A database belonging to the Digital Point forum was breached and the records of 800,000 users leaked.
Digital Point based in San Diego, with headquarters in California, is described as the «largest webmaster community in the world» that brings together freelance professionals, merchants and coders.
On July 1, the WebsitePlanet research team and cybersecurity researcher Jerry Fowler revealed an unsecured Elasticsearch database containing over 62 million records. In total, data belonging to 863,412 Digital Point users was leaked.
According to the research team, the names, emails , and internal identification numbers of the users were made public.

Additionally, the internal records and the details of users' posts were stored in the open database. When the researchers examined the database to find out who the owner was, they discovered data sets related to forum members who flagged posts and the reasons behind those reports – including claims of “bad business transactions”, spam messages or other reasons.
In addition to the usual security implications of data theft and phishing, the database could be one of many that succumbed to Bot Meow, an automated script that was responsible for breaching thousands of unsecured MongoDB and Elasticsearch in July. Once deployed, the script replaces data with numbers and the word “meow.”
“One of the dangers of a database that is not protected with a password is that it is a very dangerous target because it contains data sets”, says the team.
Fowler informed the Digital Point forum on July 1, the same day the leak was discovered. The notification was taken seriously and access to the database was revoked within a few hours.
