On December 19, a user named seasalt123 on the Raidforums forum posted what appears to be the user database of Breport.vn, a website created to help users report bugs on Bphone. The database included emails, names, and phone numbers of over 200 users. Since the user base was small, the hacker shared the data for free.
After the post gained attention on December 21, BKAV immediately suspended the Breport website. That same day, BKAV issued an official statement about the incident. They claimed the leak was caused by a “cloud system configuration on Amazon” and said their development team used some real customer data during testing.

“This test system is independently deployed on a cloud server provided by Amazon, serving as an environment for the development team to test the service. The testing process used some real data, and a system configuration error led to the leak. This incident does not affect official services, which are deployed on BKAV’s internal infrastructure,” BKAV’s statement read.
Recently, seasalt123 responded to BKAV’s statement, accusing BKAV of spreading false information to blame others for their own mistakes.
“BKAV’s response to this leak follows their usual tactic: blaming others and denying wrongdoing. So here is my reply.
BKAV advertises their website as an official customer support channel, treating it as a feature to boost product sales. It was never in a ‘testing’ state. If I waited another six months, given the vulnerabilities in their product, I could have gathered enough customer data to sell for profit, not just share for free.
My data did not come from any AWS (Amazon Web Services) misconfiguration, and during data extraction I never interacted with AWS. All issues stem from BKAV’s code, or as they call it, their ‘core technology.’ To add insult to injury, the open-source platform BKAV uses is completely secure, but their own additions exposed all the data.
After this incident, I hope they sincerely apologize to their customers instead of blaming others.”

This isn’t the first time a hacker targeting BKAV has had to clarify false claims made by BKAV. Back in August, “chunxong,” who publicly sold internal BKAV data, was labeled by BKAV as a “former employee with bad intentions.” Chunxong later denied being a BKAV employee and said they live abroad.