GeekedIn has reportedly leaked 8 million GitHub accounts that were stored in an unsecured MongoDB database. The website says it has at least a third of the database, and it is likely being traded elsewhere online.
Security researcher Troy Hunt, who runs the service Have I been Pwned?, discovered the leaked database and shared it on GitHub.
A cursory analysis of the file ultimately revealed that:
- It contains 8,200,000 unique email addresses, meaning it records approximately 8.2 million users of GitHub, Bitbucket, and possibly other online services.
- Most of these files contain usernames, email addresses, geographic location, professional skills, years of professional experience.
- All of this information is already circulating online and accessible to anyone (GeekedIn created its own database, and offers paid access to companies interested in programmers)

GitHub stated that it allows third parties to make their users' data available, as long as it is used for the same purpose that GitHub itself uses it for.
“Using this information for commercial purposes violates our privacy statement and is not permitted,” they told Hunt.
So he finally managed to get in touch with GeekedIn, who acknowledged their mistake and promised to secure the data.
Hunt made some of the data available in raw form through his service. It includes about a million GitHub users.
“This incident is not due to any kind of GitHub security vulnerability, and is more likely related to data on their website that someone recorded and then exposed to another service,” Hunt said.
