Articles

Porn Blocking App Exposed User Data Online
Data Breach Database

Porn Blocking App Exposed User Data Online

Porn Blocking App called BlockerX Suffered a data leak that may have potentially put vulnerable users at risk. On August […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Office Depot Exposed Customer Records Online
Data Breach

Office Depot Exposed Customer Records Online

On March 3rd, 2021 I discovered a non-password protected Elasticsearch database that contained just under a million records. The exposed […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Microfinance Bank’s Fintech App Leaks Customer Accounts Online
Data Breach Database Fintech

Microfinance Bank’s Fintech App Leaks Customer Accounts Online

On March 3rd I discovered a non-password protected database that contained 271k records. It was clear from the start that […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Comcast Exposed Development Database Online
Data Breach Database

Comcast Exposed Development Database Online

On December 1st, 2020 I discovered a non-password protected database that contained over 1.5 billion records. Inside the dataset were […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Smart Home Device Exposed 1 Billion Records Online Including User Data
Data Breach Database

Smart Home Device Exposed 1 Billion Records Online Including User Data

On Jan 19th I discovered an exposed dataset that contained a massive 1.2 billion records and 1.1 million “Logged in […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Fotor Photo Editing App Leaked 13 Million Users’ Info Online
Data Breach

Fotor Photo Editing App Leaked 13 Million Users’ Info Online

On October 15th I discovered a non-password protected database that contained a large number of internal records. There was a […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Luxury Real Estate Firm Exposed Owner and Agent Data Online For Months, Later Wiped Out By Malicious Meow Bot
Data Breach Database

Luxury Real Estate Firm Exposed Owner and Agent Data Online For Months, Later Wiped Out By Malicious Meow Bot

On June 17th I discovered a dataset that contained a massive amount of records that were clearly related to a […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Hosting Provider Exposed 63 Million Records and User Passwords
Data Breach Database

Hosting Provider Exposed 63 Million Records and User Passwords

On October 5th I discovered a non-password protected database that contained a large amount of monitoring and system logs. There […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Property Management Company Exposed 1.2 Million Records Online
Data Breach

Property Management Company Exposed 1.2 Million Records Online

In June 2020, I discovered a large amount of records that contained detailed information on property renters, visitors, commercials leases, […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

AI Company Exposed 2.5 Million Records Including Medical Data of Auto Accident Victims Online
Data Breach

AI Company Exposed 2.5 Million Records Including Medical Data of Auto Accident Victims Online

  In the ever-changing world of cyber security there are few types of records that are as valuable or sensitive […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Home Loan Provider Exposed 695k Records Online
Data Breach Database

Home Loan Provider Exposed 695k Records Online

Recently I discovered a large collection of what appeared to be records related to home loans. Upon further research the […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Largest US Bubble Tea Supplier Exposed Data Online
Data Breach Database

Largest US Bubble Tea Supplier Exposed Data Online

On April 28th I discovered a dataset that contained what appeared to be customer information, payment references and was labeled […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Personal Details and IDs of Millions of Indian Families Exposed As A Result of Security Incident
Data Breach Elasticsearch

Personal Details and IDs of Millions of Indian Families Exposed As A Result of Security Incident

On May 23rd, another Elasticsearch misconfiguration incident has led to the exposure of the personal details and Aadhar number for  […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director

PADI Certified Divers Records Exposed in a Misconfiguration Incident
Data Breach Elasticsearch

PADI Certified Divers Records Exposed in a Misconfiguration Incident

On May 6th I have identified an open and unprotected Elasticsearch server that appeared to contain registration details for US-based […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director

Energy Company in Poland Exposed Data of its Customers
Elasticsearch

Energy Company in Poland Exposed Data of its Customers

On April 16th I have discovered an unprotected and publicly indexed Elasticsearch cluster that contained 3,376,912 records with personally identifiable […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director

SMS Spam Operation Rebrands, Continues to Leak Customer Information
Data Security Education

SMS Spam Operation Rebrands, Continues to Leak Customer Information

Earlier this year, I discovered that SMS marketing firm, Rocket Text (rocket-text.com), failed to secure its Mongo database exposing just […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director

A UK-based Security Company Seemed To Have Inadvertently Exposed Its ‘Leaks Database’ with 5B+ Records
Data Breach Elasticsearch

A UK-based Security Company Seemed To Have Inadvertently Exposed Its ‘Leaks Database’ with 5B+ Records

On March 16th I have found an unprotected and thus publicly available Elasticsearch instance which appeared to be managed by […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director

Free Wifi User Data Exposed in Multiple UK Train Stations
Data Breach Database

Free Wifi User Data Exposed in Multiple UK Train Stations

On February 14th I discovered a non-password protected database that contained a massive amount of records totaling 146 million. Upon […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

FairBridge Inn & Suites Exposed Customer Booking Platform
Data Breach Database

FairBridge Inn & Suites Exposed Customer Booking Platform

Booking a hotel online is now so common that we consumers never give it a second thought when traveling. We […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

US non-profit for international study exposes private documents of thousands of students: report
Data Breach Database

US non-profit for international study exposes private documents of thousands of students: report

The Institute of International Education (IIE), a US nonprofit that focuses on foreign exchange study and scholarship, exposed a database […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director