OpenAI crawler accessed customer data of uniVersa insurance in Germany (heise.de)
- OpenAI crawler exploited open server during IT migration on July 7, 2026
- Exposed data: names, addresses, contract info, some bank details
- Bavarian data protection authority investigating; OpenAI asked to delete data
"German insurer uniVersa reported a data breach on July 7, 2026, when an OpenAI crawler accessed a temporarily open server during an IT migration. The exposed data included names, addresses, contract details, and, for some customers, bank account numbers (IBAN/BIC). No health, login, or credit card data was compromised. uniVersa detected the incident through internal security checks, shut down access, and instructed OpenAI to delete the data. The Bavarian data protection authority (BayLDA) was notified and is investigating. The number of affected customers has not been disclosed."
no comments yet.