Original Release Date: 10/21/2019
A Whirlpool web interface was publicly exposed, containing data for the Heartbeat monitoring service. The exposed data contained more than 28 million records of information collected from internet of things (IoT) connected home appliances, such as customer email, SAID number (smart appliance ID), model name and number, and different attributes of the scanned appliance. Within 24 hours of notifying Whirlpool, the database and web interface were taken offline and secured. While approximately 48,000 emails were publicly available, no confidential information was exposed. Whirlpool is reaching out to impacted customers.