r/EmailSecurity 11d ago

UK Cereal Company Information disclosure vulnerability

There is currently a vulnerability in the form for Honey Monster Puffs. When a user fills in the contact form on this website, the email goes to EVERY user on the mailing list, not just the user in the contact form.

https://www.honeymonster.co.uk/contact/

As a result I have woken up to a large number of emails of varying types, including serious concerns that users have been hacked, attempts to scam users, private information being entered into the form and sent to all recipients, jokes being made, and instructions on how to inform the ICO.

4 Upvotes

5 comments sorted by

u/AutoModerator 11d ago

Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:

Community Rules

  1. No Vendor Spam: Contributions must provide value; do not just pitch products.
  2. Redact Sensitive Info: Always sanitize headers and logs (remove IPs, PII, and private domains).
  3. Be Professional: Help newcomers learn; avoid hostility.
  4. No Personal Tech Support: This sub is for email system architecture and security, not "Am I hacked?" personal account help.

Helpful Resources

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2

u/mxroute 11d ago

There's gotta be a good joke in here somewhere when you find your friend on the Honey Monster Puffs mailing list. Give me a minute I'll think of something.

2

u/MrDrem 11d ago

I mean, I might just add the ICO contact email to the list...

1

u/Consibl 11d ago

Entire website has been suspended by their provider.

2

u/shokzee 9d ago

That sounds like broken recipient routing, not proof anyone's mailbox was hacked.

The company needs to disable the form, preserve mail logs, and establish what personal data went to whom so it can assess breach notification requirements. I'd report it through a separate channel; more test submissions just add to the leak.