Security News > 2021 > February > Yandex Employee Caught Selling Access to Users' Email Inboxes

Yandex Employee Caught Selling Access to Users' Email Inboxes
2021-02-12 20:39

Russian Dutch-domiciled search engine, ride-hailing and email service provider Yandex on Friday disclosed a data breach that compromised 4,887 email accounts of its users.

The company blamed the incident on an unnamed employee who had been providing unauthorized access to the users' mailboxes for personal gain.

"The employee was one of three system administrators with the necessary access rights to provide technical support for the service," Yandex said in a statement.

It's not immediately clear when the breach occurred or when the employee began offering unauthorized access to third-parties.

"A thorough internal investigation of the incident is under way, and Yandex will be making changes to administrative access procedures," the company said.

In October last year, Amazon fired an employee for sharing customers' names and email addresses with a third-party.


News URL

http://feedproxy.google.com/~r/TheHackersNews/~3/Fi_bYovO4H4/yandex-employee-caught-selling-access.html

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Yandex 7 0 25 14 1 40