Privacy News Unprotected MongoDB Exposes Scraped Profile Data of 66 Million

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Information belonging to more than 66 million individuals was discovered in an unprotected database, within anyone's reach, if they knew where to look on the web. The records look like scraped data from LinkedIn profiles.
The cache includes personal details that can identify users and could help adversaries create phishing attacks that are more difficult to recognize.

According to Bob Diachenko, Director of Cyber Risk Research at Hacken, the trove was exposed via a MongoDB instance that could be accessed without authentication.
He found 66,147,856 unique records containing full name, personal or professional email address, user's location details skills, phone number, and employment history. A link to the individual's LinkedIn profile was also present.
Check if your details were exposed

He was unable to determine the owner of the database but says that it is no longer online at the moment. This does not exclude the possibility of popping on the web again, though.

The scraped data is currently uploaded to the HaveIBeenPwned service which allows users to check if their personal information has been exposed.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top