BlackRock leaks personal data of thousands of clients
Fears over the data, which could have been available for more than a month, being used in future phishing campaigns


The investment management firm BlackRock accidentally made the personal details of thousands of its clients publicly-available for more than a month, including their names and email addresses.
The personal data leak manifested as links to three separate spreadsheet documents via the firm's website, each containing the names, email addresses and assets in the iShares exchange-traded funds (ETF) investment portfolio scheme.
The spreadsheet links were dated to 5 December 2018, according to Bloomberg reporters who saw the documents, and were taken down on Friday after BlackRock was notified of the leak. It is not confirmed whether the data was publicly-available throughout this period.
The documents also categorised clients by their status, with some labelled "dabblers" and "power users", while another column denoted their club level status such as "directors club" or "patriots club".
IT Pro approached BlackRock for comment but did not get a response at the time of writing. A spokesperson told Bloomberg the firm is conducting "a full review of the matter".
"The inadvertent and temporary posting of the information relates to two distribution partners serving independent advisers and does not include any of their underlying client information," the spokesperson continued.
The financial sector, particularly firms such as BlackRock and JP Morgan Chase, have proved a lucrative target for cyber criminals. The latter, for example, was targeted in a massive attack in 2014, with the details of 76 million US households and 7 million SMBs stolen.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Malwarebytes' lead malware intelligence analyst Chris Boyd told IT Pro at the time that such data could serve as a "spammer's goldmine" and could be used to conduct a series of future attacks on victims.
"The data... could be used over a long period of time to drip-feed potential victims with phishing, cold calling or targeted malware attacks via email," he explained.
There are concerns the BlackRock leak discovered this weekend may similarly put those whose details were exposed at risk of future phishing attacks by a host of groups targeting businesses across all sectors.
The Nigerian-based cyber gang known as 'London Blue' for example was in December found to have infiltrated the UK as part of a wider campaign to target chief financial officers (CFOs) across a range of businesses.
They generated a list of more than 50,000 high profile targets during a five-month period this year for purposes of future business email compromise (BEC) phishing campaigns.

Keumars Afifi-Sabet is a writer and editor that specialises in public sector, cyber security, and cloud computing. He first joined ITPro as a staff writer in April 2018 and eventually became its Features Editor. Although a regular contributor to other tech sites in the past, these days you will find Keumars on LiveScience, where he runs its Technology section.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Google pays largest-ever bug bounty worth £500,000
News The company remained tight-lipped over the exploit itself, but speculation is possible given its publicly available rewards breakdown
By Connor Jones Published
-
OpenSSL 3.0 vulnerability: Patch released for security scare
News The severity has been downgraded from 'critical' to 'high' and comparisons to Heartbleed have been quashed
By Connor Jones Published
-
Hacker steals $566 million from Binance Bridge using proof-forgery exploit
News An exploit discovered in the exchange platform's proof verifier let the hacker take 2m BNB without raising alarm bells
By Rory Bathgate Published
-
CISA issues fresh orders to polish security vulnerability detection in federal agencies
News The move marks the latest step in the cyber security authority's ongoing ambition to minimise the government's exposure to attacks
By Praharsha Anand Published
-
Mozilla patches high-severity security flaws in new ‘speedy’ Firefox release
News Numerous vulnerabilities across Mozilla's products could potentially lead to code execution and system takeover
By Connor Jones Published
-
WordPress plugin vulnerability leaves sites open to total takeover
News Customers on WordFence's paid tiers will get protection from the WPGate exploit right away, but those on the free-tier face a 30-day delay
By Rory Bathgate Published
-
Numerous HP business laptops and desktops vulnerable to publicly disclosed security bugs
News Researchers revealed the details of the six vulnerabilities at Black Hat in August but many laptops, desktops, and workstations remain vulnerable
By Connor Jones Published
-
HP patches high-severity security flaw in its own support tool
News The application that's installed in every HP desktop and notebook was allowing hackers to elevate privileges through a DLL hijacking vulnerability
By Connor Jones Published