BrewDog app flaw exposed data on 200,000 shareholders and customers, researchers claim
Researchers at Pen Test Partners say API token exploit could have allowed hackers to access personal information and account details
BrewDog is said to have exposed the details of 200,000 of its “Equity for Punks” shareholders and customers for approximately 18 months following a flaw in the company’s mobile app.
A fault with the way BrewDog's mobile app handled token authentication, which resulted in tokens being hard-coded into the application rather that sent after a successful authentication request, meant hackers could have easily bypassed the check and accessed user information.
Security consultants at Pen Test Partners (PTP), who discovered the fault, found that every user of the mobile app was given the same hard-coded API Bearer Token, effectively nullifying the authentication check.
The researchers, several of whom happen to be BrewDog investors, found that they could append a different customer ID to the end of the API endpoint URL and access that customer’s information. This included their name, date of birth, email and delivery addresses, number of shares held, shareholder number, and bar discount amount.
“An attacker could brute force the customer IDs and download the entire database of customers,” said researchers at PTP, in a blog post. “Not only could this identify shareholders with the largest holdings along with their home address, it could also be used to generate a lifetime's supply of discount QR codes!”
They also found the first use of hard-coded tokens was introduced with version 2.5.5 of the app, released in March 2020, meaning the app has been potentially vulnerable for around 18 months.
Following an alert to BrewDog, the company released a new version of the app on 13 September. However, the researchers claim this still allowed attackers to download bar discount codes for all users.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
A subsequent update then added the researchers to its beta programme to help it solve the issue. By 27 September a new version of the app was released, with PTP testing six different builds and giving the beer company feedback on each version for free.
“We were recently informed of a vulnerability in one of our apps by a third party technical security services firm, following which we immediately took the app down and resolved the issue. We have not identified any other instances of access via this route or personal data having been impacted in any way,” a BrewDog spokesperson told IT Pro. “There was therefore no requirement to notify users. We are grateful to the third party technical security services firm for alerting us to this vulnerability.”
In an email to PTP, posted on the research blog, BrewDog said that it has yet to find evidence in the logs that vulnerability has been exploited or that data has been exposed, although it was working to validate this conclusion.
The company also said that one of the factors in user notification is evidence of a breach as mandated by the ICO, adding that any user notification, if appropriate, would happen once the latest improvements are in place to limit further risk to its users.
It also asked PTP not to name the company in its blog post as it would expose its users to increased risk.
However, PTP has said it is unsure how BrewDog would have validated whether the vulnerability had been exploited.
"Every request will be coming from a valid account with a valid (but identical!) bearer token," the researchers said. "How therefore would they prove that the request was from the valid user and not from persons unknown?"
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Licensed mmWave: Opportunity or overhead?Industry Insights Ofcom’s latest mmWave auction unlocks major new capacity for 5G and FWA, offering a faster, more flexible complement to fiber - especially in dense urban areas
-
CISA issues alert as China-linked hackers exploit Brickstorm malware to target VMware serversNews Organizations, particularly in the critical infrastructure, government services, and facilities and IT sectors, need to be wary of Brickstorm
-
Security experts claim the CVE Program isn’t up to scratch anymore — inaccurate scores and lengthy delays mean the system needs updatedNews CVE data is vital in combating emerging threats, yet inaccurate ratings and lengthy wait times are placing enterprises at risk
-
IBM AIX users urged to patch immediately as researchers sound alarm on critical flawsNews Network administrators should patch the four IBM AIX flaws as soon as possible
-
Critical Dell Storage Manager flaws could let hackers access sensitive data – patch nowNews A trio of flaws in Dell Storage Manager has prompted a customer alert
-
Flaw in Lenovo’s customer service AI chatbot could let hackers run malicious code, breach networksNews Hackers abusing the Lenovo flaw could inject malicious code with just a single prompt
-
Industry welcomes the NCSC’s new Vulnerability Research Initiative – but does it go far enough?News The cybersecurity agency will work with external researchers to uncover potential security holes in hardware and software
-
Hackers are targeting Ivanti VPN users again – here’s what you need to knowNews Ivanti has re-patched a security flaw in its Connect Secure VPN appliances that's been exploited by a China-linked espionage group since at least the middle of March.
-
Broadcom issues urgent alert over three VMware zero-daysNews The firm says it has information to suggest all three are being exploited in the wild
-
Nakivo backup flaw still present on some systems months after firms’ ‘silent patch’, researchers claimNews Over 200 vulnerable Nakivo backup instances have been identified months after the firm silently patched a security flaw.
