On October 15th I discovered a non-password protected database that contained a large number of internal records. There was a total of more than 123 million records exposed that contained a combination of test and production data. Upon further investigation I saw that there was a large collection of user data. In total there were 13 million user records that included their names, email addresses, user ID numbers in plain text. Security Discovery’s Bob Diachenko also found the same dataset on October 19th during this time before public access was closed.
It is unclear how long these records were exposed or who else may have had access to this data. It is also unclear if users were ever informed of the data breach. Fotor (Everimaging Ltd.) is based in Chengdu, Sichuan, China. According to the description on the Google play store “Fotor is an online photo editing program with 350 million users from all around the globe”. I did see geo-location logging in the user accounts from multiple countries.
What the database contained: