Massive data leak at Klarna – extent now known
There seems to have been a massive data leak at the payment service provider Klarna. Users report that they have insights into other accounts.
Around 90,000 users of the Swedish payment service provider Klarna are affected by a massive data leak. As several users report on Twitter, yesterday, Thursday, they were able to access details of external accounts after logging in, including names, photos, but also the payment history as well as bank details and addresses.
Each time I tried to log in to my @Klarna account this morning, I’m on someone else’s account? Does this also mean someone else might currently be my on account? What the hell is going on? !! @AskKlarna pic.twitter.com/hqimF2zx7S
– esra efe laborde (@esraefe) May 27, 2021
Contents
Klarna reacts cautiously
Klarna itself reacted rather cautiously to the reports at first – we apologize for the “inconvenience” that should have been caused by “system malfunctions”. Logging into the app was no longer possible in the meantime.
Twitter users were irritated by Klarna’s reaction – being able to view the contact and transaction data of strangers is more than just an “inconvenience”, they say, for example. One user also noted that two of the displayed foreign accounts have identical data and asked if it could be a test account.
In the meantime Klarna has confirmed the incident and stated that a “human error“Was the cause. The data could be viewed by other users in the app for about half an hour – however, card and bank data were only visible in masked form. Internally, they are now working on processing the data leak and informing the Klarna customers concerned. According to Klarna, the responsible authorities have also already been informed.