Facts

Headero Security Notice

June 12, 2025

Test Database Exposure (Remediated March 2025)

On 24 March 2025 a security researcher responsibly disclosed a misconfigured test database that was reachable from the internet. We patched the vulnerability within hours and launched a full forensic review. Logs confirm a single access—by the researcher—and no data downloads. We are sharing our findings with the Office of the Privacy Commissioner of Canada and any other relevant regulators and will publish a fuller technical report within 24 hours. No passwords, payment data, or government IDs were ever at risk, and no user action is required.

Link to technical report to be found here.

Questions? Email: Info@Headero.com

Stephen Quaderer | CEO and Privacy Officer, ThotExperiment