
The French newspaper “Le Figaro” exposed approximately 7.4 billion files containing personally identifiable information (PII) of journalists and employees, as well as 42,000 users.
The data was exposed from an unsecured database belonging to “Le Figaro” and contained 8 TB of data. The data was exposed due to a misconfigured Elasticsearch server.
The “Le Figaro” website is thenews website most visited. It is read by over 23 million peopleon a monthly basis.
The database was exposed since February 2020
The database was discovered by a research team led by Anurag Sen and contained files with information about recently registered users (account creation from February to April 2020), as well as account records of old users who logged in during that period.
For older users, the database only exposed data , while for new users, credentials.

The data exposed included: emails, full names, home addresses, countries, zip codes, plain text passwords, as well as IP addresses and tokens used to access internal servers.
It is difficult to determine the exact number of users, journalists, and employees whose data was exposed.
Technical network information has also been exposed
The database also contained numerous technical files with information about backend servers Le Figaro's and other information that could make it easier for a hacker to carry out an attack on the newspaper.
These included potential access to administrator accounts, communication protocols, SQL query errors, and network traffic logs between multiple servers.
“Most worryingly, the database was completely exposed to the public – with no password required,” the researchers explain. “Anyone who knew the database’s IP address could have gained access.”
The exposed data allows for identity theft , credential phishing attacks on other sites, spear-phishing attacks on users, journalists and employees of “Le Figaro” and attacks on the company’s network and backend servers
ElasticSearch servers are often found to be unprotected and exposing data .
