Slickwraps Suffers Data Breach After Ignoring Warnings From Security Researcher

Slickwraps, a company that develops skins for Apple devices like the iPhone and Mac, yesterday suffered a data breach that saw customer info like names and addresses leaked.

News of the leak surfaced when hackers who got into the database sent out emails to Slickwraps' customer base of more than 370,000 users letting them know about Slickwraps' poor security.

slickwrapsdatabreachemail
Prior to the breach, Slickwraps was warned of the vulnerabilities in its site (linked to the create a skin feature) multiple times by a security researcher who goes by Lynx on Twitter, who has now deleted all of his tweets.

Lynx informed Slickwraps about the data breach on February 15, and attempted to get in touch with the company several times over the course of the last week, as outlined by an article shared on Medium that has now been suspended by Medium. Lynx had his emails ignored and was even blocked by Slickwraps on Twitter after attempting to inform the site of its security vulnerabilities.

Lynx's interactions with Slickwraps were not exactly polite and he was dealing with customer support staff that were clearly confused about what was going on based on the now-removed Medium article, but Slickwraps blatantly ignored multiple warnings about its poor security before the data breach. Lynx says that he did not send out the emails that were delivered to Slickwraps customers yesterday and that it was a third-party data breach that happened after his article was published, but with his Medium post suspended and all of his tweets deleted, he may be in some hot water for the public way that he disclosed the vulnerabilities in the site.

After the emails went out and customers became aware of the data breach, Slickwraps finally commented on the situation. An initial statement tweeted by Slickwraps (which is based in the United States) claimed to have just heard about the data breach on "February 22" when it was still February 21, which was inaccurate because Lynx documented his attempts to get in touch with the company on Twitter. Slickwraps later deleted the statement and tweeted a new one with the correct date. From Slickwraps' statement:

There is nothing we value higher than trust from our users. In fact, our entire business model is dependent on building long-term trust with customers that keep coming back.

We are reaching out to you because we've made a mistake in violation of that trust. On February 21st, we discovered information in some of our non-production databases was mistakenly made public via an exploit. During this time, the databases were accessed by an unauthorized party.

The information did not contain passwords or personal financial data.

The information did contain names, user emails, addresses. If you've ever checked out as "GUEST" none of your information was compromised.

Slickwraps goes on to say that it is "deeply sorry" for the oversight and promises to "learn from this mistake." It recommends that users reset their account passwords and be watchful for any phishing attempts.

Going forward, Slickwraps says that it will enhance its security processes, improve communication of security guidelines to Slickwraps employees, and make user-requested security features a "top priority." The company says that it is also partnering with a third-party cyber security firm to audit and improve security protocols.

Slickwraps' data breach demonstrates the importance of penetration testing for any site that deals with customer data. Data breaches are pretty much impossible to avoid these days, but customers can protect themselves somewhat by using unique passwords for every site and using two-factor authentication where appropriate.

Popular Stories

15 New Things Your iPhone Can Do in iOS 18

18 New Things Your iPhone Can Do in iOS 18.1

Monday October 21, 2024 1:44 am PDT by
Apple is expected to release iOS 18.1 on Monday, October 28, bringing the first set of Apple Intelligence features to iPhone 15 Pro and iPhone 16 models. This update marks the first significant step forward in Apple's AI integration, offering a new Siri contextually-aware experience and a range of additional capabilities powered by on-device machine learning and large language models. There are a ...
Tim Cook Vision Pro

Tim Cook Admits Truth About Vision Pro Following Lackluster Sales

Monday October 21, 2024 8:21 am PDT by
The Wall Street Journal's Ben Cohen this summer interviewed Apple CEO Tim Cook about the Vision Pro, innovation, Apple Intelligence, and more. Image Credit: Vanity Fair Cook admitted that the Vision Pro headset is not a mass-market product due to its high price. "At $3,500, it's not a mass-market product," said Cook. "Right now, it's an early-adopter product. People who want to have...
airpods pro 2 pink

Apple Releases New AirPods Pro, AirPods, and AirPods Max Firmware

Tuesday October 22, 2024 11:39 am PDT by
Apple today released a new firmware update for the original AirPods Pro, the AirPods 2, the AirPods 3, and the Lightning version of the AirPods Max headphones. The new firmware is version 6F21, up from the prior 6A326 firmware that these devices were previously running. There is no word on what's included in the firmware, but given that these are all older models, it is likely that the new...
apple vision pro orange

Report: Apple May Stop Producing Vision Pro by the End of 2024

Wednesday October 23, 2024 6:11 am PDT by
Apple has abruptly reduced production of the Vision Pro headset and could stop making the current version of the device completely by the end of 2024, The Information reports. Citing multiple people "directly involved" in making components for the headset, the report says that the scaling back of production began in the early summer. This indicates that Apple now has a sufficient number of...
M4 Mac mini Silver Perspective

5 Reasons to Get Excited About the New Mac Mini

Wednesday October 23, 2024 6:55 am PDT by
Apple's Mac mini has long been a powerhouse in a compact form, offering impressive performance in a small package. With rumors swirling about a completely overhauled new model that is likely just days away from being announced, anticipation is building for what Apple has in store. From enhanced connectivity to major hardware upgrades, the upcoming Mac mini promises to bring significant...
M4 Mac mini Ortho Black Cooler

Gurman: 'M4 Mac Launch' is 'Next Week'

Tuesday October 22, 2024 10:29 am PDT by
Just a few hours after claiming that the first Macs with M4 chips are launching "very soon," Bloomberg's Mark Gurman has followed up with a slightly more specific timeframe. In his latest social media post today, he said an "M4 Mac launch" is on Apple's schedule for next week, but he did not mention a specific day. A concept of a smaller Mac mini with front-facing USB-C ports "Busy week for...
m3 mbp space black

Gurman: New MacBook Pro, iMac, and Mac Mini Models With M4 Chips Launching 'Very Soon'

Tuesday October 22, 2024 7:11 am PDT by
Apple is planning to launch its first Macs with the M4 series of chips "very soon," according to Bloomberg's Mark Gurman. In a social media post today, Gurman said these Macs will include new MacBook Pro, iMac, and Mac mini models specifically. He continues to expect the next Mac mini to feature a "revamped" design, in line with his previous reporting that said the new model will be nearly...
mac magic keyboard

Apple Working on New Magic Mouse 2, Magic Trackpad 2 and Magic Keyboard

Monday October 21, 2024 10:59 am PDT by
Apple may soon release new versions of the Magic Mouse, Magic Keyboard, and Magic Trackpad, according to code found in the iOS 18.1 release candidate by MacRumors contributor Aaron Perris. There are references to a new Magic Mouse 2, Magic Trackpad 2, and several Magic Keyboards, which would include versions with Touch ID and number pads, as well as models without. While there is no...
airpods pro 2 hearing aids

Apple Confirms AirPods Pro 2 Hearing Features Launching in iOS 18.1 Next Week

Monday October 21, 2024 5:32 am PDT by
Apple will release iOS 18.1 next week, introducing a suite of advanced hearing health capabilities to the AirPods Pro 2 and the first Apple Intelligence features. The timing of the update was confirmed by reviewers who were given early access to the AirPods Pro 2's new hearing health features, which are now known to be included in the update. The update will include three core features:...
Whatsapp Feature

WhatsApp for iOS Gets New Home Screen Widget for Chats, Camera Updates

Monday October 21, 2024 2:37 pm PDT by
Popular messaging app WhatsApp was today updated to add a new Home Screen widget that's specific to chats. The widget is available on the iPhone after updating to version 24.21.81, which came out this afternoon. After updating the widget can be added to the Home Screen using the Edit interface. Users can choose from Recents, Favorites, Pinned, or Frequently Contacted to get quick access to...

Top Rated Comments

twistedpixel8 Avatar
61 months ago
Complacency regarding security in 2020 is inexcusable. If you behave this way with customer data you shouldn’t run a company.
Score: 50 Votes (Like | Disagree)
Dave-Z Avatar
61 months ago

he may be in some hot water for the public way that he disclosed the vulnerabilities in the site.
He made attempts to alert the company, they outright refused to acknowledge him. He then disclosed it publicly. That's literally what every security researcher does.
Score: 24 Votes (Like | Disagree)
primarycolors Avatar
61 months ago
If anyone doesn't know, SlickWraps already had an incredibly sleazy track record. Constant discounts from false prices (false advertising), failing to deliver on orders, failing to respond to customer service, alleged artwork theft... not to mention their ridiculous social media bots posting fake pro-SlickWraps BS on Reddit and mass downvoting anything against them. I unfortunately fell for the fake sales when I didn't know better and got my info in their system...

SlickWraps is a true train wreck company. I'm absolutely enraged yet not surprised by their poor handling of this.

Now, I'm really curious to see what charges they will face from GDPR violations.
Score: 17 Votes (Like | Disagree)
Will Tisdale ? Avatar
61 months ago
I wonder on what grounds Medium ‘suspended’ that researchers post?

I guess that’s yet another reason not to use blogging services like that for anything remotely important.

Also, if the researcher has been ignored and then blocked as appears to have happened, then public disclosure is the only way. I don’t see an issue with it.
Score: 16 Votes (Like | Disagree)
Bkxmnr Avatar
61 months ago
"Fat, drunk, and stupid is no way to go through life son." Ignoring advice from security experts falls under the stupid category.
Score: 16 Votes (Like | Disagree)
Will Tisdale ? Avatar
61 months ago

An important lesson and message companies like Slickwrap are conveying with this: if you find a vulnerability of a service on the internet, never ever disclose it to the owners. You will be deemed the Problem and your behind gets prosecuted to set an example. You make them look bad, you make them do extra work, you piss them off. You need to be silenced.

Instead, sit on that information quietly. Sell the exploit on the black market if you want to profit off it. Get wild, just try not to get caught. You'll be way safer that way.
Yep, it’s a completely irresponsible way of dealing with a report. What’s so wrong or difficult about listening to the researcher, reproducing the issue and fixing it without being an arse about it?

Ignoring someone who is ultimately trying to help is very much a spoilt child mentality.
Score: 13 Votes (Like | Disagree)