Vero Moda, Jack and Jones, Bestseller Site's Bug Had Put User Data at Risk

A security researcher uncovered the flaw with Bestseller India's sites in 2019, but the company only fixed in December.

Advertisement
By Gopal Sathe | Updated: 8 April 2021 14:56 IST
Highlights
  • A bug on Bestseller sites like Vero Moda put user data at risk for months
  • The bug has been fixed, but it's not clear how many users were affected
  • Phone numbers and addresses were revealed through this bug

Although the flaw has now been resolved, user records could have been leaked in the last year.

Vero Moda, Jack and Jones, Only, and other Bestseller India websites had a security flaw that allowed the hijacking of user accounts by anyone who simply knew the targets email ID used for signing up. This would in turn expose information such as the user's delivery addresses, their full name and phone number, and any saved credits with the sites. Although this information might not worry you, such data is actually highly valuable, and such information is also often used in phishing attacks to impersonate a real business and scam you out of your money. After Gadgets 360 raised the issue with the company — a full year after the security researcher had done so — the flaw was finally fixed, so customers data is no longer accessible, but the company has shared no details on how long customer data was at risk.

Security researcher Sayaan Alam wrote to the company's executives in September 2019. At the time, Alam tweeted to the company's CEO and was asked to send an email. Alam then sent a report of the issue to the company's CEO, and received a tweet in response from Vero Moda India's account, which said it had “forwarded this to the concerned team.”

In emails reviewed by Gadgets 360, Alam explained that he had been carrying out security testing and found a bug that could allow takeover of accounts for Vero Moda, Jack and Jones, and Only India. He asked to be connected to the company's CTO.

Advertisement

More than a year later, Alam said he did not receive any further information from the company, while the bug remained active. In December, Alam contacted Gadgets 360, and by creating a dummy account with a secret detail, we were able to confirm that Alam could in fact take over an account if he was aware of the email ID used to sign up.

Advertisement

Given how widely email IDs are used, it wouldn't be difficult for someone to obtain anyone's email ID, and then through this, get other details like a person's home address, compromising their safety and security.

In chats with Gadgets 360, Alam explained that he “did not want to make the issue public while the bug was still active, as that could put user accounts at risk.”

Advertisement

We created a dummy account to test whether the account takeover bug was live
Photo Credit: Screenshot

Advertisement

Gadgets 360 then reached out to the company, and exchanged emails with its Chief Information Officer Ranjan Sharma who responded quickly and collected information about Alam's findings. After getting the details, Sharma replied that he would “check.” A week later, when asked for updates, Sharma replied that the bug had been fixed.

“First of all let me thank you for bringing this to our notice,” he said via email. “We did a deep dive and found a version issue with our system and hence the token exchange was getting missed out which we fixed the same day. We are also working on a plan to reach out to our registered customers.”

At this point, we asked for information about how many customers use the site, and whether the company has any bug bounty program to encourage security researchers towards bringing in reports. However, Sharma did not share any responses after that and it's unclear if any users were informed — the test account we created did not receive any updates about its information being breached — three months after the issue was disclosed to the company and the bug fixed.

Sharma and Bestseller responded quickly when contacted by Gadgets and resolved the issue once it was discussed, which is a positive development. However, the lack of communication to users is one area that could certainly be improved upon.

The bug in question, as demonstrated by Alam, was fairly simple, and it is possible that any number of user data could have been compromised by this flaw. However, this is in line with a continuing problem in India, where security researchers are actively discouraged from exploring weaknesses in online systems — and users are rarely, if ever, told about problems unless the matter goes public from other sources.


Does WhatsApp's new privacy policy spell the end for your privacy? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, and wherever you get your podcasts.

Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Security, Data Leak
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  2. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  3. [Exclusive] Noise to Launch Flagship Master Series Over-Ear Headphones Soon
  4. Samsung Begins Rolling Out One UI 8 Update to the Galaxy S25 Series
  5. Flipkart Big Billion Days Sale: Discounts on Motorola Phones Announced
  6. iOS 26 Update for iPhone Releases Today: Everything You Need to Know
  7. Realme P3 Lite 5G With 6,000mAh Battery Launched in India at This Price
  8. Best Mobiles Under Rs. 60,000 in India
  9. Gemini Overtakes ChatGPT on App Store, Reaches the Top Spot
  10. US President Donald Trump Appeals Block on Removing Fed Governor Lisa Cook
  1. iOS 26 Update Released Alongside iPadOS 26 and macOS Tahoe: Check Eligible Models, How to Download
  2. Scientists Propose Space Missions to Chase Down Interstellar Comets
  3. Iceland Plume Discovery Reveals Ancient Volcanic Funnels Across North Atlantic
  4. Huawei Watch Ultimate 2 Design Renders Leaked, Could Launch Soon
  5. Marvel's Wolverine Will Reportedly Launch in 2026; Insomniac's Venom Game in 'Active Development'
  6. US President Donald Trump Challenges Block on Removing US Fed’s Lisa Cook
  7. iPhone 17 Series Outpaces iPhone 16 in Demand While iPhone 17 Pro Max Tops Pre-Orders, Analyst Says
  8. iPhone 16 Remained Top Selling Smartphone For Second Consecutive Quarter Globally: Report
  9. Samsung Galaxy S25 FE Launched in India With 6.7-Inch AMOLED Screen, 50-Megapixel Camera: Price, Features
  10. iPhone 18 Series Tipped to Feature Smaller Dynamic Island, Might Launch Without Under-Display Face ID
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.