Slickwraps Suffers Data Breach After Ignoring Warnings From Security Researcher

Slickwraps, a company that develops skins for Apple devices like the iPhone and Mac, yesterday suffered a data breach that saw customer info like names and addresses leaked.

News of the leak surfaced when hackers who got into the database sent out emails to Slickwraps' customer base of more than 370,000 users letting them know about Slickwraps' poor security.


Prior to the breach, Slickwraps was warned of the vulnerabilities in its site (linked to the create a skin feature) multiple times by a security researcher who goes by Lynx on Twitter, who has now deleted all of his tweets.

Lynx informed Slickwraps about the data breach on February 15, and attempted to get in touch with the company several times over the course of the last week, as outlined by an article shared on Medium that has now been suspended by Medium. Lynx had his emails ignored and was even blocked by Slickwraps on Twitter after attempting to inform the site of its security vulnerabilities.

Lynx's interactions with Slickwraps were not exactly polite and he was dealing with customer support staff that were clearly confused about what was going on based on the now-removed Medium article, but Slickwraps blatantly ignored multiple warnings about its poor security before the data breach. Lynx says that he did not send out the emails that were delivered to Slickwraps customers yesterday and that it was a third-party data breach that happened after his article was published, but with his Medium post suspended and all of his tweets deleted, he may be in some hot water for the public way that he disclosed the vulnerabilities in the site.

After the emails went out and customers became aware of the data breach, Slickwraps finally commented on the situation. An initial statement tweeted by Slickwraps (which is based in the United States) claimed to have just heard about the data breach on "February 22" when it was still February 21, which was inaccurate because Lynx documented his attempts to get in touch with the company on Twitter. Slickwraps later deleted the statement and tweeted a new one with the correct date. From Slickwraps' statement:

There is nothing we value higher than trust from our users. In fact, our entire business model is dependent on building long-term trust with customers that keep coming back.

We are reaching out to you because we've made a mistake in violation of that trust. On February 21st, we discovered information in some of our non-production databases was mistakenly made public via an exploit. During this time, the databases were accessed by an unauthorized party.

The information did not contain passwords or personal financial data.

The information did contain names, user emails, addresses. If you've ever checked out as "GUEST" none of your information was compromised.

Slickwraps goes on to say that it is "deeply sorry" for the oversight and promises to "learn from this mistake." It recommends that users reset their account passwords and be watchful for any phishing attempts.

Going forward, Slickwraps says that it will enhance its security processes, improve communication of security guidelines to Slickwraps employees, and make user-requested security features a "top priority." The company says that it is also partnering with a third-party cyber security firm to audit and improve security protocols.

Slickwraps' data breach demonstrates the importance of penetration testing for any site that deals with customer data. Data breaches are pretty much impossible to avoid these days, but customers can protect themselves somewhat by using unique passwords for every site and using two-factor authentication where appropriate.

Top Rated Comments

(View all)
Avatar
6 weeks ago
Complacency regarding security in 2020 is inexcusable. If you behave this way with customer data you shouldn’t run a company.
Score: 50 Votes (Like | Disagree)
Avatar
6 weeks ago


he may be in some hot water for the public way that he disclosed the vulnerabilities in the site.

He made attempts to alert the company, they outright refused to acknowledge him. He then disclosed it publicly. That's literally what every security researcher does.
Score: 24 Votes (Like | Disagree)
Avatar
6 weeks ago
If anyone doesn't know, SlickWraps already had an incredibly sleazy track record. Constant discounts from false prices (false advertising), failing to deliver on orders, failing to respond to customer service, alleged artwork theft... not to mention their ridiculous social media bots posting fake pro-SlickWraps BS on Reddit and mass downvoting anything against them. I unfortunately fell for the fake sales when I didn't know better and got my info in their system...

SlickWraps is a true train wreck company. I'm absolutely enraged yet not surprised by their poor handling of this.

Now, I'm really curious to see what charges they will face from GDPR violations.
Score: 17 Votes (Like | Disagree)
Avatar
6 weeks ago
I wonder on what grounds Medium ‘suspended’ that researchers post?

I guess that’s yet another reason not to use blogging services like that for anything remotely important.

Also, if the researcher has been ignored and then blocked as appears to have happened, then public disclosure is the only way. I don’t see an issue with it.
Score: 16 Votes (Like | Disagree)
Avatar
6 weeks ago
"Fat, drunk, and stupid is no way to go through life son." Ignoring advice from security experts falls under the stupid category.
Score: 16 Votes (Like | Disagree)
Avatar
6 weeks ago


An important lesson and message companies like Slickwrap are conveying with this: if you find a vulnerability of a service on the internet, never ever disclose it to the owners. You will be deemed the Problem and your behind gets prosecuted to set an example. You make them look bad, you make them do extra work, you piss them off. You need to be silenced.

Instead, sit on that information quietly. Sell the exploit on the black market if you want to profit off it. Get wild, just try not to get caught. You'll be way safer that way.

Yep, it’s a completely irresponsible way of dealing with a report. What’s so wrong or difficult about listening to the researcher, reproducing the issue and fixing it without being an arse about it?

Ignoring someone who is ultimately trying to help is very much a spoilt child mentality.
Score: 13 Votes (Like | Disagree)

Top Stories

Leaker Claims New 13-inch MacBook Pro Coming as Soon as Next Month

Monday April 6, 2020 2:56 am PDT by Tim Hardwick
Apple will announce a new 13-inch MacBook Pro in May with the codename J223, according to a rumor shared by YouTuber and leaker Jon Prosser. Note: it’s a refresh to the current 13” So the bigger 14” display upgrade is a big possibility— Jon Prosser (@jon_prosser) April 4, 2020 Analyst Ming-Chi Kuo has said Apple plans to release new MacBook Pro and MacBook Air models with scissor keyboards ...

iOS 14 Could Offer Home Screen Widgets, Wallpaper Customizations

Saturday April 4, 2020 3:30 pm PDT by Frank McShan
iOS 14 could offer home screen widgets and wallpaper customizations for the first time, according to 9to5Mac and Twitter user DongleBookPro. Apple is reportedly working to implement widgets that can be moved freely around like icons on the iPhone and iPad homescreen for the very first time. The feature is reportedly codenamed "Avocado" and no other details are available. It was also...

'Leaked' Images Allegedly Show iPhone 12 With Smaller Notch, Rear Camera Redesign, and Home Screen Widgets

Tuesday April 7, 2020 4:28 am PDT by Tim Hardwick
Two images shared on social media this morning are currently stoking speculation about possible hardware redesigns coming to the iPhone 12 and the potential introduction of Home screen widgets in iOS 14. Shared by Twitter user Fudge (choco_bit), the images depict a front and rear graphical representation of a smartphone with interface elements on the screen, suggesting it came out of a...

More References to Apple's Upcoming Low-Cost iPhone Appear Online

Monday April 6, 2020 4:38 am PDT by Tim Hardwick
Further references to Apple's upcoming low-cost iPhone have appeared online, one on a Chinese e-commerce website and another on Verizon's smartphone trade-in page. Spotted by tech blog MySmartPrice, Chinese retailer JD.com has published a placeholder for Apple's so-called "iPhone 9" that includes a teaser image of a veiled smartphone, but other than that it lacks any particularly revealing...

The New York Times, IFTTT, Medium, and Other Apps Adopt Sign in With Apple Ahead of June 30 Deadline

Sunday April 5, 2020 7:08 pm PDT by Frank McShan
Apps with sign-in functionality, including The New York Times, IFTTT, Medium, and more, have continued to adopt Apple's secure Sign in with Apple feature ahead of a deadline of June 30. The deadline for these apps to support the feature was recently extended from April 30. Sign in with Apple, first introduced in iOS 13, allows users to create accounts for apps and websites using an Apple ID. ...

Some Users Experiencing System Crashes on macOS 10.15.4, Especially During Large File Transfers

Monday April 6, 2020 8:17 am PDT by Joe Rossignol
A sizeable number of Mac users are experiencing occasional system crashes after updating to macOS Catalina version 10.15.4, released a few weeks ago. The crashing issue appears to be most prominent when users attempt to make large file transfers. In a forum post, SoftRAID described the issue as a bug and said that it is working with Apple engineers on a fix for macOS 10.15.5, or a...

Apple Releases iOS and iPadOS 13.4.1 With Fix for FaceTime Bug

Tuesday April 7, 2020 10:06 am PDT by Juli Clover
Apple today released iOS and iPadOS 13.4.1, minor updates that come two weeks after the release of iOS and iPadOS 13.4, major updates that introduced iCloud Folder Sharing, a new Mail toolbar, trackpad support for the iPad, and more. The iOS and ‌iPadOS‌ 13.4.1 updates are available on all eligible devices over-the-air in the Settings app. To access the updates, go to Settings > General...

Top Stories: Apple Leaks iPhone SE and AirTags, Apple Buys Dark Sky, and More

Saturday April 4, 2020 6:00 am PDT by MacRumors Staff
With the calendar rolling over to April this week, we yet again saw several leaks and rumors, most notably including Apple itself leaking some references to a pair of long-rumored products: a new budget iPhone SE and AirTags item trackers. Subscribe to the MacRumors YouTube channel for more videos. Apple also acquired popular weather app Dark Sky, while Amazon's Prime Video app now allows...

Apple Reportedly Targeting WWDC for Over-Ear Headphones Launch, New 'AirPods X' Later in the Year

Tuesday April 7, 2020 7:00 am PDT by Eric Slivka
Rumors of Apple-branded over-ear headphones have been circulating for quite some time, while more recent rumors have mentioned an "AirPods Pro Lite" that could also be in the works, and Twitter leaker Jon Prosser's recent foray into Apple rumors provides a bit more detail on what we might able to expect for these products. Current Beats Studio3 Wireless and BeatsX On the over-ear side,...

Apple Donating Over 20 Million Masks to Healthcare Professionals, Producing Face Shields With Suppliers

Sunday April 5, 2020 2:51 pm PDT by Joe Rossignol
Apple CEO Tim Cook today shared a video message with an update on the company's response to the ongoing pandemic. Cook said Apple has now sourced over 20 million masks that it is in the process of donating to healthcare professionals around the world. Apple is working with governments to ensure that the masks are donated to the places of greatest need. Cook added that Apple's design,...