Code.org Hacked: Emails and Locations Data of Volunteers Compromised

Advertisement
By Manish Singh | Updated: 13 March 2016 23:56 IST

Code.org suffered a security breach on its website this week, the non-profit has confirmed. A firm based in Singapore managed to access some personal data on Code.org website leveraging a client-side vulnerability. As a result, Code.org says, more than 12,000 volunteer email addresses, and some locations data were compromised.

On Saturday, Code.org began to inform users whose email address or locations data had been compromised. The organisation confirmed to Gadgets 360 that the email was indeed genuine, with the CEO Hadi Partovi pointing us to the publication of a blog post on his website. The organisation said that it first wanted to warn the impacted users.

In the blog post, Code.org, a website that aims to encourage people to learn Computer Science, shed more light on the nature of the attack. It noted that only engineers and others who had volunteered to help in classrooms were impacted. The organisation insists that none of its 10 million student or teacher accounts are impacted.

Advertisement

"Earlier this week, a volunteer engineer told us he received an unsolicited recruiting email from a technical freelancing firm in Singapore," the firm wrote on a blog post. "We determined the firm was able to retrieve the volunteer's private email address by exploiting a client-side vulnerability on our volunteer map. We've since had 6 similar cases reported."

Advertisement

Code.org also noted that it has fixed the vulnerability and all private data was "secured against future attacks late Friday. We also inspected and secured the rest of our site from similar vulnerabilities."

Code.org also interestingly reached out to the Singapore-based recruiting firm which had exploited the vulnerability on its website. Here's the email the firm sent to Partovi. "Sorry about this.... our intention was we thought it'd be good to get them more opportunities to improve their own Computer Science skills beyond the opportunities available in their geographical boundaries / location. We've told our team to stop this with immediate effect. No one should be receiving anymore e-mails from us from this point onwards. You have my word that we will delete their email addresses from our mailing lists. They should not receive anymore emails from us."

Advertisement

Update 11:30PM IST: Partovi says that the Singapore-based firm has assured them that it will remove all the emails from its database.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Code, Education, Hacking, Internet, Security
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15 Battery Capacity, Charging Speed Teased Days Ahead of Launch
  2. These Are the 5 Biggest OxygenOS 16 Features You Should Know About
  3. iQOO 15 Launched With Snapdragon 8 Elite Gen 5, 50-Megapixel Cameras
  4. Realme GT 8, Realme GT 8 Pro With Ricoh GR Optics Launched: See Price
  5. Redmi K90 Pro Max Key Features Revealed Ahead of Launch on October 23
  6. WhatsApp Says AI Firms Can't Offer Chatbot Access via WhatsApp Business
  7. Sony WH-1000XM6 Review: The Best Just Got Better
  8. OnePlus 15 India Launch Teased; Key Features Revealed Ahead of Launch
  1. Samsung Galaxy XR Headset Launching Today: Know Price, Features, and Specifications
  2. Smartwatch Breakthrough Brings GPS Accuracy Down to a Few Centimetres
  3. SpaceX Launches 10,000th Starlink Satellite, Sets New Annual Record
  4. Scientists Discover New Seismic Clue to Predict Mount Etna Eruptions
  5. NASA and ESA Trace Mysterious Lunar Flashes to Meteors and Gas Leaks
  6. Valsala Club Is Streaming Now: Know All About the Malayali Comedy-Drama Movie
  7. Ganoshotru OTT Release: Know When and Where to Watch the Bengali Crime-Thriller Online
  8. Mr Shudai OTT Release: Know When and Where to Watch the Punjabi Horror-Comedy
  9. SpaceX May Miss First Crewed Moon Landing as NASA Reopens Artemis Bid
  10. OpenAI Introduces ChatGPT Atlas, an AI-Powered Web Browser With Agentic Capabilities
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.