Homegrown startup Yes Madam exposes customers' sensitive data: Report


New Delhi, Mar 7 (IANS): Homegrown startup Yes Madam has exposed the sensitive data of its customers and gig workers due to a server-side misconfiguration, the media reported.

According to TechCrunch, since February 20, the startup has left a database containing the full names, mobile numbers, mailing addresses, and email addresses of hundreds of thousands of Yes Madam customers who have been connected to the internet without a password.

In addition, customers' location data, including latitude and longitude values, as well as payment links and user device details, such as model names and IMEI numbers, were included in the database.

Yes Madam is a Home Salon and a tech-enabled platform for beauty and wellness that brings salon and spa services to customers' homes. It operates in more than 30 cities in the country, according to the company's website.

The platform provides at-home salon services such as therapies, massage, spa, and male grooming.

Yes Madam's mobile apps received over a million downloads as well.

Moreover, the startup also exposed profile images, names and mobile numbers of gig workers on the platform, the report mentioned.

The database had entries of more than 9,00,000 users, according to CloudDefense.ai security researcher Anurag Sen, who discovered the exposed database.

However, Yes Madam later secured the database, said the report.

 

  

Top Stories


Leave a Comment

Title: Homegrown startup Yes Madam exposes customers' sensitive data: Report



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.