• About
  • Advertise
  • Careers
  • Contact
Friday, March 31, 2023
No Result
View All Result
NEWSLETTER
Cyber360 News
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
No Result
View All Result
Cyber360 News
No Result
View All Result
Home Security

The 400GB worth of data was exposed due to a misconfigured Elasticsearch database.

by Cyber360 News
January 12, 2021
in Security
0
The 400GB worth of data was exposed due to a misconfigured Elasticsearch database.
0
SHARES
35
VIEWS
Share on FacebookShare on Twitter

The 400GB worth of data was exposed due to a misconfigured Elasticsearch database.

Safety Detectives’ cybersecurity reported that a Chinese startup called Socialarks became the victim of a massive data breach. According to Safety Detectives team head Anurag Sen, around 400 GB worth of private data was exposed in the breach. 

Socialarks Data Breach

The breach occurred due to an unsecured ElasticSearch database, which contained personally identifiable information of approximately 214 million social media users from across the globe.

See: Personal data of millions of Americans exposed from PC in China

Impacted users include many high-profile celebrities, food bloggers, and social media influencers. Most of the users were associated with Facebook, Instagram, and LinkedIn.

Affected Server was Segmented

Tencent, a Chinese multinational technology conglomerate holding company hosted the vulnerable server. It was segmented into indices, probably to store data obtained from different social media sources. However, the team discovered records from only three major aforementioned social media platforms.

Data ‘Scraped’ due to Poor Password Protection.

The ElasticSearch database wasn’t secured with a strong password or encryption. Lack of protection on a server means that anyone possessing its IP address can access the database. The same happened in the case of Socialarks. Resultantly, the private data of millions of users got exposed.

Exposed Data Includes…..

According to Safety Detectives’ blog post, the database contained “a “huge trove” of sensitive personal information to the tune of 408GB and more than 318 million records in total.”

See: “BreedReady” database of 1.8m Chinese women surfaced online

The exposed database contained profiles of over 11,651, 162 Instagram users, 66,117, 839 LinkedIn users, and 81,551,567 Facebook users. Around 55,300,000 Facebook user profiles were deleted within a few hours after Safety Detectives’ team discovered the vulnerable server.

Instagram users

Instagram users’ data included profile pictures, biographies, followers count, biographies, location settings, and contact data, such as email and phone numbers.

Chinese firm leaked 200m Facebook, Instagram, LinkedIn users' data

Leaked Instagram data

Facebook users

Leaked Facebook data included 40 million phone numbers mostly from pages, and 32 million email addresses, as well as full name, About text, email addresses, country, phone numbers, Messenger ID, Like, Follow, and Rating count, Facebook and Website link with profile pictures, and profile description.

LinkedIn users

LinkedIn’s exposed data included full name, email IDs, user tags, job profile, seniority level and job title, LinkedIn profile link, domain name, user tags, and connected social media accounts information such as Twitter.

Not for the first time

This however is not the first time when scraped data of millions of users was leaked online. In December 2018, an unprotected Elasticsearch server leaked names and phone numbers of 267 million Facebook users.

In another incident, an unprotected database leaked phone numbers of 419 million Facebook users including 133 million records from the US, 18 million in the UK, and 50 million in Vietnam.

Did you enjoy reading this article? Don’t forget to like our page on Facebook and follow us on Twitter! 

Cyber360 News

Cyber360 News

Next Post
pakistan android malware

Warning — 5 New Trojanized Android Apps Spying On Users In Pakistan

Recent Posts

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

October 6, 2021
Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

October 1, 2021
Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

October 1, 2021

Whats New in Kali Linux?

September 14, 2021

Kali Linux 2019.3 Release (CloudFlare, Kali-status, metapackages, Helper-Scripts & LXD)

September 14, 2021

Kali Linux 2021.3 Release (OpenSSL, Kali-Tools, Kali Live VM Support, Kali NetHunter Smartwatch)

September 14, 2021

Kali Linux 2018.4 Release

September 14, 2021

Kali Linux 1.0.5 and Software Defined Radio

September 14, 2021

Kali Tools Website Launched, 1.0.9 Release

September 14, 2021

Kali Linux Dojo at Black Hat Vegas 2016

September 14, 2021

Category

Site Links

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

About Us

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

© 2019 Cyber360 News - Powered by WebSensePro

No Result
View All Result
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us

© 2019 Cyber360 News - Powered by WebSensePro

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In