Cannabis Company GrowDiaries Suffers Data Breach of 3.4 Million Users

Stu Sjouwerman | Nov 4, 2020

GrowDiaries Data BreachA recent report from SiliconANGLE released information that cannabis company GrowDiaries suffered a data breach with details of 3.4 million users being exposed online. 

The data breach incident was first discovered by security researcher Bob Diachenko on LinkedIn but was indexed by search engine BinaryEdge on September 22nd. The database was not taken down until almost a month later. The data exposure was on an unsecured database that had no passwords. This data includes email addresses, IP addresses, usernames, MD5-hashed passwords, and image URL's. 

GrowDiaries confirmed the database exposure but has not disclosed whether user details have been made available from unwanted third parties. 

“This breach is yet another example of a company leaving a server and critical information unsecured without any password protection, an unfortunate trend that has been the cause of many recent leaks,” Dr. Vinay Sridhara, chief technology officer of security posture firm Balbix Inc., told SiliconANGLE. 

This data breach was a major learning lesson to make sure that all of your organizational databases stay secure. This breach could also potentially be a potential gold mine for the bad guys to use this information for future planned social engineering attacks if this information is available on the dark web. 

SiliconANGLE has the full story

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.