Articles

Estee Lauder Exposed 440 Million Records Online
Database

Estee Lauder Exposed 440 Million Records Online

Cosmetic Company Estée Lauder Exposed Online Database containing millions of records and references to internal doccuments and sales.
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Pabbly Email Marketing Exposes 51.2 Million Records Online
Data Breach Database

Pabbly Email Marketing Exposes 51.2 Million Records Online

Pabby Email Marketing Exposed Customer Emails Online. Security Researchers Find Database of Pabbly's Customers and Their Email Marketing Lists
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Online Eyewear Websites Expose Data of 186k Customers
Data Breach Database

Online Eyewear Websites Expose Data of 186k Customers

Online eyeglasses VoogueMe and Zeelool expose 186k customer sales records online in large data breach. VoogueMe and Zeelool Data Leak
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Honda Exposes Vehicle Owner Records on the Web
Data Breach Database Elasticsearch

Honda Exposes Vehicle Owner Records on the Web

On December 11th, 2019, I have identified an open and unprotected Elasticsearch cluster with 976 millions of records which appeared […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director

Prank Call Service PrankDial Exposed 138 Million Records Online
Data Breach Database Elasticsearch

Prank Call Service PrankDial Exposed 138 Million Records Online

PrankDial exposed millions of log records online that exposed user emails and IP addresses. Read more about the PrankDial data leak
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

2.59 Million Credit Card Transactions Exposed –
Data Breach Database Elasticsearch

2.59 Million Credit Card Transactions Exposed –

Nigerian PayPad Exposed 2.59 Million Card Transactions Online. This was the 2nd data exposure this year for Electronic Settlements Limited
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Religious Website and Software Provider Leaks Customer and Credit Card Data for Many Months
Data Breach Elasticsearch

Religious Website and Software Provider Leaks Customer and Credit Card Data for Many Months

Clover Sites Inc exposed thousands of clients for months and leaked credit card data in the process. Parent company Ministry Brands LLC closed access after months long data leak.
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Whirlpool Exposed Database with Home Appliances Scan Results
Data Breach

Whirlpool Exposed Database with Home Appliances Scan Results

On October 1st, I have found a rather unusual web interface of Heartbeat monitoring service. The open and publicly available […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director

When Test Data is Not Test Data
Data Breach Data Security Education

When Test Data is Not Test Data

There is a growing trend among organizations and companies to simply deny that live production data is real. As a […]
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Large Italian Online Shop Exposed Customers Details
Data Breach Elasticsearch

Large Italian Online Shop Exposed Customers Details

On Sept 4th I have identified an open and unprotected Elasticsearch cluster containing sensitive details of customers of Calcioshop.it, popular […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director

Mexican Online Bookstore Exposed Data – Again
Data Breach

Mexican Online Bookstore Exposed Data – Again

On September 9th, I have discovered three (3) open and unprotected MongoDB instances which appeared to be part of Librería Porrúa, […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director

Investment Research Company Exposed Subscribers, Credit Card Data, and Evidence of Ransomware
Data Breach Database Elasticsearch

Investment Research Company Exposed Subscribers, Credit Card Data, and Evidence of Ransomware

Wyatt Research exposed customer data for months and security researchers discovered evidence of Ransomware in the database.
Mark Daniels

Mark Daniels

Security Researcher & Data Analyst

Mattress Company Exposes 387k Customer Records Online
Data Breach Database Elasticsearch

Mattress Company Exposes 387k Customer Records Online

Security Discovery researcher Jeremiah Fowler discovered a database with 387,000 customer records that belongs to the Verlo Mattress Company
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Banking Trojan Database Exposed – Millions of Users At Risk
Database

Banking Trojan Database Exposed – Millions of Users At Risk

On July 5th I discovered two (!) open and publicly accessible MongoDB instances which appeared to be part of the […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director

Bold.com Exposed Its Internal Infrastructure
Data Breach Data Security Education Elasticsearch

Bold.com Exposed Its Internal Infrastructure

Bold.com, company behind popular solutions to help jobseekers find jobs, and help businesses find candidates – LiveCareer, Resume-Now, my Perfect Resume, Mighty […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director

Auto Dealer Leads Network Exposed 198 Million Records Online
Data Breach Database Elasticsearch

Auto Dealer Leads Network Exposed 198 Million Records Online

Security Researchers discover millions of records that appear to belong to Dealer Leads LLC. Car dealer leads leaked online.
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

Gartner’s Legacy System Exposed Online
Database Elasticsearch

Gartner’s Legacy System Exposed Online

On August 14th I have sent a responsible disclosure notice to Gartner, the world’s leading information technology research and advisory company, […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director

Fundraising Platform Exposes 7.5 Million Records Online
Data Breach Database Elasticsearch

Fundraising Platform Exposes 7.5 Million Records Online

Wedid.it fundraising platfom owned by Allegiance Fundraising Group exposed millions of records online
Jeremiah Fowler

Jeremiah Fowler

Director of Security Research and Senior Communications Consultant

UK Property Preservation Company Has Data Exposed Online by 3rd Party
Data Breach Database

UK Property Preservation Company Has Data Exposed Online by 3rd Party

Security Researchers discover data leak by 3rd party that exposed UK based Timberwise files online. Timberwise claims it was a 3rd party who leaked the data
Mark Daniels

Mark Daniels

Security Researcher & Data Analyst

Home and Family Job Search Engine Exposed Its Database
Data Breach

Home and Family Job Search Engine Exposed Its Database

FamilaFacil, a Madrid-based home and family job search platform, has exposed its MongoDB database with details on their users and […]
Bob Diachenko

Bob Diachenko

Cyber Threat Intelligence Director