A data leak has exposed the personal information of about 5,600 users of Google’s VirusTotal cybersecurity platform. The leaked data includes the names and emails of employees at U.S. and German intelligence organizations and some German corporations.
German newspaper Der Speigel, which first reported the breach, said some VirusTotal users in the leaked file could be found on LinkedIn, confirming that the data is authentic.
A spokeswoman for Google told Der Speigel that sometime in June, a VirusTotal employee accidentally uploaded a file containing the personal details of users on the platform, but the file was taken down within an hour.
VirusTotal is a free online service that allows users to upload and scan files and URLs for malware. The service compares files against the database of 70 antivirus engines.
Organizations Affected by the VirusTotal Leak
According to Der Spiegel, about 20 accounts in the leaked VirusTotal database belong to employees at the U.S. Cyber Command. The leaked file also includes the data of employees at the U.S. Department of Justice, the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI).
German organizations affected by the leak include the Federal Police, the Federal Criminal Police Office, the Military Counterintelligence Service (MAD), the Federal Office for Information Security (BSI), and the Federal Communications Statistics Office.
The leaked file also includes the data of employees at several German corporations, including Deutsche Bahn, BMW, Mercedes-Benz, Allianz, Bundesbank, and Deutsche Telekom.
In March 2022, the BSI warned organizations against automatically uploading suspicious files to VirusTotal as such files could contain sensitive data. In light of this leak, the BSI reiterated its warning, adding that VirusTotal’s terms of use allow the platform to share data with third parties.
Fallout of the Data Leak
Meanwhile, Google says VirusTotal is reviewing its internal processes to prevent a similar incident in the future.
While the leaked file only includes names and email addresses, this is enough information for cybercriminals to target the affected employees in phishing and other social engineering attacks.
Threat actors are launching increasingly sophisticated phishing attacks, posing as trusted brands to snare victims. According to a report by IBM, about 41 percent of cyberattacks in 2022 began with phishing. The report also revealed that Google, Microsoft, and Yahoo were the top three most impersonated brands in phishing attacks in 2022.
You can learn how to spot phishing attacks and improve your online safety in our comprehensive guide to phishing.
