Practice by Numbers remediated an access-control flaw in its dental patient portal after a patient discovered that changing sequential document numbers in the URL let any authenticated user view other patients’ files. The exposed records included private health information, medical histories, personal details, and photo identification. After difficulties reporting the issue through the company’s broken or missing security contact channels, TechCrunch alerted the vendor, which took the portal offline, fixed the bug, and restored service. Practice by Numbers said server logs indicate fewer than 10 patients were affected, that it found no evidence of earlier exploitation, and that it is notifying the impacted dental practice.
In a separate privacy exposure, researcher Jeremiah Fowler found a publicly accessible, passwordless database containing 86,859 private images, screenshots, and messages linked to a high-profile European celebrity and several social media influencers. The leaked material included chats from WhatsApp, Facebook, TikTok, and Instagram, along with phone numbers, email addresses, invoices, receipts, and identity-related documents. Fowler said the screenshots appeared to have been captured from victims’ phones, pointing to suspected stalkerware activity before the data was exposed through a misconfigured server, and he notified affected individuals and law enforcement while withholding names to limit further harm.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Following the stalkerware-linked data discovery, Fowler said he contacted affected people using leaked phone numbers and notified law enforcement. He withheld names publicly to protect the privacy of the victims.
Jeremiah Fowler discovered a publicly accessible, passwordless database containing 86,859 private images, screenshots, messages, and personal documents linked to a prominent European celebrity and several social media influencers. His analysis suggested the material had been collected from victims’ phones using stalkerware before being exposed via a misconfigured server.
Practice by Numbers brought its patient portal back online after fixing the access-control flaw. The company later said server logs indicated fewer than 10 patients were affected and that it found no evidence of prior exploitation.
After Cox was unable to find an effective security reporting channel, TechCrunch alerted Practice by Numbers to the vulnerability. The company then took the patient portal offline in response.
Dental patient Joseph R. Cox found that changing a document number in the Practice by Numbers patient portal URL exposed other patients’ records to any authenticated user. The document identifiers appeared sequential and guessable, allowing access to personal information, medical histories, and photo identification.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehackread.com
Open sourcetechcrunch.com
Open sourceexpressvpn.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.