Rainwalk Pet Insurance, a company based in South Carolina, suffered a significant data exposure incident after a misconfigured and unsecured database was discovered online. The database, which was not protected by a password or encryption, contained approximately 158 GB of sensitive data, including over 85,000 files. The exposed information included customers' names, phone numbers, physical and email addresses, and partial credit card numbers. In addition to customer data, the database also contained detailed information about their pets, such as names, breeds, microchip numbers, and medical histories. The breach was discovered by cybersecurity researcher Jeremiah Fowler, who reported the issue to Website Planet for verification. Fowler notified Rainwalk of the exposure, but the company reportedly took almost a month to secure the database after being alerted. The delay in response increased the risk that malicious actors could have accessed the data during the exposure window. The leaked data poses significant privacy and financial threats to affected customers, as threat actors could potentially use the information to make fraudulent insurance claims, conduct scams related to pet microchip expiration, or create fake invoices. There is also a risk that attackers could intercept refunds or payments intended for customers, especially through platforms like Venmo. The incident highlights the lack of specific privacy regulations for pet data, which, when combined with personal identifying information, becomes a lucrative target for cybercriminals. Screenshots of the exposed data, including claim approvals and veterinary invoices, were shared by the researcher to demonstrate the severity of the leak. The breach underscores the need for pet insurance companies to implement stronger encryption and access controls to protect sensitive customer and pet information. The full extent of the exposure remains unclear, as it is not known how long the database was accessible or whether unauthorized parties accessed the data. The incident serves as a warning to other organizations handling similar data to prioritize security and respond promptly to vulnerability disclosures. Rainwalk's delayed response to the notification has drawn criticism from cybersecurity experts. The exposure of both financial and personal data increases the risk of identity theft and financial fraud for affected customers. The case also raises questions about industry standards for data protection in the pet insurance sector. Overall, the incident demonstrates the critical importance of securing databases and responding swiftly to security reports to mitigate potential harm.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
A misconfiguration exposed approximately 158 GB of data belonging to Rainwalk Pet Insurance, affecting U.S. customer and pet information. The available references describe the incident as an inadvertent leak rather than a malicious breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.