Slickwraps Suffers Data Breach After Ignoring Warnings From Security Researcher

Slickwraps, a company that develops skins for Apple devices like the iPhone and Mac, yesterday suffered a data breach that saw customer info like names and addresses leaked.

News of the leak surfaced when hackers who got into the database sent out emails to Slickwraps' customer base of more than 370,000 users letting them know about Slickwraps' poor security.

slickwrapsdatabreachemail
Prior to the breach, Slickwraps was warned of the vulnerabilities in its site (linked to the create a skin feature) multiple times by a security researcher who goes by Lynx on Twitter, who has now deleted all of his tweets.

Lynx informed Slickwraps about the data breach on February 15, and attempted to get in touch with the company several times over the course of the last week, as outlined by an article shared on Medium that has now been suspended by Medium. Lynx had his emails ignored and was even blocked by Slickwraps on Twitter after attempting to inform the site of its security vulnerabilities.

Lynx's interactions with Slickwraps were not exactly polite and he was dealing with customer support staff that were clearly confused about what was going on based on the now-removed Medium article, but Slickwraps blatantly ignored multiple warnings about its poor security before the data breach. Lynx says that he did not send out the emails that were delivered to Slickwraps customers yesterday and that it was a third-party data breach that happened after his article was published, but with his Medium post suspended and all of his tweets deleted, he may be in some hot water for the public way that he disclosed the vulnerabilities in the site.

After the emails went out and customers became aware of the data breach, Slickwraps finally commented on the situation. An initial statement tweeted by Slickwraps (which is based in the United States) claimed to have just heard about the data breach on "February 22" when it was still February 21, which was inaccurate because Lynx documented his attempts to get in touch with the company on Twitter. Slickwraps later deleted the statement and tweeted a new one with the correct date. From Slickwraps' statement:

There is nothing we value higher than trust from our users. In fact, our entire business model is dependent on building long-term trust with customers that keep coming back.

We are reaching out to you because we've made a mistake in violation of that trust. On February 21st, we discovered information in some of our non-production databases was mistakenly made public via an exploit. During this time, the databases were accessed by an unauthorized party.

The information did not contain passwords or personal financial data.

The information did contain names, user emails, addresses. If you've ever checked out as "GUEST" none of your information was compromised.

Slickwraps goes on to say that it is "deeply sorry" for the oversight and promises to "learn from this mistake." It recommends that users reset their account passwords and be watchful for any phishing attempts.

Going forward, Slickwraps says that it will enhance its security processes, improve communication of security guidelines to Slickwraps employees, and make user-requested security features a "top priority." The company says that it is also partnering with a third-party cyber security firm to audit and improve security protocols.

Slickwraps' data breach demonstrates the importance of penetration testing for any site that deals with customer data. Data breaches are pretty much impossible to avoid these days, but customers can protect themselves somewhat by using unique passwords for every site and using two-factor authentication where appropriate.

Top Rated Comments

twistedpixel8 Avatar
19 months ago
Complacency regarding security in 2020 is inexcusable. If you behave this way with customer data you shouldn’t run a company.
Score: 50 Votes (Like | Disagree)
Dave-Z Avatar
19 months ago

he may be in some hot water for the public way that he disclosed the vulnerabilities in the site.
He made attempts to alert the company, they outright refused to acknowledge him. He then disclosed it publicly. That's literally what every security researcher does.
Score: 24 Votes (Like | Disagree)
primarycolors Avatar
19 months ago
If anyone doesn't know, SlickWraps already had an incredibly sleazy track record. Constant discounts from false prices (false advertising), failing to deliver on orders, failing to respond to customer service, alleged artwork theft... not to mention their ridiculous social media bots posting fake pro-SlickWraps BS on Reddit and mass downvoting anything against them. I unfortunately fell for the fake sales when I didn't know better and got my info in their system...

SlickWraps is a true train wreck company. I'm absolutely enraged yet not surprised by their poor handling of this.

Now, I'm really curious to see what charges they will face from GDPR violations.
Score: 17 Votes (Like | Disagree)
Will Tisdale ? Avatar
19 months ago
I wonder on what grounds Medium ‘suspended’ that researchers post?

I guess that’s yet another reason not to use blogging services like that for anything remotely important.

Also, if the researcher has been ignored and then blocked as appears to have happened, then public disclosure is the only way. I don’t see an issue with it.
Score: 16 Votes (Like | Disagree)
Bkxmnr Avatar
19 months ago
"Fat, drunk, and stupid is no way to go through life son." Ignoring advice from security experts falls under the stupid category.
Score: 16 Votes (Like | Disagree)
Will Tisdale ? Avatar
19 months ago

An important lesson and message companies like Slickwrap are conveying with this: if you find a vulnerability of a service on the internet, never ever disclose it to the owners. You will be deemed the Problem and your behind gets prosecuted to set an example. You make them look bad, you make them do extra work, you piss them off. You need to be silenced.

Instead, sit on that information quietly. Sell the exploit on the black market if you want to profit off it. Get wild, just try not to get caught. You'll be way safer that way.
Yep, it’s a completely irresponsible way of dealing with a report. What’s so wrong or difficult about listening to the researcher, reproducing the issue and fixing it without being an arse about it?

Ignoring someone who is ultimately trying to help is very much a spoilt child mentality.
Score: 13 Votes (Like | Disagree)

Top Stories

Pro Display XDR Yella

Apple Working on External Display With Built-In A13 Chip

Friday July 23, 2021 9:37 am PDT by
Apple is developing an external display that includes an A13 chip with Neural Engine, according to a new rumor from 9to5Mac. The A13 chip with Neural Engine would presumably serve as an eGPU, though details are light at this time. Having a CPU/GPU built into the external display could help Macs deliver high-resolution graphics without using all the resources of the computer's internal chip....
maxresdefault

Apple Music to Livestream Premiere of Kanye West's New Album 'Donda' on Thursday

Wednesday July 21, 2021 1:49 am PDT by
Apple Music on Thursday will host a global livestream for the premiere of Kanye West's tenth studio album, titled "Donda." The sold-out event will take place at the Mercedes-Benz Stadium in Atlanta, Georgia, and Apple Music's livestream will start at 8:00 p.m. Eastern Time. The livestream was revealed in a Beats Studio Buds ad that aired during the NBA Finals. The ad features U.S. track...
airpods 3 gizmochina Feature

AirPods 3 Rumored to Launch Alongside iPhone 13 at Expected September Event

Friday July 23, 2021 12:54 am PDT by
The third-generation AirPods will likely launch at the same event revealing Apple's upcoming iPhone 13 lineup, according to a report from DigiTimes, which makes the claim citing sources familiar with the matter. The report as a whole echoes previous reporting that production of the third-generation AirPods will kickstart in August, meaning a launch shortly after can be easily expected. DigiTi...
idos 2 app ios

Apple to Pull 'iDOS 2' DOS Emulator From App Store

Thursday July 22, 2021 3:22 pm PDT by
iDOS 2, an app designed to allow users to play classic DOS games, will soon be pulled from the App Store, the app's creator said today. According to iDOS developer Chaoji Li, he tried to submit an iDOS update with bug fixes to the App Store, but was told that the update was rejected because it violated the 2.5.2 App Store guideline that says apps cannot install or launch executable code.Durin...
iPad mini pro feature

Next iPad Mini Won't Feature Mini-LED Display, Claims Display Analyst

Friday July 23, 2021 8:07 am PDT by
Yesterday, DigiTimes claimed that the upcoming iPad mini will feature a mini-LED display, but now, display analyst Ross Young is going at odds with that report, claiming that while the updated iPad mini continues to be on track for a release this year, it won't feature a mini-LED display. Young says he "confirmed" with Radiant Opto-Electronics, who DigiTimes claims would provide Apple with...
AirPods Pro Beta Firmware

AirPods Pro Beta Firmware Now Available

Wednesday July 21, 2021 6:50 am PDT by
Upcoming AirPods Pro firmware updates are now available to Apple Developer Program members as beta versions. AirPods Pro firmware beta one features FaceTime Spatial Audio and Ambient Noise Reduction. Custom Transparency mode, including Conversation Boost, was initially expected to be included in the beta but appears to have been delayed for a later version. Apple made the announcement...
iPad mini pro feature

Next-Generation iPad Mini Will Reportedly Feature a Mini-LED Display

Thursday July 22, 2021 9:03 am PDT by
Apple is widely rumored to be planning a new iPad mini with a significant redesign, including a larger 8.5-inch to 9-inch display with slimmer bezels, a Touch ID power button instead of a home button, a USB-C port instead of a Lightning connector, and more. According to a paywalled preview of a DigiTimes report today, the sixth-generation iPad mini will also feature a mini-LED display:BLU...
discount m1 macbook yellow

Deals: Shop Record Low Prices Across Apple's Full MacBook Pro and MacBook Air Lineup (Up to $499 Off)

Friday July 23, 2021 8:23 am PDT by
Apple's MacBook Pro and MacBook Air lineup is seeing all-time low discounts across the board today, including the 2019 16-inch MacBook Pro, 2020 13-inch MacBook Air, and 2020 13-inch MacBook Pro. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running. 13-Inch M1...
ios wifi settings

Apple Confirms iOS 14.7 Fixes WiFi Bug and Many Other Vulnerabilities

Wednesday July 21, 2021 11:38 am PDT by
Following the release of iPadOS 14.7 this morning, Apple has shared details on the security updates that are included in iOS 14.7, iPadOS 14.7, macOS Big Sur 11.5, watchOS 7.6, and tvOS 14.7, all of which came out this week. Notably, Apple's documentation confirms that the iOS 14.7 and iPadOS 14.7 updates address a WiFi-related vulnerability that could impact iOS devices when joining a...
macOS Big Sur Feature Orange

Apple Releases macOS Big Sur 11.5 With Podcast App Updates and Bug Fixes

Wednesday July 21, 2021 10:15 am PDT by
Apple today released macOS Big Sur 11.5, the fifth major update to the macOS Big Sur operating system that launched in November 2020. macOS Big Sur 11.5 comes two months after the release of macOS Big Sur 11.4. The new ‌‌‌‌‌macOS Big Sur‌‌‌‌ 11.5 update can be downloaded for free on all eligible Macs using the Software Update section of System Preferences. macOS Big Sur...