A recent data breach involving field service management company ServiceBridge has exposed nearly 32 million files containing sensitive personal and business information. Security researcher Jeremiah Fowler discovered the unprotected data, which included contracts, invoices, agreements, and more, accessible without any security authorization.
The exposed data, dating back to 2012, impacts companies across Canada, Europe, the U.S., and the U.K. The breach affects a wide range of industries served by the ServiceBridge platform, including commercial and industrial services, pest and animal control, cleaning, landscaping, construction, and others. Customers range from private homeowners and schools to large chain restaurants, casinos, medical providers, and more.
Screenshot of an inspection of an iOT device.ServiceBridge Data Breach Exposes Site Audit Reports and Sensitive Information (Website Planet)
Beyond financial documents, the exposed files also contained inspection reports, phone numbers, HIPAA consent forms, and “site audit reports” with pictures of business interiors and exteriors, gate access codes, and other access data. This wealth of information puts individuals and businesses at significant risk of fraud and targeted attacks like spear phishing.
The duration of the exposure remains undisclosed, as does the identity of anyone who may have accessed the data. This lack of transparency further compounds the potential risks for those affected.
Fowler recommends that businesses and individuals maintain meticulous records of vendors, contractors, and customers to verify the legitimacy of payment requests. He emphasizes caution, advising against rushing payments and verifying any suspicious invoices. Customers should also be wary of unexpected contact from businesses requesting additional information or payments.
The ServiceBridge breach highlights the increasing prevalence of data breaches and underscores the importance of proactive security measures. Protecting personal and business information is paramount in today’s digital landscape.
Identity theft protection services can offer an added layer of security in the face of these growing threats. Taking steps to protect your data is crucial in mitigating the risks associated with data breaches.