Yellow Social Interactive Limited disclosed an incident on April 27, 2022, where a bug bounty hunter exploited an API vulnerability to access a supporting database. The individual accessed names, driver's license numbers, and in limited cases, passport numbers. The company fixed the vulnerability, and the individual destroyed the copied data. No evidence of misuse was found. Credit monitoring was offered to affected customers.