
The team behind the open -source content management system (CMS) Joomla announced a data breach last week.
The breach is attributed to a member of the Joomla Resources Directory (JRD) team who lefta full backup of the JRD site ( resources .joomla.org) exposed in an AmazonWebServices S3 bucket owned by the company.
According to the Joomla team, the backup was not encrypted and contained data for approximately 2,700 users who had registered and created profiles on the JRD site (a portal where professionals advertise their Joomla skills).
Joomla administrators are still investigating the breach. At this time, we know that user data was exposed, but it is unclear if anyone found and stole the data from the S3 server.

In case someone found the backup ,they had access to the following data:
- Full name
- Business address
- Business email address
- Business phone number
- Company URL
- Nature of the business
- Encrypted password (hashed)
- IP address
The breach is not considered particularly serious, as most of this information was already public. The JRD portal serves as a directory for Joomla professionals. However, the hashed passwords and IP addresses were not intended to be public.
The Joomla team recommends that all JRD users change their passwords on the JRD portal, as well as on other sites and applications that may have used the same passwords. If someone has found the details, they can use them to gain access to other accounts.
The Joomla team said that as soon as they learned about this backup leak, they conducted a full security audit of the JRD portal.
Joomla is a very popular system (CMS), a web application used to create and manage self-hosted websites. It currently ranks third on the list of most used CMSs on the Internet.
