Groupon Exposes Customer Emails In Google Results
It looks like this is some kind of Google Analytics tracking flaw for a Groupon marketing campaign, and the emails are from people who have referred deals to others through Groupon’s insecure links. It seems as though when someone clicks on a deal link in a Groupon email and posts it anywhere else online, Google has indexed this sensitive information.
Groupon, which launched its service allowing merchants to create their own deals yesterday, might be suffering some data issues along the lines of what happened to purchase sharing startup Blippy when it exposed credit card numbers through Google search results in April.
I have gotten in touch with Google, Groupon and a few of the people with exposed email addresses about the flaw and will update this post when I hear back.
Update: Groupon Director of Engineering Shinji Kuwayama responds to the issue in the comments section of this post.
“We can see that a number of email addresses — less than 80 — have gotten out into Google’s index, due to having been pasted into publicly-crawlable pages around the Web.
Fortunately, only a tiny fraction of our subscribers are affected, and we’re working directly with Google right now to get our subscribers 100% excluded from both Google’s index and Google’s cache.”