[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsartxf2jfapk":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":4,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda488251db","flex-booker","FlexBooker Data Breach","flexbooker","flexbooker.com","2021-12-23T00:00:00.000Z","2022-01-06T06:11:10.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:50:57.337Z","Third party breach","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fflexbooker-discloses-data-breach-after-37-million-accounts-traded-on-hacker-forum\u002F",[16],3756794,"known",null,"unknown","Critical",[24,25,26,27,28],"Email addresses","Names","Partial credit card data","Passwords","Phone numbers","\u003Cp>The FlexBooker data breach is a security incident that occurred in December 2021 on the platform that provides online appointment and booking services. The verified scope includes 3,756,794 unique accounts. The leaked primary fields are email addresses, full names, and phone numbers. Additionally, password hashes and partial credit card data were exposed for a smaller group of accounts. The company reported that the incident was associated with a compromised account in its own cloud service environment. Therefore, the risk is serious both for user contact information and for the security of customers of the institutions providing the booking service.\u003C\u002Fp>\u003Cp>FlexBooker registration is particularly important for individuals using the platform for appointments, service reservations, training, non-health consultations, sports, beauty, events, or local business bookings. Since the platform holds customer information on behalf of service providers, the affected person may have registered through a business using this system, even if they do not directly remember the name FlexBooker. It should be noted that partial card data and password hashes are only valid for a limited number of accounts; it should not be assumed that all registrations contain full payment information or passwords.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data verified in this record are email addresses, names, phone numbers, passwords, and partial credit card information. The main risk is the large-scale exposure of contact information combined with the context of reservations. Email and phone information can be used for fake appointment reminders, cancellations, payment updates, deposits, service fees, or customer record verification messages. Name information makes these messages more convincing.\u003C\u002Fp>\u003Cp>Password hashes and partial credit card data were reported not for all users, but for a more limited group of accounts. This distinction is important. Partial card data usually does not mean the full card number or card security code; however, it may help an attacker provide credibility in fake payment update messages by using some card details. Password hashes also increase the risk of account takeover for weak or reused passwords.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The number of verified unique accounts is 3,756,794. The incident date is recorded as December 23, 2021, and it is associated with the FlexBooker online booking platform. Email, name, and phone fields constitute the main scope. Password hashes and partial credit card fields are applicable for a limited number of accounts. The incident has been reported to have originated from a compromised cloud service account; this is an access issue experienced on the service provider side, not on the user side.\u003C\u002Fp>\u003Cp>This record does not include full credit card numbers, card security codes, bank accounts, official identification documents, health records, physical addresses, or verified data fields containing private message content. Users should conduct risk assessment within this limitation. The most realistic risks are fake reservation or payment messages, social engineering via phone calls, password retry attempts, and fraud attempts that exploit partial card information.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The people at highest risk are users who have made an appointment or reservation through businesses using FlexBooker. These users may not directly recognize the platform name, as they may have completed the reservation through a salon, course, consultant, service provider, or local business. People with email and phone information can be targeted with messages about fake appointment changes, service cancellations, prepayments, subscription renewals, or customer profile updates.\u003C\u002Fp>\u003Cp>Password hashes pose an additional risk for users in the limited group affected. If the same password is reused on other accounts, attackers may try this combination on different services. People whose partial card data has been compromised should not panic unnecessarily as if their entire card information has been leaked; however, they should keep banking notifications on and be cautious of fraudulent verification requests related to their card. Individuals calling and speaking as if they have old appointment information should also be verified.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>If you have created an account through FlexBooker or a business using this system, change the password you use for that account. If the same password exists on other accounts, switch to a unique password on those accounts as well. Two-step verification should be enabled on your email account, and security notifications should be kept on. In unexpected messages regarding appointments, payments, deposits, or cancellations, use the business's official communication channel instead of clicking on a link.\u003C\u002Fp>\u003Cp>Users who think that partial card information may have been affected should monitor their card transactions, enable notifications from their banking app, and immediately report to the bank if they see any unfamiliar transactions. Since the full card number or card security code is not confirmed to be compromised, automatically canceling the card may not be necessary in every case; however, it is essential to be cautious against fraudulent payment update messages. The caller knowing your name or previous booking is not proof of trustworthiness.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>The FlexBooker incident shows that booking and appointment platforms can hold a large amount of customer data on behalf of different businesses. Users should use unique passwords for each booking service in the long term, protect their email account strongly, and limit the contact information they share with appointment services. Unused accounts should be closed, and it should be checked whether phone and payment information registered on old booking platforms is being retained.\u003C\u002Fp>\u003Cp>For service providers, cloud account security, access key management, the principle of least privilege, and monitoring of unusual data download activities are critically important. Although reservation systems may appear to be just a calendar service, they store valuable data sets that increase the risk of fraud due to customer names, phone numbers, email addresses, and payment context. Therefore, data minimization, strong access control, and prompt customer notification should be part of a permanent security strategy.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If your email address appears in this record, consider whether you have any appointment or booking history with a business that uses FlexBooker. Change the password you used for the relevant account and update other accounts where the same password is repeated. Instead of following links in appointment cancellation, payment update, service fee, or customer profile verification messages, use the official contact information of the business directly.\u003C\u002Fp>\u003Cp>The main risk in the FlexBooker data breach is the large-scale exposure of email, name, and phone information; password hashes and partial card data apply only to a limited group of accounts. The most appropriate action is to end password reuse, protect email accounts with two-factor authentication, monitor card transactions, and carefully verify reservation-themed fraudulent messages. This approach focuses on the real risks without creating unnecessary panic as if full card data had been leaked.\u003C\u002Fp>","","FlexBooker Data Breach (3.8 Million Reported Records)","FlexBooker Data Breach. 3.8 Million reported records were reported. Reported data: Email addresses, Names, Partial credit card data. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fflexbooker_com.webp",false,{"name":36,"sector":37,"country":38,"website":10,"websiteArchiveUrl":30,"websiteStatus":30,"websiteCheckedAt":20},"FlexBooker","Booking Software","United States"]