In recent weeks, security researcher Chris Vickery has been working on discovering insecure apps and reaching out to the makers of those apps to resolve these issues. One of the apps he found leaking a significant amount of user data is MacKeeper from Kromtech Alliance.

MacKeeper is the equivalent of an antivirus combined with adware, which many Mac users have come to hate in recent years and in fact, to show their aversion to the application, they have gone so far as to collectively sue the programmer for displaying false warnings about non-existent malware on their Mac computers.
Now, as Mr. Vickery reveals, the company behind the app has left a MongoDB server active that does not appear to be configured correctly and is accessible via external connections. This server had information on 13 million MacKeeper users.
The issue is old, documented by many security researchers in the past, so only Kromtech Alliance is solely responsible for the data leak. Apparently, the development team had used a MongoDB machine without changing its default settings, if the 27017 port was left open for connections over the Internet.
A previous investigation from February revealed that about 40,000 MongoDB databases had data leaked in the same way. In July, later in the year, the number dropped to 30,000, but businesses still had 600 terabytes of data leaked. Even worse, in August, another set of investigations found 1.2 petabytes of data leaked in the same way, but also from Redis, Elasticsearch, and Memcached servers.
Furthermore, MongoDB representatives told us that the open-door issue only existed in very old versions of MongoDB and was patched over a year ago. So, in addition to leaving an online database vulnerable, Kromtech Alliance was also using an older version, something no security expert would ever suggest.
When Vickery discovered the flaw, he contacted Kromtech, which patched the issue right away and issued a press release about the incident, reassuring users that, after an internal review, it was determined that only Mr. Vickery had accessed the vulnerable server and no one else had looked into their database.
Kromtech also said that a third party handled the credit card data, so there was no way users would have had any serious issues if others had ever accessed the data.
Using the same technique that discovered the insecure MacKeeper database, Mr. Vickery also found a large amount of user data leaking from many other apps and services. These are:
- OkHello – video chat application (2.6 million accounts)
- Slingo – online gambling game (2.5 million accounts)
- Fit – fitness app (576.000 accounts)
- Vixlet – social network (377.000 accounts)
- California Virtual Academies – online school network (74.000 accounts)
- Hzone – dating app for patients with HIV (5.027 accounts)
