Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

OpenAI chief Sam Altman plans visit to India as AI leaders converge in New Delhi: sources

How PopWheels helped a food cart cut generators for e-bike batteries

Tech CEOs brag and argue about artificial intelligence at Davos

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Tech CEOs brag and argue about artificial intelligence at Davos

    24 January 2026

    Legal AI giant Harvey acquires Hexus as competition heats up in legal tech

    24 January 2026

    Meta cuts off teen access to AI characters before the new version

    23 January 2026

    Former Sequoia partner’s new startup uses AI to negotiate your calendar for you

    23 January 2026

    Are AI agents ready for the workplace? A new benchmark raises doubts.

    22 January 2026
  • Apps

    Ex-Googlers seek to captivate kids with an AI-powered learning app

    24 January 2026

    TikTok users are freaking out over the app’s “immigration status” collection — here’s what it means

    24 January 2026

    The latest Google Photos feature lets you make a meme

    23 January 2026

    Google now offers free SAT practice tests, powered by Gemini

    23 January 2026

    Substack launches a TV app

    22 January 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    50% off +1 ends | TechCrunch

    23 January 2026

    Capital One acquires Brex for a steep discount to its valuation, but early believers are laughing all the way to the bank

    23 January 2026

    Tiger Global and Microsoft will fully exit Walmart-backed PhonePe through its IPO

    22 January 2026

    Fintech firm Betterment confirms data breach after hackers sent fake crypto scam alert to users

    12 January 2026

    Flutterwave buys Nigeria’s Mono in rare African fintech exit

    5 January 2026
  • Hardware

    Apple iPhone just had its best year in India as the smartphone market remains generally flat

    24 January 2026

    From invisibility cloaks to AI chips: Neurophos raises $110 million to build tiny optical processors for inference

    23 January 2026

    Ring adds a new content verification feature to videos

    22 January 2026

    OpenAI aims to ship its first device in 2026, and it could be a headset

    21 January 2026

    Why Serve Robotics is acquiring a hospital assistant robot company

    21 January 2026
  • Media & Entertainment

    Amagi debuts in India as cloud TV software company tests investor appetite

    24 January 2026

    What you need to know about Netflix’s acquisition of Warner Bros.

    24 January 2026

    TikTok-style mini-dramas are set to make billions this year, even though they’re kind of crap

    23 January 2026

    TechCrunch Disrupt 2026 tickets now on sale: Lowest prices all year

    23 January 2026

    Spotify brings AI-powered playlists to the US and Canada

    22 January 2026
  • Security

    Investigators say Russian government hackers are behind attempted power outage in Poland

    24 January 2026

    Microsoft gave FBI set of BitLocker encryption keys to unlock suspects’ laptops: reports

    23 January 2026

    Ireland proposes new law to allow police to use spyware

    23 January 2026

    Under Armor says it is “aware” of data breach claims after 72 million customer records were posted online

    22 January 2026

    UStrive Security Lapse exposed personal data of its users, including children

    21 January 2026
  • Startups

    OpenAI chief Sam Altman plans visit to India as AI leaders converge in New Delhi: sources

    25 January 2026

    This startup will send the ashes of 1,000 people into space — affordably — in 2027

    24 January 2026

    The Rippling/Deel corporate espionage scandal may have taken another crazy turn

    24 January 2026

    Palmer Luckey Says Coolest Thing About Anduril’s Long Beach Expansion Is The Fighter Jets

    23 January 2026

    Humans& believes coordination is the next frontier for artificial intelligence, and they’re building a model to prove it

    23 January 2026
  • Transportation

    How PopWheels helped a food cart cut generators for e-bike batteries

    25 January 2026

    Tesla is shutting down Autopilot in an effort to boost adoption of its Full Self-Driving software

    24 January 2026

    Waymo was investigated by the National Transportation Safety Board for illegal school bus conduct

    24 January 2026

    Waymo continues the robotaxi ramp with its Miami service now open to the public

    23 January 2026

    GM to End Chevy Bolt EV Production Next Year, Move Chinese Buick to US Plant

    23 January 2026
  • Venture

    PraxisPro Raises $6M Seed Fund From AlleyCorp To Mentor Medical Sales Reps

    23 January 2026

    Ex-CEO of celeb fav gym Dogpound launches $5 million fund to back wellness companies

    22 January 2026

    Former OpenAI Sales Lead Joins VC Firm Acrew: OpenAI Taught Her Where Startups Can Build A ‘Moat’

    22 January 2026

    Sources: SGLang project emerges as RadixArk at $400M valuation as inference market explodes

    21 January 2026

    Retail startup Another raises $2.5 million to help sell excess inventory

    20 January 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Petco takes down Vetco website after exposing customers’ personal information
Security

Petco takes down Vetco website after exposing customers’ personal information

techtost.comBy techtost.com10 December 202504 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Petco Takes Down Vetco Website After Exposing Customers' Personal Information
Share
Facebook Twitter LinkedIn Pinterest Email

Pet wellness company Petco has taken part of its Vetco Clinics website offline after a security breach exposed troves of personal customer information to the open web.

After TechCrunch alerted the company to the exposed data related to Vetco customers and their pets, Petco confirmed in a statement that it was investigating the data breach at its veterinary services company and declined to comment further.

The security flaw allowed anyone on the Internet to download customer files from Vetco’s website without needing a user’s login information. At least one customer file was exposed and indexed by Google, allowing anyone to find the data by searching for it.

The customer records, seen by TechCrunch, included visit summaries, medical histories, and prescription and vaccination records, among other records related to Vetco customers and their pets.

The files also contained customer names. their home address, email address, and phone number; the location of the Vetco clinic where the services were performed; medical evaluations, tests, and diagnoses; and the cost of goods, names of veterinarians, consent forms, owner signatures, and dates of services.

We also found animal names, species and breed, their sex, age and date of birth, their microchip number (if registered), their medical information and prescription records in the records.

TechCrunch notified Petco of the security flaw on Friday after discovering the vulnerability. The company acknowledged the data exposure days later the following Tuesday after TechCrunch followed up by attaching several exposed customer files to our email.

Petco spokesman Ventura Olvera told TechCrunch late Tuesday that the company “has implemented and will continue to implement additional measures to further strengthen the security of our systems,” though the company did not provide evidence for the claim.

Olvera would not say whether the company has the technical means, such as logs, to determine whether data was extracted from the company’s systems during the data breach.

How TechCrunch found the data breach

TechCrunch found a vulnerability in the way Vetco’s website creates copies of PDF documents for its customers.

Vetco’s customer portal, located at petpass.comallows customers to log in and obtain veterinary records and other documents related to their pet’s care. But TechCrunch found that the PDF creation page on Vetco’s website was public and not password protected.

Therefore, it was possible for anyone on the Internet to access sensitive customer records directly from Vetco’s servers by modifying the web address to enter a customer’s unique identification number. Vetco’s customer numbers are sequential, meaning someone could access other customers’ data just by changing a customer number by a digit or two.

TechCrunch checked at intervals of 100,000 customers to determine how many records may have been exposed in total. The back-to-back customer numbers suggest that millions of Petco customer information could have been recovered.

The bug is classified as an insecure direct object reference (or IDOR), a common flaw in security practices that allows unrestricted access to files on a server because there aren’t proper checks in place to make sure the person accessing the data is allowed.

It’s unclear how long these customer files have been exposed, but the customer file cited by Google dates back to mid-2020.

Third Petco breach this year

By TechCrunch’s count, this is Petco’s third data breach of 2025.

Earlier this year, hackers associated with the hacking collective Scattered Lapsus$ Hunters allegedly stole reams of data from a database of customer information that Petco hosts with cloud giant Salesforce. The hackers demanded that the victim companies pay a ransom in order not to leak their information.

In September, Petco disclosed a second data breach involving a security issue the company said it discovered on its own. Petco blamed the data leak on “a setting in one of our software applications that inadvertently allowed certain files to be accessible online,” but did not provide specific details about the incident.

This data breach included sensitive customer information such as social security numbers, driver’s licenses and financial information including debit and credit card numbers.

Olvera declined to say how many people are affected by the September incident, but California law requires companies to publicly disclose data breaches when the number of victims in the state exceeds 500 people.

TechCrunch believes this latest data breach involving Vetco is a separate security incident, given that Petco began notifying its customers of the previous data breach several months ago.

customers cyber security data breach data report Exclusive exposing information personal Petco takes vetco website
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCashew research goes after the $90 billion market research industry with artificial intelligence
Next Article Founder of AI startup Tavus says users talk to AI Santa ‘for hours’ a day
bhanuprakash.cg
techtost.com
  • Website

Related Posts

OpenAI chief Sam Altman plans visit to India as AI leaders converge in New Delhi: sources

25 January 2026

How PopWheels helped a food cart cut generators for e-bike batteries

25 January 2026

Apple iPhone just had its best year in India as the smartphone market remains generally flat

24 January 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

OpenAI chief Sam Altman plans visit to India as AI leaders converge in New Delhi: sources

25 January 2026

How PopWheels helped a food cart cut generators for e-bike batteries

25 January 2026

Tech CEOs brag and argue about artificial intelligence at Davos

24 January 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

50% off +1 ends | TechCrunch

23 January 2026

Capital One acquires Brex for a steep discount to its valuation, but early believers are laughing all the way to the bank

23 January 2026

Tiger Global and Microsoft will fully exit Walmart-backed PhonePe through its IPO

22 January 2026
Startups

OpenAI chief Sam Altman plans visit to India as AI leaders converge in New Delhi: sources

This startup will send the ashes of 1,000 people into space — affordably — in 2027

The Rippling/Deel corporate espionage scandal may have taken another crazy turn

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.