Siemens Metaverse breach: Millions of sensitive corporate data exposed. Learn how hackers could exploit this vulnerability and how to protect your business.

Continue reading
Siemens Metaverse, a virtual space designed to create digital ‘twins’ of factories and offices, was found leaking sensitive information that included office plans, IoT devices, and ComfyApp user credentials. The data leak could have disastrous effects on the company and other corporations using its services. The Siemens-owned app, ComfyApp, aids with workspace management and requires sensitive data like floor plans, IoT devices, employee calendars, and interior pictures. Cybernews discovered that Siemens leaked four sets of WordPress users, ComfyApp credentials, endpoints, and three sets of backend and authentication endpoint URLs on different endpoints of the affected systems. Siemens claimed the issue was not critical, and it has been mitigated, but Cybernews researchers urged caution, saying that hackers could exfiltrate a treasure trove of sensitive data. In this article, we will explore the data leak and potential security threats and discuss how the metaverse is causing privacy issues and criminal concerns.
On March 1, the Cybernews research team discovered an environment file hosted on a metaverse.siemens.com domain. It contained ComfyApp credentials and endpoints. The WordPress sets exposed only user names and avatar pictures, but all four Siemens WordPress-based subdomains were vulnerable to a flaw that WordPress fixed in 2017, raising concerns of severe vulnerabilities on these sites. Backend and authentication endpoint URLs used to verify users before giving them access could lead to attackers testing them for vulnerabilities and exploiting them. The most alarming discovery was exposed office management platform ComfyApp user credentials. ComfyApp is a Siemens-owned app that aids workspace management, and it is hungry for sensitive data such as floor plans, IoT devices, employee calendars, and interior pictures.

*ComfyApp credentials and endpoints*
If attackers had gained access to the exposed data, it could have had devastating consequences, including ransomware attacks. Siemens' customers include multibillion-dollar companies handling extremely sensitive data, which would be valuable to attackers. After snooping around the digital office, attackers could show up in the physical office as if they have worked there for years, familiar with all the spaces and office devices such as smart air conditioners. Attackers would be more likely to plug in an infected USB drive, which could eventually lead to ransomware. Since the metaverse is built so that it should have up-to-date factory data, attackers could even extract some trade secrets like manufacturing techniques. The metaverse represents an unprecedented digital and physical attack surface, which poses new challenges to cybersecurity.
The metaverse concept has excited companies and users, presenting exciting opportunities and creating new digital frontiers. However, it also presents unique challenges, including privacy and criminal concerns. The metaverse is a new Wild West of privacy issues and criminal concerns, with reports of harassment, bullying, hate speech, and rape. Cyberattacks like phishing are likely harder to prevent since the attack vector expands to your brain. Trend Micro researchers even predicted the rise of the darkverse - a sort of dark web in the metaverse where threat actors would thrive out of law enforcement's reach. There is also a lack of clear legal frameworks on how to manage criminal acts in the metaverse, leaving users with no place to file their complaints.

A publicly accessible registration portal, a misconfigured Entra tenant, and no server-side authorization checks. That was enough to reach the systems controlling live World Cup streams