Smart home technology company Wyze Labs admitted that the data of 2.4 million of its users was exposed online from December 4 to December 26.The data was in an unsecured database.
The company that discovered the exposed data was Twelve Security. A report was published about the security , which is how Wyze was notified.
However, according to Dongsheng Song, co-founder of Wyze, some of the reported information was not accurate.
“We do not send data to Alibaba Cloud and do not collect highly personal information, even from products in beta testing,” it said in response to Twelve Security’s disclosure.
Insecure database
The data contained in the unsecured database contained various information about Wyze users. Essentially, the data was a copy of the production-related database. It was created by Wyze to “calculate key metrics, such as device, failed connections,” etc.
Initially, the database was configured correctly and protected Wyze customers. However, an employee accidentally overturned the security protocols on December 4th.
“We locked down the database in question before we confirmed it was exposed,” Song added. “We did this as a precaution because the published Twelve Security article referred to a database connected to Elasticsearch:a tool we use.”
The security issue was also confirmed by Security Discovery researcher Bob Diachenko . According to Diachenko, the database contained 1,807,201,457 files.

Wyze user information exposed
Song confirmed some of Twelve Security's information about the exposed user data.
The database contained the following information: emails user. The health data belonged to a small number of beta testers.
However, Song said the database “did not contain user passwords or personal and financial information.” In contrast, Twelve Security said in its report that such data was included.
Also, according to Wyze's co-founder, "there is no evidence that the API tokens for iOS and Android were exposed, but we decided to renew them as a precaution when we began our investigation.".
Wyze advises all its customers to be cautious, as a malicious hacker may have possession of the emails and carry out phishing attacks.
