
The National Safety Council (NSC), a non-profit organization focused on workplace and driving safety training in the United States, has inadvertently exposed the sensitive credentials of thousands of its members, including prestigious entities like NASA, Tesla, the Department of Justice (DoJ), Verizon, and many more.
The NSC, boasting a membership of nearly 55,000 individuals spanning diverse industries, serves as a hub for online resources and training materials. The organization’s digital platform fell victim to a critical vulnerability that went undetected for five months.
Cybersecurity research team Cybernews unearthed this security lapse when they stumbled upon publicly accessible web directories on the NSC website, unwittingly exposing thousands of credentials.
Among the extensive list of compromised accounts were employees representing over 2,000 companies and government entities, representing a broad spectrum of industries:
These organizations seemingly held accounts on the NSC platform to access training materials and participate in NSC-sponsored events.
The consequences of this breach extended beyond the NSC itself, as the exposed credentials could have been exploited in various malicious ways. Threats such as credential stuffing attacks targeting internet-connected tools like VPN portals, HR management platforms, or corporate email systems were among the primary concerns. The leaked credentials might have also served as a gateway for cybercriminals to infiltrate corporate networks, potentially deploying ransomware, pilfering or sabotaging internal documents, or compromising user data.
Upon discovering this vulnerability on March 7, Cybernews promptly notified the NSC, which took immediate corrective action to rectify the issue. The security lapse was traced to a subdomain on the NSC website, presumably employed for developmental purposes, inadvertently left open to public access. This subdomain exposed critical web server files and, shockingly, a backup of a database housing user emails and hashed passwords. The data had been accessible to the public for five months, initially indexed by IoT search engines on January 31, 2023.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543