HomeSecurityCafeCanli: Personal user data leaked

CafeCanli: Leaked user personal data

CafeCanli Turkish live video chat provider, has leaked sensitive details about hundreds of thousands of users.

CafeCanli

The only positive is that the website administrators quickly secured the database leak.

Few places on the internet demand more privacy than dating sites or sites like OnlyFans, where content creators provide private videos to paying users. However, Cybernews’ research team discovered an exposed MongoDB database from CafeCanli, containing sensitive information for 421,381 users.

Read more: Data leak affects thousands of doctors in the US!

CafeCanli ,which primarily serves users in Turkey, is a well-established live video chat service provider that allows users to connect to public and private chat rooms. The website’s homepage strongly suggests that it focuses on female content creators. “The exposure of such a wide range of sensitive data, particularly within the context of an online platform offering live video chat services, is extremely concerning. Users of platforms like CafeCanli expect their interactions and financial transactions to be secure and private,” the researchers said.

What CafeCanli data was exposed?

Meanwhile, the exposed MongoDB database hosted a wealth of sensitive details about the users . According to the team, the unprotected database exposed:

  • Usernames
  • Email addresses
  • IP addresses
  • Connection information
  • Encrypted passwords
  • Payment transactions
  • User conversations
  • Internal platform files
  • Account traffic details

See also: Fujitsu: Customer data breach

Not all of the same details were exposed for all users. For example, the group reported that 54,000 payment transaction records were exposed. However, given the potentially sensitive nature of the site's services, a data leak of this kind could seriously impact user privacy.

According to the team, the site shut down the exposed database less than 48 hours after it was discovered, minimizing the potential impact on users. However, hackers scour the internet for open databases, sometimes exploiting anything the moment a database becomes public.

We have reached out to CafeCanli for comment and will update the article once we receive a response.

Why is CafeCanli's leak dangerous?

Data leaks of this nature serve as a stark reminder of the critical importance of securing databases containing sensitive user data. Researchers believe that hackers could use the leaked data to carry out identity theft attacks, especially since personal and financial transaction data was exposed.

Privacy is another major issue with the leak, as malicious actors who gain access to information stored in the unprotected database could use the exposed conversations for blackmail or otherwise use them against users.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Read more: Microlise confirms ransomware data breach

Additionally, researchers believe that hackers could use the exposed financial information to make unauthorized transactions from user accounts.

It's not just users who could suffer consequences from this data leak: exposed internal files and settings could allow cybercriminals to further breach the platform's security and move internally within its systems.

"The immediate action taken to secure the exposed database was critical, but the incident highlights the need for proactive security measures to prevent the exploitation of such vulnerabilities in the first place," the researchers said.

CafeCanli

See also: NVIDIA UFM vulnerability allows hackers to escalate privileges

To reduce the risks associated with leakage, researchers recommend the following:

  • Instant security seal: Ensure all MongoDB databases are properly secured with authentication and authorization checks
  • Data encryption: Implement stronger encryption for sensitive data, especially passwords and financial transactions
  • Access Controls: Enforce strict access controls and ensure that only authorized personnel have access to sensitive data
  • Regular security audits: Conduct regular security audits and penetration tests to identify and fix vulnerabilities in the platform
  • Notify users: Notify affected users about the breach and provide recommendations for steps they can take to protect themselves, such as changing passwords
  • Legal and Regulatory Compliance: Reviewing compliance with data protection regulations and taking steps to address potential legal implications

Source: cybernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS