Hipshipper left 14.3 million shipping records exposed in open cloud bucket

Organization
Hipshipper
Exploit
Misconfiguration
Industry
Transportation & Logistics

Hipshipper, an international shipping platform used by sellers on eBay, Amazon and Shopify, left a cloud storage bucket open to the internet, exposing more than 14.3 million shipping records. Researchers at Cybernews found the unprotected Amazon Web Services bucket on December 2, 2024, at the height of the holiday shipping season, and notified the company a week later on December 9. The bucket was not closed until January 8, 2025.

The exposed files were mostly shipping labels and customs declaration forms. Between them they carried buyers' full names, home addresses and phone numbers, together with order details, mailing dates and parcel information. Some accounts of the leak also described invoices and email addresses among the records.

Hipshipper secured the storage after being contacted and the data was no longer publicly reachable. The company did not issue a public statement about the exposure or say whether it had notified the people whose details were involved, and there was no confirmation that anyone other than the researchers had retrieved the files.

Reporting on the leak in February 2025 focused on the fraud risk created by detailed shipping records, which allow a caller or emailer to reference a genuine order when approaching a buyer. Hipshipper operates in more than 150 countries, so the exposed records covered customers of many independent sellers rather than a single retailer.

Sources