BrewDog exposes data of 200,000 customers and shareholders


BrewDog, one of the world’s largest craft beer brewers, has exposed personally identifiable information (PII) belonging to more than 200,000 of its shareholders and customers, according to cybersecurity researchers.
Cybersecurity consulting firm PenTest Partners discovered that a flaw in the official BrewDog app, which persisted for more than 18 months, made it easy for anyone to access the PII of other users.
In its detailed report, PenTest Partners notes that the mobile app doled out the same hard coded API Bearer Token, which effectively rendered request authorization useless.
We’re looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won’t take more than 60 seconds of your time, and we’d hugely appreciate if you’d share your experiences with us.
“It was therefore trivial for any user to access any other user’s PII, shareholding, bar discount, and more,” share the researchers.
The researchers say that, thanks to the flaw, any user could append the customerID of another user to the API endpoint URL to extract their PII and other details.
In addition to being damaging to the user, the flaw could’ve also been used to adversely affect the company since the leaked details could’ve been used to generate QR codes to get discounted and even free beers.
BrewDog started using hard-coded tokens with v2.5.5 of its app, launched in March 2020, before finally patching the flaw in v2.5.13 release in September 2021.
Lack of alerts?
Worryingly, the company decided not to reveal the vulnerability to its users, even after it was fixed, going as far as to claim that there wasn’t anything “too exciting in this release”.
Furthermore, PenTesting Partners says that, in its correspondence with the company, BrewDog claimed it found no evidence of the flaw being abused.
“We were recently informed of a vulnerability in one of our apps by a third party technical security services firm, following which we immediately took the app down and resolved the issue,” said the firm in a statement.
“We have not identified any other instances of access via this route or personal data having been impacted in any way. There was therefore no requirement to notify users.”
However, the researchers suggest that the nature of the flaw means its abuse wouldn’t have been apparent in the logs, making identifying misuse virtually impossible.
While the company had asked the researchers not to name them in its disclosure, BleepingComputer contends that BrewDog will be forced to inform the UK’s data protection officer, since PII falls under the purview of the General Data Protection Regulation (GDPR).
However, it appears the company disagrees. In a private forum post seen by TechRadar Pro, the company told shareholders it is under no obligation to report the incident to the Information Commissioner’s Office (ICO), as per the advice of an external expert.
“The ICO is very clear on this,” the company wrote. “We have to notify when users’ data has been put at risk. As this was a vulnerability report, and the only personal data that was accessed was that of the third party conducting the assessment, there is no requirement to notify.”
BrewDog also took steps to prepare shareholders for a backlash that may arise as a result of the bug discovery.
“Vulnerability disclosure is a key part of the cybersecurity landscape and is a common occurrence. Many businesses invite this practice and offer bounties to those who find issues. Unfortunately, following the negative press earlier this year, this occurrence may be viewed publicly through a different lens.”
TechRadar Pro has contacted BrewDog for comment.
Update:
BrewDog has since provided us with the following statement:
“We are grateful to the third party technical security services firm for alerting us to this vulnerability. We are totally committed to ensuring the security of our user’s privacy. Our security protocols and vulnerability assessments are always under review and always being refined, in order that we can ensure that the risk of a cyber security incident is minimized.”
Via BleepingComputer
BrewDog, one of the world’s largest craft beer brewers, has exposed personally identifiable information (PII) belonging to more than 200,000 of its shareholders and customers, according to cybersecurity researchers. Cybersecurity consulting firm PenTest Partners discovered that a flaw in the official BrewDog app, which persisted for more than 18 months,…
Recent Posts
- Adidas Promo Codes & Deals: 30% Off
- Volvo’s ES90 sedan will be built with a Nvidia supercomputer
- With the Humane AI Pin now dead, what does the Rabbit R1 need to do to survive?
- One of the best AI video generators is now on the iPhone – here’s what you need to know about Pika’s new app
- Apple’s C1 chip could be a big deal for iPhones – here’s why
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010