Whirlpool Leaves Customer Database Exposed and Reveals Nosy Practices

  • Whirlpool spilled the email addresses of many of its customers, admitting a number of 48000.
  • The exposed database contained 28.1 million records, constituting of device scanning reports.
  • The scans took place every sixty minutes, sending network status and appliance attributes back to Whirlpool.

Security researcher Bob Diachenko has noticed an unusual type of information in a publicly available instance on the Heartbeat monitoring service. Upon further inspection, the researcher figured out that the data belonged to people who owned Whirlpool appliances, and the database was hosting full system scan reports. As it became apparent very quickly, the database received new entries every hour. This means that Whirlpool is scanning their appliances in very frequent time intervals, checking their internet connection status. If they were online, Whirlpool collected the SAID numbers, model name and number, various attributes, and the customer email.

The exposed database contained more than 28.1 million records, which means that the email addresses of that number of people have been potentially compromised. While losing your email address isn’t exactly catastrophic, having this information correlated with other data can lead to phishing attacks and other forms of targeting. Moreover, scanning a device every 60 minutes is a bit too much as a practice, even if it is done on benevolent intentions.

Whirlpool_Stats
Source: Security Discovery

The researcher informed the century-old American manufacturer, and they took the database and service instance down the following day. Their official statement came a couple of days later, and it was the following:

“Our company was recently made aware of potential security concerns with respect to one of its databases. The database was immediately taken offline and secured. Our investigation showed that 48,000 emails were publicly available – but no confidential information was exposed. We are in the process of reaching out to impacted consumers. Our company appreciated this notification so the issue could be quickly addressed.”

The fact that 28.1 million records corresponded to just 48000 email addresses is up to you to accept. In the same way that using Whirlpool IoT appliances is up to you to decide. Generally, whatever is connected to the internet constitutes a privacy and security risk. This case of dishwashers and refrigerators phoning back to Whirlpool every hour works perfectly to highlight the risks that we consumers often forget when dealing with smart devices.

Do you own a Whirlpool smart appliance? Will you be trusting them from now on? Let us know of your comments in the section down below, or join the discussion on our socials, on Facebook and Twitter.

Latest
How to Watch Parental Guidance Season 2 (2023) Online Free from Anywhere
Parental Guidance is back with a second season of parenting styles, and you’ll be able to stream the episodes online quite easily...
How to Watch Vicky McClure: My Grandad’s War Online Free from Anywhere
Vicky McClure: My Grandad's War is a new British special that will relive one of the most momentous chapters of World War...
How to Watch For Her Sins Online Free from Anywhere
Behind every perfect family lies unseen drama, which makes For Her Sins the perfect show to watch this month. The best part...
For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: Chrome, Edge, Firefox, Safari