
Security researchers have discovered a vulnerable Elasticsearch server containing datasets of more than 1.2 billion users. The data was found to be related to two different data enrichment companies.
Data enrichment is the process of improving a userby adding new information.
The vulnerable server discovered contains personal user information that is not protected by a password or authentication. Anyone can access and download this data by simply going to http://35(.)199(.)58(.)125:9200.
1.2 billion records exposed
The researchers who discovered the vulnerable server, Bob Diachenko and Vinny Troia, published a screenshot showing the discovered database indexes labeled “PDL” and “OXY.” It is the largest single-source data leak in the organization ’s history .
Database index
The researchers examined the files of 50 users. The data they found came from two data enrichment companies, People Data Labs and OxyData.
Analysis of the Oxy database revealed that the datasets contained almost entirely LinkedIn data ,including employee details. The researchers contacted OxyData and were informed: “the server did not belong to them.”
Researchers are unable to attribute the database to any specific company, they believe the data belongs to customers of both companies.
“Due to obvious privacy concerns, cloud are not sharing any of their customers’ information, which unfortunately leads to a dead end in the investigation. Agencies like the FBI can request this information through legal process, but they do not have the authority to force the organization to disclose a breach.”
