Catalin Cimpanu reports: As security experts predicted since last year, ElasticSearch servers –a technology for powering search functions– are becoming the next big source of massive data leaks. The latest company to be added to the list of breach incidents caused by an exposed ElasticSearch server is Sky Brasil, one of the biggest subscription television…
Category: Exposure
ElasticSearch server exposed the personal data of over 57 million US citizens
Catalin Cimpanu reports: An ElasticSearch server that was left open on the Internet without a password has leaked the personal information of nearly 57 million Americans for almost two weeks, ZDNet has learned. The leaky server was spotted by Bob Diachenko, Director of Cyber Risk Research for cyber-security firm Hacken, during a regular security audit…
Singapore State Courts’ digital files accessed illegally due to system loophole
Eileen Yu reports: Singapore’s State Courts has revealed that several digital documents have been accessed without proper authorisation due to a loophole in a filing system. The Integrated Criminal Case Filing and Management System (ICMS) was used in court for criminal proceedings and to support an Accused Person online portal. The portal could be accessed…
Urban Massage exposed a huge customer database, including sensitive comments on its creepy clients
Zack Whittaker reports: Urban Massage, a popular massage startup that bills itself as providing “wellness that comes to you,” has leaked its entire customer database. The London, U.K.-based startup — now known as just Urban— left its Google-hosted ElasticSearch database online without a password, allowing anyone to read hundreds of thousands of customer and staff…
Data Protection Authority of Baden-Württemberg Issues First German Fine Under the GDPR
Here’s a more detailed analysis of the GDPR fine of 20,000€ levied against a German flirting site, knuddels.de. Dr. Henrik Hanssen and Dr. Stefan Schuppert write: In the first fine issued by a German data protection authority under the European General Data Protection Regulation (“GDPR”), on 21 November 2018 the authority of the German state…
AU: ‘Appalling’ emergency services data breach to be investigated
Matilda Boseley & Simone Fox Koob report on a breach of sensitive information in Victoria: The state government will launch an immediate investigation into an “appalling” data breach that saw personal details of emergency services staff posted to the web. The breach reportedly occurred in October and saw private details – including addresses and medical…