HomeSecurityAdult site CAM4 exposes 11 million users

Adult site CAM4 exposes 11 million users

CAM4

7TB of user and member data from popular adult live streaming site CAM4 has been leaked.

The leak was the result of an error that left one of the website's databases vulnerable and open to anyone from the internet.

CAM4 has approximately 2 billion visitors each year and its members stream over 1 million hours of adult content each week, with over 75,999 private shows broadcast daily.

Private conversations and IP addresses exposed

Security research group Security Detectives, led by Anurag Sen, was the first to spot the exposed CAM4 database, which was then immediately taken down by its parent company Granity Entertainment.

The leaked data included a lot of information about the site's users, such as names, sexual orientation, emails , IP addresses, and even users' private conversations.

Additionally, 11 million of the nearly 11 billion records found in the exposed database contained at least one email address from a variety of email providers, including gmail.com, icloud.com, and hotmail.com.

Based on the results analyzed from CAM4's insecure database, over 6.5 million of the exposed users were residents of the US, over 5.3 million were from Brazil, and 4.8 million were from Italy. Additionally, 4.1 million French and 3 million Germans were also affected.

Adult site CAM4 exposes 11 million users

This data could potentially be used by attackers as part of a wide range of attacks targeting users and members, from highly convincing phishing attacks and extortion campaigns to identity theft and various types of fraud.

Data breaches from adult websites have a serious impact on users, as attackers can blackmail victims for a long time, threatening them with revealing the information to their spouses. In addition, there have been cases where malicious actors have also attacked unsuspecting spouses. There have even been incidents where victims of blackmail committed suicide.

To reduce the chances of this happening, Elastic NV advises database administrators to secure their ElasticSearch clusters by “preventing unauthorized access, with password protection, role-based access control, and IP filtering,” as well as by setting passwords for built-in users. On the Elastic NV website, administrators can also find a quick guide on how to secure ElasticSearch clusters. 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS