Original Release Date: 1/6/2020
A security researcher identified an unsecured Amazon S3 bucket while using Vistaprint’s logomaker service. Approximately 638,000 files containing both default and user-created logos were displayed, exposing some personalized information. While the database was secured within a few hours of notification and is not a great risk to personal data, this is the second exposure associated with Vistaprint within one month. Additionally, while attempting to contact the company, the researcher identified that two of the company’s domains do not have proper SSL certificates, raising security and data control concerns.