The company recently misconfigured one of its Elasticsearch servers, leaving the sensitive customer information stored on it accessible to the public since August 18th. If a malicious group or individual accessed the information, they could use the included emails to carry out phishing attempts.
They're still using Amazon Web Services (AWS) aren't they? I've lost count as to how many tech companies using AWS have left their area unsecured on the web letting "Joe Anyhacker" an easy way to access customer information.
This hardware company requires an online account just to change settings. Then, the information is compromised. I hope they file for bankruptcy.