Skip to main content

Massive data leak just exposed the personal info of 6 million shoppers — how to stay safe

A person sat at a computer and a tablet, coding
(Image credit: Getty Images)

Editor's note: We received a statement from VTEXT to clarify details within this article and have updated this article with quotes from the company's official statement as well as additional details to reflect the most updated information possible.

A major e-commerce company, VTEX, has been affected by a data leak that involves the personally identifiable information and sensitive data of more than 6 million people for more than half a year, according to an investigation from Cybernews. This is particularly concerning with a major shopping event like Amazon Prime Big Day Deals going on, as there will likely be even more scams, phishing attacks and fraud attempts.

In February of this year, Cybernews researchers said they found that VTEX had unknowingly uploaded a very large amount of their users data to the open internet. This occurred because of an unauthenticated container — basically, human error which caused a cloud storage environment to be misconfigured or left open without a password. Private data was then visible and accessible to anyone online who searched for it.

How to stay safe after a data breach

Woman using smartphone and laptop

(Image credit: Shutterstock)

One of the main risks after a data breach is phishing attacks, which may look like they come from a legitimate retailer or website. So one of the things to stay on alert for is emails or texts that appear like they come from a VTEX-affiliated site or any site you've shopped at previously in regard to a delivery issue. Likewise, you may see phishing emails which claim there is an order confirmation for something you didn’t buy.

If you haven't already invested in one of the best identity theft protection services, it's best to do so before it's too late. Those who have identity theft protection in place will be able to receive alerts for any suspicious behavior and will have experts on-hand should any of their data be misused.

As always, we recommend you to be on high alert for phishing attempts – specifically look out for any emails that sound urgent and want you to “act now” to fix an issue, to provide additional personal or financial details, or need you to correct an account problem. It's also important to stay vigilant against social engineering attacks and to monitor your accounts for suspicious activity. The best way to stay safe against phishing is to avoid clicking on any links, QR codes or attachments in emails or messages from unknown senders.

From there, you'll want to make sure you're protected from online scams and hacks by using one of the best antivirus software solutions on all your devices, and when you're online, use their built-in protections like a VPN or a hardened browser to help keep you and your devices safe from malware and other online threats.

Follow Tom's Guide on Google News to get our up-to-date news, how-tos, and reviews in your feeds. Make sure to click the Follow button.

More from Tom's Guide

Amber Bouman
Senior Editor Security

Amber Bouman is the senior security editor at Tom's Guide where she writes about antivirus software, home security, identity theft and more. She has long had an interest in personal security, both online and off, and also has an appreciation for martial arts and edged weapons. With over two decades of experience working in tech journalism, Amber has written for a number of publications including PC World, Maximum PC, Tech Hive, and Engadget covering everything from smartphones to smart breast pumps. 

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.