Cybersecurity News and Headlines
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityNewsPetco Takes Down Vetco Website After Exposing Customers’ Personal Information
Petco Takes Down Vetco Website After Exposing Customers’ Personal Information
Cybersecurity

Petco Takes Down Vetco Website After Exposing Customers’ Personal Information

•December 10, 2025
0
TechCrunch (Cybersecurity)
TechCrunch (Cybersecurity)•Dec 10, 2025

Companies Mentioned

Salesforce

Salesforce

CRM

Google

Google

GOOG

Why It Matters

The breach underscores persistent cybersecurity gaps in the pet‑care sector, exposing millions of customers to privacy risks and potential regulatory penalties, while eroding brand trust.

Key Takeaways

  • •IDOR flaw let anyone download Vetco PDFs.
  • •Records included owners' personal and pet medical data.
  • •Exposure potentially affected millions of Petco customers.
  • •Third Petco breach in 2025 raises compliance concerns.
  • •Petco promises further security enhancements, no breach details.

Pulse Analysis

The Vetco Clinics incident illustrates how a classic insecure direct object reference can turn a routine document‑generation feature into a data‑leak vector. By exposing a PDF‑generation endpoint without authentication, the site allowed attackers to iterate sequential customer IDs and harvest sensitive files. IDOR vulnerabilities are common across web applications, especially those that rely on predictable identifiers, and they often go unnoticed until a researcher or malicious actor discovers the flaw. In Vetco’s case, the issue persisted long enough for a 2020 record to be indexed by Google, amplifying the exposure.

Beyond the technical lapse, the breach raises significant privacy and compliance concerns. The leaked data includes personally identifiable information (PII) such as home addresses, phone numbers, and email addresses, as well as detailed veterinary records that could be considered health information under state privacy statutes. With California’s data‑breach notification law requiring disclosure when over 500 residents are affected, Petco may face legal scrutiny and potential fines. Repeated incidents this year also threaten customer confidence, as pet owners increasingly expect the same data‑security standards from pet‑care providers as they do from financial or healthcare services.

Petco’s response—promising additional security measures without detailing remediation—highlights a broader industry challenge: balancing rapid digital service rollout with robust security governance. Best practices include implementing strict access controls, randomizing or hashing customer identifiers, and conducting regular penetration testing focused on IDOR scenarios. For consumers, monitoring credit and identity alerts, and using unique passwords for pet‑care portals, can mitigate risk. The Vetco breach serves as a cautionary tale that even niche markets must adopt enterprise‑grade cybersecurity to protect both human and animal data.

Petco takes down Vetco website after exposing customers’ personal information

Read Original Article
0

Comments

Want to join the conversation?

Loading comments...