Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Photobooth Supply Co

Photobooth Supply Co Vendor Cyber Rating & Cyber Score

photoboothsupplyco.com

Photobooth Supply Co. is reinventing the idea of photobooths with open spaces, marketing tools, and elegant aesthetics that allow you to thrive. You might be a business looking to expand your marketing through data collection and social outreach. You might be an individual looking for a chance to establish a brand and chase the American dream of entrepreneurship. Photobooth Supply Co. can help you do it all with hardware and solutions The iconic Salsa photobooth brings a suite of tools for existing businesses. If you’re looking to expand your marketing efforts, you’ll be able to deploy a booth at a trade show and gather the email addresses of hundreds of smiling guests. Rather than being stuck with a business email or attempting to cold


PSC A.I CyberSecurity Scoring

PSC
Company Information
Website:http://www.photoboothsupplyco.com
Employees number:57
Number of followers:5,874
NAICS:54192
Industry Type:Photography
Homepage:photoboothsupplyco.com
PSC Risk Score (AI oriented)
Between 650 and 699
logo
PSCPhotography
Updated:
04/04/2026
678/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
PSC Global Score (TPRM)
xxxx
logo
PSCPhotography
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

PSC
PSCWeak
Current Score
678B (WEAK)
01000
1 incidents
-78 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
682Before Incident
JUNE 2026
682Before Incident
MAY 2026
680Before Incident
APRIL 2026
679Before Incident
MARCH 2026
677Before Incident
FEBRUARY 2026
676Before Incident
JANUARY 2026
673Before Incident
DECEMBER 2025
750Before Incident
Breach
12 Dec 2025PSC
Photobooth Supply Co: Photo Booth Website Bug Exposed Thousands of Users’ Photos

Photo Booth Maker's Website Exposes Thousands of Images and Videos Due to Insecure Access Control

672After Incident
CRITICAL-78
PHO1765565027
Photo Booth Vendor’s Security Flaw Exposed Thousands of Private Images and Videos A security researcher, known as Zeacer, uncovered a critical vulnerability in a photo booth vendor’s website that left thousands of images and videos—including intimate moments and drunken party snapshots—publicly accessible without authentication. The flaw stemmed from insecure direct object references, where media files were served via predictable URLs, allowing attackers to enumerate and download entire galleries using simple scripts. The company had recently reduced file retention from two to three weeks to just 24 hours, limiting the volume of exposed content at any given time. However, this change did not prevent attackers from scraping daily uploads. At one point, over 1,000 images from a Melbourne-based photo booth service were visible, highlighting the scale of the risk. The incident underscores the dangers of broken access control, ranked by OWASP as the top web application security risk. Event photo booths often capture highly personal moments—weddings, corporate events, and private gatherings—where sensitive details like home addresses, children’s faces, or organizational affiliations may be inadvertently exposed. Even with short retention periods, scraped data remains permanently accessible to attackers. The financial and reputational consequences of such breaches can be severe. IBM’s Cost of a Data Breach Report estimates global breach costs in the multi-millions, while consumer-facing brands built on "shareable moments" face lasting reputational harm. The flaw likely resulted from common shortcuts in event-tech development, such as public object storage, client-side-only checks, and predictable URL patterns—issues that could have been mitigated with server-side protections like signed URLs, randomized IDs, and rate limiting. Regulatory risks also loom large. Under Australia’s privacy laws, businesses must proactively secure data and disclose breaches, while GDPR in the EU and UK imposes fines of up to 4% of global turnover for serious violations. The vendor’s role—as either a data processor or controller—determines specific compliance obligations, but minimizing retention and enforcing strict access controls are baseline requirements. Customers who used affected photo booths in the past month should assume potential exposure and request gallery deletions from vendors. Event organizers are advised to demand transparency from suppliers, including details on file retention, link security, and third-party audits like SOC 2 or ISO 27001. Contracts should explicitly address data processing terms and breach notification responsibilities. The incident reflects a broader trend in event tech, where rapid growth often outpaces security hardening. As web app vulnerabilities remain a leading cause of data breaches, basic safeguards—such as private-by-default storage and continuous logging—can prevent such exposures without requiring complex solutions. While the vendor’s retention reduction limits immediate risk, it does not replace proper authentication and authorization, leaving galleries vulnerable to persistent scraping.
INCIDENT DETAILS -
TYPE
Data Exposure
IMPACT
Data Compromised: Thousands of images and videos, including personal and sensitive momentsSystems Affected: Photo booth website media storage and serving endpointBrand Reputation Impact: Significant reputational damage, especially for a consumer-facing brand predicated on 'shareable moments'Legal Liabilities: Potential regulatory fines under GDPR, Australian Privacy Act, and other privacy lawsIdentity Theft Risk: Exposure of personally identifiable information (e.g., home addresses, affiliations)
DATA BREACH
ImagesVideosNumber Of Records Exposed: Over 1,000 images at one stage (prior to retention change)Sensitivity Of Data: High (personal moments, identifiable individuals, potential PII)Data Exfiltration: Possible via scraping scriptsImagesVideosPersonally Identifiable Information: Yes (e.g., home addresses, affiliations, children)
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident
SEPTEMBER 2025
750Before Incident
AUGUST 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for PSC ?
?
What was PSC's A.I Rankiteo Cyber Score in June 2026 ?
?
What was PSC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was PSC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was PSC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was PSC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was PSC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was PSC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was PSC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was PSC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was PSC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was PSC's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on PSC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with PSC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view PSC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?