WizCase security researchers have discovered unprotected databases belonging to various e-learning platforms that were exposed online without password protection. The unencrypted databases leaked personally identifiable information (PII) of over 1 million e-learning platform users. The leaked user data includes names, emails , passwords, social security numbers, phone numbers, home addresses, dates of birth, as well as information related to courses taken on the e-learning platforms.
The databases were hosted on servers with a “bad” configuration, allowing anyone to access them without authentication. WizCase reported that it discovered breaches at five different online educational institutions. The data was stored in four Amazon S3 buckets and an ElasticSearch server.

The breach detected by Wizcase researchers affects 5 different e-learning companies:
- Escola Digital: Several CSV files containing the personal information of its users were leaked from the Brazilian e-learning website. The leaked data was collected from 2016 to 2017.
- MyTopDog: The platform specifically aimed at school-age children, based in South Africa, exposes data from over 800,000 students, as well as other business information.
- Okoo: The e-learning platform for children, exposes nearly 1 million records of user activity.
- Square Panda: The virtual platform created to help children learn to read and write through various online games, exposes files from over 15,000 users.
- Playground Sessions: The platform that offers virtual piano lessons had files of over 4,000 users leaked. Many of the users affected by the breach are children and young people, and attackers may use this information to carry out phishing and fraud attacks.

With the outbreak of the global COVID-19, the use of e-learning platforms has increased. As a result, hackers have targeted numerous e-learning portals to steal users’ personal information. Recently, India-based e-learning platform “Unacademy” suffered a data breach that exposed information of 22 million users. Cybersecurity firm “Cyble” revealed that hackers had put 21,909,707 user records up for sale on underground forums for $2,000. The information that was compromised included usernames, passwords, membership dates, last login date, account status, email addresses, first and last names, and other user account details. Also, the Spanish e-learning platform “8Belts” suffered a data breach that resulted in the personal data of over 100,000 e-learners from around the world being leaked.
