Data Breaches

DigitalOcean Security Breach – Customers Billing Information and Payment Card Data is Exposed

Digital Ocean, a US-based cloud infrastructure provider, revealed a data breach that exposed some of their customer’s billing and payment card information. Scary enough? Yes, it is!!

When did the DigitalOcean Security Breach happen?

According to the email sent out by Digital Ocean, the breach happened between April 9th, 2021, and April 22nd, 2021. Here Digital Ocean accepts a “Flaw” that allowed this unauthorized user access to the Customer’s billing information.

Email sent to Digital Ocean’s customers:

An unauthorized user gained access to some of your billing account details through a flaw that has been fixed. This exposure impacted a small percentage of our customers,” – Email that is sent to customers! A snap of the same below:

What is the exposed information?

The exposed/breached information includes a customer’s billing name, billing address, payment card expiration, last four digits of credit card, and the payment card’s bank name, the basic information needed for the payment.

But, luckily, DigitalOcean states that they have fixed the flaw and disclosed the breach to data protection authorities though it is not clear what agencies were notified. Also,  The company said that customers’ DigitalOcean accounts were “not accessed,” and passwords and account tokens were “not involved” in this breach.

The email also says, “To be extra careful, we have implemented additional security monitoring on your account. We are expanding our security measures to reduce the likelihood of this kind of flaw occurring [sic] in the future,” In a statement, DigitalOcean’s security chief Tyler Healy said 1% of billing profiles were affected by the breach. Here, the companies with customers in Europe are subject to GDPR and can face fines of up to 4% of their global annual revenue.

Also Read

MobiKwik Data Breach – Hackers Selling Over 8TB of Users Personal and Financial Data

Online Alcohol Delivery Startup Drizly Hacked – 2.5 million Drizly Accounts Stolen

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago