Last scanned 5 hours ago
No CVEs on record.
Not yet scanned
Not yet scanned
Not yet scanned
Thousands of web applications built on Netlify's AI-powered platform exposed sensitive corporate and personal data publicly on the internet due to improper data handling by developers using the platform. The incident demonstrates a systemic issue where Netlify's tools enabled rapid app creation without adequate built-in safeguards against data exposure.
Netlify was abused as an infrastructure service by attackers in the "AccountDumpling" phishing campaign that compromised approximately 30,000 Facebook accounts worldwide. The incident indicates Netlify's platform was leveraged without authorization to facilitate credential harvesting attacks.
Netlify was identified as one of several platforms abused by AccountDumpling, a Vietnamese-linked phishing operation, to facilitate a campaign that compromised approximately 30,000 Facebook accounts. The incident represents a confirmed case of Netlify's infrastructure being leveraged for malicious phishing purposes, though the breach itself originated from the threat actor's misuse rather than a vulnerability in Netlify's platform.
Netlify's platform was leveraged as an infrastructure component in the AccountDumpling phishing operation that compromised over 30,000 Facebook accounts worldwide. While Netlify itself was not breached, its service was actively used to facilitate the attack, indicating a confirmed security incident involving the vendor's platform.
Track score changes, new CVEs, and breach news automatically.
Start free monitoring - no credit cardGet daily risk scores, breach alerts, and compliance reports for all your SaaS tools.
Start free - 30 day trial