
The OWASP Foundation, a nonprofit organization dedicated to enhancing software security globally, has warned its members about a recent data breach. Discovered in late February 2024, the breach stemmed from a misconfiguration of an outdated Wiki server operated by OWASP. The breach potentially affected individuals who were organization members between 2006 and 2014.
The breach primarily exposed resumes submitted by members during the specified period, comprising personal details such as names, email addresses, phone numbers, and physical addresses. OWASP disclosed that these resumes were collected as part of an earlier membership process, which required applicants to demonstrate ties to the OWASP community. However, the organization clarified that it no longer mandates the submission of resumes for membership.
Andrew van der Stock, Executive Director of the OWASP Foundation, stated that approximately 1,000 resumes were identified on the server. He emphasized that while there is no evidence of external access, the exact extent of unauthorized access remains unclear due to limited logs and the server’s archival by the Wayback Machine in 2023.
In response to the breach, OWASP has taken several measures to mitigate further risk, including disabling directory browsing, conducting a thorough review of the web server and MediaWiki configurations, removing the exposed resumes from the site entirely, and purging the CloudFlare cache. Additionally, the organization has requested that the information be removed from the Web Archive.
The Foundation acknowledged the challenge of notifying affected individuals, many of whom are no longer affiliated with OWASP and may have outdated contact information. While OWASP assured members that their information has been removed from the internet, it advised caution if any personal details remain current. OWASP recommends vigilance against potential phishing attempts or scam communications.
OWASP expressed regret for the breach and pledged to enhance data retention policies and implement additional security measures to prevent similar incidents. The organization reaffirmed its commitment to safeguarding member information and maintaining the integrity of its cybersecurity initiatives.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543