• About Us
  • Disclaimer
  • Contact Us
  • Privacy Policy
Saturday, March 14, 2026
mGrowTech
No Result
View All Result
  • Technology And Software
    • Account Based Marketing
    • Channel Marketing
    • Marketing Automation
      • Al, Analytics and Automation
      • Ad Management
  • Digital Marketing
    • Social Media Management
    • Google Marketing
  • Direct Marketing
    • Brand Management
    • Marketing Attribution and Consulting
  • Mobile Marketing
  • Event Management
  • PR Solutions
  • Technology And Software
    • Account Based Marketing
    • Channel Marketing
    • Marketing Automation
      • Al, Analytics and Automation
      • Ad Management
  • Digital Marketing
    • Social Media Management
    • Google Marketing
  • Direct Marketing
    • Brand Management
    • Marketing Attribution and Consulting
  • Mobile Marketing
  • Event Management
  • PR Solutions
No Result
View All Result
mGrowTech
No Result
View All Result
Home Technology And Software

Petco takes down Vetco website after exposing customers’ personal information

Josh by Josh
December 10, 2025
in Technology And Software
0
Petco takes down Vetco website after exposing customers’ personal information


Pet wellness company Petco has taken a portion of its Vetco Clinics website offline after a security lapse exposed reams of customers’ personal information to the open web. 

After TechCrunch alerted the company to the exposed data relating to Vetco customers and their pets, Petco confirmed in a statement that it was investigating the data leak at its veterinary services company, and declined to comment further. 

The security lapse allowed anyone on the internet to download customer records from Vetco’s website without needing a user’s login information. At least one customer record was exposed and indexed by Google, allowing anyone to find the data by searching for it.

The customer records, seen by TechCrunch, included visit summaries, medical histories, and prescription and vaccination records, among other files relating to Vetco customers and their pets. 

The files also contained customer names; their home address, email address, and phone number; the location of the Vetco clinic where the services were performed; medical assessments, tests and diagnoses; and the costs of goods, names of veterinarians, consent forms, owner signatures, and dates of service.

We also found animal names, species and breed, their sex, age and date of birth, their microchip number (if registered), their medical vitals, and prescription records in the files.

TechCrunch alerted Petco to the security lapse on Friday after discovering the vulnerability. The company acknowledged the data exposure days later on the following Tuesday after TechCrunch followed-up by attaching several exposed customer files to our email.

Petco spokesperson Ventura Olvera told TechCrunch late on Tuesday that the company has “implemented, and will continue to implement, additional measures to further strengthen the security of our systems,” though the company did not provide evidence for the claim.

Olvera would not say if the company has the technical means, such as logs, to determine if any data was extracted from the company’s systems during the course of the data spill.

How TechCrunch found the data spill

TechCrunch identified a vulnerability in how Vetco’s website generates copies of PDF documents for its customers.

Vetco’s customer portal, located at petpass.com, allows customers to log in and obtain veterinary records and other documents relating to their pet’s care. But TechCrunch found that the PDF generating page on Vetco’s website was public, and not protected with a password.

As such, it was possible for anyone on the internet to access sensitive customer files directly from Vetco’s servers by modifying the web address to input a customer’s unique identification number. Vetco customer numbers are sequential, which means one could access other customers’ data simply by changing a customer number by one or two digits. 

TechCrunch checked at intervals of 100,000 customers to determine how many records may have been exposed in total. The sequential customer numbers suggest that millions of Petco customers’ information could have been retrieved.

The bug is classed as an insecure direct object reference (or IDOR), a common lapse in security practices  that allows unfettered access to files on a server because there aren’t proper checks in place to make sure the person accessing the data is permitted to.

It’s not clear how long these customer records have been left exposed, but the customer record listed on Google was dated mid-2020.

Third Petco breach this year

By TechCrunch’s count, this is Petco’s third data breach in 2025.

Earlier this year, hackers associated with the Scattered Lapsus$ Hunters hacking collective allegedly stole reams of data from a database of customer information that Petco hosts with cloud giant Salesforce. The hackers demanded victim companies pay a ransom to not have their information leaked.

In September, Petco disclosed a second data breach involving a security issue that the company said it discovered on its own. Petco blamed the data leak on “a setting within one of our software applications that inadvertently allowed certain files to be accessible online,” but did not provide specific details of the incident. 

That data breach included sensitive customer information, such as Social Security numbers, driver’s licenses, and financial information, including debit and credit card numbers.

Olvera declined to say how many people are affected by the September incident, but California law requires companies to disclose data breaches publicly when the number of victims in the state crosses 500 people.

TechCrunch believes this latest data leak involving Vetco is a separate security incident, given that Petco began notifying its customers of the previous data leak several months ago.



Source_link

READ ALSO

Y Combinator-backed Random Labs launches Slate V1, claiming the first 'swarm-native' coding agent

OpenAI reportedly plans to add Sora video generation to ChatGPT

Related Posts

Y Combinator-backed Random Labs launches Slate V1, claiming the first 'swarm-native' coding agent
Technology And Software

Y Combinator-backed Random Labs launches Slate V1, claiming the first 'swarm-native' coding agent

March 14, 2026
OpenAI reportedly plans to add Sora video generation to ChatGPT
Technology And Software

OpenAI reportedly plans to add Sora video generation to ChatGPT

March 14, 2026
What to Do in Vegas If You’re Here for Business (2026)
Technology And Software

What to Do in Vegas If You’re Here for Business (2026)

March 14, 2026
Nyne, founded by a father-son duo, gives AI agents the human context they’re missing
Technology And Software

Nyne, founded by a father-son duo, gives AI agents the human context they’re missing

March 13, 2026
NanoClaw and Docker partner to make sandboxes the safest way for enterprises to deploy AI agents
Technology And Software

NanoClaw and Docker partner to make sandboxes the safest way for enterprises to deploy AI agents

March 13, 2026
This web app lets you ‘channel surf’ YouTube like a ’90s kid watching cable
Technology And Software

This web app lets you ‘channel surf’ YouTube like a ’90s kid watching cable

March 13, 2026
Next Post
Craft Food Roblox Blueberry Banana Popsicle Recipe

Craft Food Roblox Blueberry Banana Popsicle Recipe

POPULAR NEWS

Trump ends trade talks with Canada over a digital services tax

Trump ends trade talks with Canada over a digital services tax

June 28, 2025
Communication Effectiveness Skills For Business Leaders

Communication Effectiveness Skills For Business Leaders

June 10, 2025
15 Trending Songs on TikTok in 2025 (+ How to Use Them)

15 Trending Songs on TikTok in 2025 (+ How to Use Them)

June 18, 2025
App Development Cost in Singapore: Pricing Breakdown & Insights

App Development Cost in Singapore: Pricing Breakdown & Insights

June 22, 2025
Google announced the next step in its nuclear energy plans 

Google announced the next step in its nuclear energy plans 

August 20, 2025

EDITOR'S PICK

Why Reddit’s Refusal to Track You Is Marketing Gold [+ Video]

Why Reddit’s Refusal to Track You Is Marketing Gold [+ Video]

July 2, 2025
Why Your Fitness Trainers Are Your Most Underutilized Marketing Asset

Why Your Fitness Trainers Are Your Most Underutilized Marketing Asset

February 1, 2026
How to Get Free Seeds in Grow a Garden

How to Get Free Seeds in Grow a Garden

September 2, 2025
How to use Pixel features for Halloween

How to use Pixel features for Halloween

October 18, 2025

About

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

Follow us

Categories

  • Account Based Marketing
  • Ad Management
  • Al, Analytics and Automation
  • Brand Management
  • Channel Marketing
  • Digital Marketing
  • Direct Marketing
  • Event Management
  • Google Marketing
  • Marketing Attribution and Consulting
  • Marketing Automation
  • Mobile Marketing
  • PR Solutions
  • Social Media Management
  • Technology And Software
  • Uncategorized

Recent Posts

  • Gemini’s task automation is here and it’s wild
  • Y Combinator-backed Random Labs launches Slate V1, claiming the first 'swarm-native' coding agent
  • Silverpush Releases Trend Intelligence Platform for Contextual Advertising
  • What Is Content Decay? (And How to Fix It Before It Tanks Your Traffic)
  • About Us
  • Disclaimer
  • Contact Us
  • Privacy Policy
No Result
View All Result
  • Technology And Software
    • Account Based Marketing
    • Channel Marketing
    • Marketing Automation
      • Al, Analytics and Automation
      • Ad Management
  • Digital Marketing
    • Social Media Management
    • Google Marketing
  • Direct Marketing
    • Brand Management
    • Marketing Attribution and Consulting
  • Mobile Marketing
  • Event Management
  • PR Solutions