Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      June 2, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      June 2, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      June 2, 2025

      How To Prevent WordPress SQL Injection Attacks

      June 2, 2025

      How Red Hat just quietly, radically transformed enterprise server Linux

      June 2, 2025

      OpenAI wants ChatGPT to be your ‘super assistant’ – what that means

      June 2, 2025

      The best Linux VPNs of 2025: Expert tested and reviewed

      June 2, 2025

      One of my favorite gaming PCs is 60% off right now

      June 2, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      `document.currentScript` is more useful than I thought.

      June 2, 2025
      Recent

      `document.currentScript` is more useful than I thought.

      June 2, 2025

      Adobe Sensei and GenAI in Practice for Enterprise CMS

      June 2, 2025

      Over The Air Updates for React Native Apps

      June 2, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      You can now open ChatGPT on Windows 11 with Win+C (if you change the Settings)

      June 2, 2025
      Recent

      You can now open ChatGPT on Windows 11 with Win+C (if you change the Settings)

      June 2, 2025

      Microsoft says Copilot can use location to change Outlook’s UI on Android

      June 2, 2025

      TempoMail — Command Line Temporary Email in Linux

      June 2, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Durex India’s Security Lapse Reveals Personal Data of Customers

    Durex India’s Security Lapse Reveals Personal Data of Customers

    August 30, 2024

    Durex India, the local arm of the popular British condom and personal lubricants brand, has reportedly suffered a significant cyberattack that has exposed sensitive customer information online. The Durex India data breach reportedly involved a leak of sensitive customer data being accessible through an inadequately secured order confirmation page on the Durex India website.

    The exposed information included full names, phone numbers, email addresses, shipping addresses, ordered items and payment details. The incident, discovered in late August 2024, raises concerns about data security practices and the potential consequences for consumers who shared their private details.

    Scope of Durex India Data Breach and Response

    Security researcher Sourajeet Majumder was the first to report this issue. on his X account. Majumder found that that over hundreds of customers were affected due to inefficient security measures on the brand’s order confirmation page. Although the exact number of customers affected and the duration of the vulnerability are still unknown, Majumder highlighted the gravity of the situation, given the intimate nature of the products involved.

    “A leak as such not only puts the customer’s privacy at risk but also makes them prone to social harassment or moral policing,” he posted on X.

    Source: X

    Following his discovery, Majumder shared that he reached out to India’s Computer Emergency Response Team (CERT-In) which acknowledged his email. If proven, the potential consequences of this data breach could be critical. Durex India should take appropriate measures to protect the privacy and security of the stakeholders involved. Data breaches of this nature can lead to identity theft, financial fraud, and a loss of trust among clients, potentially jeopardizing the company’s standing in the industry.

    As things stand, details regarding the extent of the Durex India data breach, data compromised, and the motive behind the cyber assault remain undisclosed.

    To ascertain the veracity of the data breach, The Cyber Express has reached out to the officials of Durex India and its parent company Reckitt. As of writing of this news report, no response has been received from Durex or Reckitt leaving the data breach claim unverified.

    Hostinger

    Repercussions of Alleged Breach

    This kind of data leak can have serious repercussions for affected customers. Having personal details like names, addresses, and phone numbers exposed online can be a significant privacy violation. These details can be used for targeted marketing campaigns, spam calls, or even identity theft.

    In regions with conservative social norms surrounding sexual health, customers who purchased Durex products could be subjected to social stigma or embarrassment due to the exposed data. If payment information was also accessible, it could put customers at risk of fraudulent charges.

    The Durex India data breach highlights the importance of robust data security practices in the e-commerce industry. Businesses that collect sensitive customer information, especially personal details related to health and wellness, have a responsibility to ensure the highest levels of security. Practices like secure coding, data encryption, and regular security audits are crucial to prevent breaches and protect customer data.

    This incident also raises questions about data protection regulations in India. While the General Data Protection Regulation (GDPR) has been a driving force for data privacy in Europe, India is still in the process of finalizing its own comprehensive data protection framework. The potential effects of the exposed Durex India data on affected customers might highlight the need for stricter data security regulations in the country.

    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleNew Malware Masquerades as Palo Alto VPN Targeting Middle East Users
    Next Article Fota Wildlife Park Confirms Cyberattack, Investigates Data Exposure

    Related Posts

    Security

    Chrome Zero-Day Alert: CVE-2025-5419 Actively Exploited in the Wild

    June 2, 2025
    Security

    CISA Adds 5 Actively Exploited Vulnerabilities to KEV Catalog: ASUS Routers, Craft CMS, and ConnectWise Targeted

    June 2, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    You will soon be able to VLC player’s AI subtitles in multiple languages

    Operating Systems

    The Elder Scrolls 4: Oblivion Remastered has already reached 4 million players in its first week

    News & Updates

    Xbox CEO Phil Spencer says Xbox Series X|S and PlayStation 5 are too similar — “I want us to innovate and make hardware the differentiator.”

    News & Updates

    CVE-2025-48491 – Project AI Exposed Hardcoded API Key Vulnerability

    Common Vulnerabilities and Exposures (CVEs)
    GetResponse

    Highlights

    CVE-2025-47512 – Tainacan Path Traversal

    May 24, 2025

    CVE ID : CVE-2025-47512

    Published : May 23, 2025, 1:15 p.m. | 15 hours, 14 minutes ago

    Description : Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in tainacan Tainacan allows Path Traversal. This issue affects Tainacan: from n/a through 0.21.14.

    Severity: 8.6 | HIGH

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Mitigating Memorization in Language Models: The Goldfish Loss Approach

    June 21, 2024

    FBI and CISA Warn of BlackSuit Ransomware That Demands Up to $500 Million

    August 8, 2024

    The 47 best Amazon Labor Day deals you can shop now

    August 31, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.