Spoutible's API exposed personal data of its users, leading to a major data breach.
- Spoutible, an alternative social media platform, suffered a data breach due to an enumerable API.
- The API endpoint returned standard user data such as name and username, but also exposed sensitive information like email, IP address, and phone number.
- This data was not indicated to be publicly available, raising concerns about privacy and security.
- Actions recommended for Spoutible users include changing passwords, enabling two-factor authentication, and invalidating keys on other platforms.
- 207k exposed email addresses are now searchable in Have I Been Pwned, and impacted subscribers have been notified.