, otherwise fines can be imposed.
Gorillas apparently had access to all data. "That means name, telephone number, email address and physical address. Where the order should go, which products have been ordered," a member of the research team told Tagesschau. The Berlin-based start-up writes on Instagram that the data was "neither stolen nor misused in any other way" and that "the security gaps were closed within two hours of becoming known."
Gorillas is not the first fast delivery service to suffer a data leak: As recently as March, research by RBB and the Zerforschung collective revealed that Gorillas' competitor Flink had 3,700 pieces of user data exposed. More recently, Zerforschung also investigated security gaps at the Hamburg start-up Bringoo, where 7,000 customer data could be accessed.

Newsletter
Startups, stories and stats from the German startup ecosystem straight to your inbox. Subscribe with 2 clicks. Noice.
LinkedIn ConnectFYI: English edition available
Hello my friend, have you been stranded on the German edition of Startbase? At least your browser tells us, that you do not speak German - so maybe you would like to switch to the English edition instead?
FYI: Deutsche Edition verfügbar
Hallo mein Freund, du befindest dich auf der Englischen Edition der Startbase und laut deinem Browser sprichst du eigentlich auch Deutsch. Magst du die Sprache wechseln?