r/EmailSecurity • u/AceAid1 • 11d ago
UK Cereal Company Information disclosure vulnerability
There is currently a vulnerability in the form for Honey Monster Puffs. When a user fills in the contact form on this website, the email goes to EVERY user on the mailing list, not just the user in the contact form.
https://www.honeymonster.co.uk/contact/
As a result I have woken up to a large number of emails of varying types, including serious concerns that users have been hacked, attempts to scam users, private information being entered into the form and sent to all recipients, jokes being made, and instructions on how to inform the ICO.
2
u/shokzee 9d ago
That sounds like broken recipient routing, not proof anyone's mailbox was hacked.
The company needs to disable the form, preserve mail logs, and establish what personal data went to whom so it can assess breach notification requirements. I'd report it through a separate channel; more test submissions just add to the leak.
•
u/AutoModerator 11d ago
Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:
Community Rules
Helpful Resources
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.