Menu
Browse

Cyber Incident Victim: Typeform

Date:

Jun 2018

Location:

Spain

Summary

An online survey and form service experienced a data breach when an attacker exploited a vulnerability to download a backup file containing customer information collected through surveys and forms, though passwords and payment details were not compromised. The company detected the intrusion, addressed the security flaw within 30 minutes, and notified affected customers two days later, with impact limited to those receiving notifications; one customer, a payment provider, confirmed exposure of data for approximately 20,000 users. The incident affected clients including major technology firms and other prominent organizations.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 4 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On June 27, 2018, at 14:00 Central European Time, Typeform employees detected unauthorized access to a server containing a customer data backup file. The Barcelona-based online survey provider confirmed an attacker exploited an undisclosed vulnerability to download this backup, which included information collected through customer surveys and forms up to May 3, 2018. Within thirty minutes of discovery, the company secured the compromised server and remediated the security flaw. Typeform delayed public disclosure until late Friday, June 29—two days after detection—limiting immediate media response due to weekend staffing constraints. The breach notification clarified that stolen records did not contain user passwords or payment card details, though it encompassed sensitive respondent information submitted through Typeform-powered questionnaires. Impacted customers received direct email notifications, indicating the backup file did not contain all client data but selectively affected certain accounts.

Cyber Incident Image

The incident exposed information from high-profile organizations using Typeform's services, including Apple, Uber, Airbnb, Nike, Trello, and Forbes. Subsequent disclosures revealed specific consequences, such as payment provider Monzo reporting compromise of survey data for approximately 20,000 users. Typeform characterized the breach as contained following the server's rapid isolation but did not disclose forensic details regarding the attacker's identity, intrusion methodology beyond the initial vulnerability exploitation, or total affected records. This marked the third major data security incident reported that week, following breaches at Ticketmaster and Adidas. The company's communication emphasized the exclusion of financial credentials from exfiltrated data while acknowledging exposure of customer-collected survey responses through its platform.

Sources
Sources available to members
1 source