+49 (0) 821 / 80 99 46 - 0
+49 (0) 821 / 80 99 46 - 0
Request call-back
Contact us
Report a claim
exali.com My business. My insurance.
My exali login
exali.com
  • Insurance

    Professional Indemnity

    Professional Indemnity Insurance for Digital Professions

    General

    Professional Indemnity Insurance
    General Liability Insurance
    Financial Losses Insurance

    More Information

    Selected Professions
    Glossary
  • News & Stories
  • Blog
  • Product finder
    Product finder
  • My exali login
  • Report a claim
"Personal support for reliable business protection in Portugal"
Tobias Steinle
Product & Online-Marketing Manager
Tobias Steinle,Product & Online-Marketing Manager
My business. My insurance.
Tobias Steinle
Product & Online-Marketing Manager
Tobias Steinle,Product & Online-Marketing Manager

Already in?

With our Newsflash, you benefit from the latest news and topics relating to your business every month:

  • Tips, information and expert interviews
  • Real damage events
  • Legal matters and dangers of warnings
The perfect support for your success.

Home / News&Stories /
App Data Leak: How a Delivery Service Slopped Up on Security
Inadequate Cybersecurity

App Data Leak: How a Delivery Service Slopped Up on Security

Post by Daniela Reichert Post by Daniela Reichert Author
Post by Daniela Reichert Post by Daniela Reichert Author
Friday, 25 November 2022
Friday, 25 November 2022
Back to the overview

Data leak at the German grocery delivery service Gorillas: Because the app had some gaps, data from over 200,000 customers was publicly accessible. Every company’s nightmare came true for this start-up - but the incident also showed how important it is not to take risks when protecting personal data.

Inadequate Cybersecurity in Delivery Service App

2021 was not a good year for Gorillas, even though it all started so magically: Founded in Berlin in March 2020, the start-up received an incredible 244 million euros in the second round of investors and was seen as a unicorn in financing circles. Gorillas quickly became one of the most successful grocery delivery services in Germany, due to its supermarket prices, fast delivery (goods should reach the customer within ten minutes of completing the order) and the fact that no additional delivery costs apply.

Unfortunately, the euphoria got its first damper in early 2021 when it turned out that the Berlin start-up had a massive data problem. A group of tech-savvy German researchers from Ulm took a closer look at the Gorillas app and discovered: There was an urgent need for some catch-up work. “Zerforschung” (a word play from the German words "Zerstörung" (destrucion) and "Forschung" (research) literally translates as: Destruction Research) is the name of a German collective that regularly puts technical devices and IT programs through their paces. The researchers struck gold with the delivery service.

Security Hack Reveals Data Leak

Over one million order details from 200,000 customers were obtained by the collective from Gorillas during a review of the app. Particularly explosive: Among the data that Zerforschung received via the app were photos of front doors and doorbells. These probably came from drivers who were apparently supposed to document the order delivery. This kind of data would of course be a godsend for real cyber criminals. Because anyone who got their hands on all this customer data could contact the customers in Gorilla’s name - and get them to pay an invoice twice for example.

Zerforschung documented their “security hack” on their website and, according to their own statements, forwarded it to the Federal Administration’s Computer Emergency Response Team (CERT-Bund). The CERT-Bund then informed Gorillas about the data leak. According to a statement on Berlin.de, the start-up reacted immediately and announced that the security gap had now been closed. “To the best of the company’s knowledge, no data was stolen or otherwise misused,” Gorillas continued. By the way: Gorillas is actually the second delivery service where Zerforschung found a data security issue. In March 2021, the collective documented a similar data leak with its competitor Flink.

Tip:

Read the following article to find out which cyber risks your company is exposed to and how you can best prepare your business for them: IT Risks: Lessons Learned and Precautions For Your Business

An Embarrassing Glitch but No Real Damage

Of course, both companies were fortunate in their misfortune, as there doesn’t appear to be any real harm caused aside from the embarrassment. In the event of an actual hacker attack, the whole thing could have been significantly more expensive: Because hacker attacks no longer only affect larger companies, but also small companies and freelancers from the IT sector. The potential damage from cybercrime includes:

  • Ransomware for stolen or encrypted data (ransomware)
  • Claims for damages from customers who became victims of fraud due to the hack
  • Costs of restoring or repairing IT systems
  • Costs of hiring external computer forensics analysts

Better Protection against Cybercrime with exali

In addition to Professional Indemnity Insurance via exali, you can book the optional First-party Cyber and Data Risks Insurance (FPC) add on. It offers you additional protection against the incalculable risks of cybercrime. First-party claims are insured - i.e. damage caused to your own IT systems by, for example, hacker attacks, ransomware, malware, phishing or theft of data carriers. The insurer not only covers the costs associated with restoring or repairing your IT systems, but also the costs of hiring external computer forensic specialists and specialised lawyers, as well as crisis management and PR.

Daniela Reichert
Author profile
Daniela Reichert
Online Editor

Daniela has been working in the areas of (online) editing, social media and online marketing since 2008. At exali, she is particularly concerned with the following topics: Risks through digital platforms and social media, cyber dangers for freelancers and IT risk coverage.
In addition to her work as an online editor at exali, she works as a freelance editor and therefore knows the challenges of self-employment from her own experience.

Author profile
Daniela Reichert
Daniela Reichert

Online Editor

Daniela has been working in the areas of (online) editing, social media and online marketing since 2008. At exali, she is particularly concerned with the following topics: Risks through digital platforms and social media, cyber dangers for freelancers and IT risk coverage.
In addition to her work as an online editor at exali, she works as a freelance editor and therefore knows the challenges of self-employment from her own experience.

Previous article
 
Back
 
Next article
These articles might also interest you
Expert Interview: Cyber Security for Companies
Expert Interview: Cyber Security for Companies
How you Can Protect your Business against Critical Vulnerabilities in Operating Systems  or Software
How you Can Protect your Business against Critical Vulnerabilities in Operating Systems or Software
Viruses, Worms and Trojans: What Are the Differences and How You Can Protect Yourself
Viruses, Worms and Trojans: What Are the Differences and How You Can Protect Yourself
Personal Injury Due to Programming Error: Singer Falls Five Meters
Personal Injury Due to Programming Error: Singer Falls Five Meters
These articles might also interest you
Expert Interview: Cyber Security for Companies
Expert Interview: Cyber Security for Companies
How you Can Protect your Business against Critical Vulnerabilities in Operating Systems  or Software
How you Can Protect your Business against Critical Vulnerabilities in Operating Systems or Software
Viruses, Worms and Trojans: What Are the Differences and How You Can Protect Yourself
Viruses, Worms and Trojans: What Are the Differences and How You Can Protect Yourself
Personal Injury Due to Programming Error: Singer Falls Five Meters
Personal Injury Due to Programming Error: Singer Falls Five Meters
0 Comments
Write a comment
Please fill in all areas marked as * required fields.

By clicking the ‘Send’ button, the data entered in the above form will be collected and processed for the purpose of processing your request. All data is transmitted in encrypted form and only processed within the scope of the information in the data protection information. You have a right of objection with effect for the future.

Insurance

  • Professional Indemnity for Digital Professions
  • Selected Professions
  • Report damage event

News & Stories

  • Articles
  • Videos
  • Glossary
  • Subscribe to Newsletter

About us

  • About exali
  • Jobs
  • Contact us
  • Imprint
  • Data Protection Declaration
  • Right of withdrawal
© exali AG, all rights reserved
Unfortunately, your web browser is out of date! Please update your browser in order to be able to use all functions in the premium calculator.
Choose the location of your headquarter
Depending on your country, the insurance offered by exali may vary slightly. Please select the country where you have your headquarter to get the offer that suits you best.