Skip to main content
Back
PAAY LLC

PAAY LLC Data Breach (2020)

PAAY LLC

highVERIS
Disclosed

April 3, 2020

2184 days ago

Records

2.5M

Confirmed

Root Cause

Misconfiguration

Industry

Technology

Description

A database with 2.5 million credit card transactions belonging to New York mobile payments solutions provider PAAY LLC has been found exposed online. Discovered and revealed today by security researcher Anurag Sen, the database included credit card numbers, expiration dates and amount spent dating back to Sept. 1. The database did not include cardholder name or card verification values, somewhat limiting the usefulness of the data to hackers. The data is said to have been exposed online for at least three weeks until it was taken offline after TechCrunch contacted the company. PAAY admitted that a database belonging to it had been accidentally exposed but disputed the claim that the database included credit card numbers. “On April 3, we spun up a new instance on a service we are currently in the process of deprecating,” PAAY co-founder Yitz Mendlowitz said. “An error was made that left that database exposed without a password.” Although not confirmed, it would appear to be yet another case of a company failing to properly secure a cloud-hosted database. The list of companies who have exposed data in this way is extraordinarily long, although cases have dropped off in 2020 as security awareness around the issue continues to improve. “PAAY offers a service as a third-party middleman between two banks by providing an additional security layer for the transactions but unfortunately leaves all records exposed without passwords and vulnerable to attacks,” Robert Prigge, chief executive officer of identity verifications solutions company Jumio Corp., told SiliconANGLE. “It’s important for banks of all sizes only rely on vendors and third parties that are PCI-compliant and come equipped with the necessary security and certifications to keep customers protected.”