Bluspark Global
Incident posture
Linked entities
- Victim
- Bluspark Global
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Bluspark Global shipped a supply chain platform that left plaintext employee and customer passwords exposed and provided an unauthenticated API allowing anyone to retrieve user records and create administrator accounts. A security researcher identified these flaws, reported them through the Maritime Hacking Village, and after receiving no reply from the company alerted TechCrunch, which eventually prompted a response from Bluspark’s legal counsel. The company stated it had remedied the vulnerabilities, was engaging a third party for an independent assessment, and was developing a vulnerability disclosure program while asserting there was no indication of customer data misuse.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Eaton Zveare first identified security weaknesses in Bluspark Global’s systems in October 2025 after examining the source code of a customer’s website contact form that communicated with Bluspark’s API. He reported the findings to the Maritime Hacking Village, which attempted to notify Bluspark, but the company did not respond despite multiple emails, voicemails and LinkedIn messages over several weeks. After receiving no reply, Zveare contacted TechCrunch as a last resort, and TechCrunch reached out to Bluspark’s CEO Ken O’Brien and senior leadership, receiving no response on the first two attempts. On the third outreach, TechCrunch included a partial copy of O’Brien’s password to illustrate the severity of the exposure, prompting a reply from a law firm representing Bluspark a few hours later. The law firm indicated that Bluspark had begun addressing the flaws and was seeking a third‑party firm for an independent security assessment.
Zveare’s investigation revealed that Bluspark’s API documentation page allowed unauthenticated testing of commands, enabling anyone to retrieve user account records, including plaintext passwords for employees and customers, without needing credentials. Using the API, he was able to create a new administrator account, log into Bluvoyix, and access customer shipment records dating back to 2007. He also demonstrated that the contact form on a customer’s website could be altered to send malicious emails, such as phishing lures, appearing to originate from a legitimate Bluspark customer. The API’s user‑specific token was shown to be unnecessary for completing requests, confirming the lack of authentication. These actions exposed the full scope of customer data, shipment histories and internal credentials to anyone on the internet.
Following contact with Bluspark’s legal counsel, Zveare permitted TechCrunch to share his vulnerability report, after which the law firm stated that most of the flaws had been remediated and that Bluspark was working to retain an independent assessor. Bluspark’s attorney Ming Lee told TechCrunch the company was confident in the steps taken to mitigate potential risk but declined to disclose specifics of the vulnerabilities, the fixes, or the identity of any retained third‑party assessor. When asked whether any customer shipments had been manipulated via the exposed bugs, Bluspark said there was no indication of customer impact or malicious activity attributable to the issues, though it did not provide the evidence supporting that conclusion. Lee also noted that Bluspark was in discussions to establish a disclosure program for external security researchers to report future vulnerabilities, while CEO Ken O’Brien did not comment for the article.
Sources
Sources available to members: 1 source.