Willow Pays left customer bill payment database open on the internet
- Organization
- Willow Pays
- Exploit
- Misconfiguration
- Industry
- Financial Services
Willow Pays, a fintech that lets consumers defer bills and repay them over time, left a database reachable on the internet without a password. Security researcher Jeremiah Fowler found it and published his findings on January 15, 2025.
Fowler reported that the database held 241,970 records. Folders were labeled for bills, repayment schedules, mailing lists, account inconsistencies and screenshots. Exposed material included names, email addresses, phone numbers, credit limits, account status, bank account details, partial payment card numbers and images of bills. A single spreadsheet listed 56,864 individuals and classified each as a prospect, an active customer or a blocked account.
American Banker, which reviewed the findings, reported that the exposure did not appear to include Social Security numbers or driver's license numbers, but noted that billing documents combined with contact details would be useful material for targeted phishing.
Fowler sent a responsible disclosure notice and the database was restricted from public access shortly afterwards. He said he received no reply from the company, and American Banker reported that Willow did not respond to its request for comment either.
It was not established how long the data had been reachable, whether anyone else accessed it, or whether the database was managed by Willow Pays directly or by a third party contractor. Fowler said answering those questions would require an internal forensic review.