A European fashion retailer exposed the personal data of millions of its customers after using a misconfigured cloud database. Researchers at vpnMentor discovered the unencrypted Elasticsearch server . The discovery was made on June 28th, and parent company BrandBQ secured it about a month later, on August 20th.

The retailer, based in Krakow, has both online and physical stores. The physical stores are located throughout Eastern Europe: Poland, Romania, Hungary, Bulgaria, Slovakia, Ukraine and the Czech Republic. Its core brands are Answear and WearMedicine.com .
According to the researchers, the exposed database contained approximately 1 billion records. Of these, 6.7 million belonged to the company 's online customers . The exposed data includes: personally identifiable information (PII), such as full names, emails , home addresses, dates of birth, phone numbers, and payment records (however, there was no payment card information).
Additionally, the database contained 50,000 records related to local contractors. In these cases, information such as VAT and purchase information was exposed. Finally, according to vpnMentor researchers, data related to Answear's mobile app was affected, exposing personal information of 500,000 users of the Android app as well as users of the iOS version.
Researchers believe that the exposed database contains enough information that cybercriminals could leverage to carry out successful and highly convincing phishing attacks.

“ The same tactics could be used against contractors and the BrandBQ company itself. A successful phishing campaign against a business can be absolutely devastating and countering it is a challenge ,” BrandBQ explained
“Furthermore, all it takes is one employee with no training in cybercrime to click on a malicious link in an email. And that could infect a company's entire network. With more than 700 employees, this is a real risk for BrandBQ.“.
According to Infosecurity Magazine, attackers could also use the exposed data for corporate espionage and leverage “sensitive technical information” in the database to discover vulnerabilities that they could exploit.
