Millions of records containing sensitive, personally identifiable information, were sitting online in yet another unencrypted, non-password-protected database, experts have warned.
Found by security researcher Jeremiah Fowler, who discovered and reported his findings to vpnMentor, the database contained 3,637,107 records, and was 12.2TB in total size. It belongs to a company called Passion.io, a Delaware-based no-code app-building platform that allows creators, influencers, entrepreneurs, and coaches, to create websites without having any prior coding knowledge. They can also create, and sell, interactive courses.
Read more…
Source: TechRadar News
Sign up for our Newsletter
The latest news and insights delivered right to your inbox.
Related:
- UK: 250 Afghan interpreters’ details in data breach, MoD confirms
September 21, 2021
The Ministry of Defence has launched an investigation into a data breach involving the details of 250 Afghan interpreters. An MoD spokeswoman told Sky News 250 email addresses are part of the breach, but it is not yet known if they contain the names or photos of the translators involved. The breach was carried out by the ...
- Is it OK to use stolen data? What if it’s scientific research in the public interest?
September 20, 2021
There’s a fine line between getting hold of data that may be in the public interest and downright stealing data just because you can. And simply because the data is out there – having been stolen by online intruders and then leaked – does not mean it is right to use it. A paper published in ...
- Stolen Credentials Led to Data Theft at United Nations
September 10, 2021
A threat actor used stolen credentials from a United Nations employee to breach parts of the UN’s network in April and steal critical data, a spokesman for the intergovernmental organization has confirmed. That data lifted from the network can be used to target agencies within the UN, which already has experienced and responded to “further attacks” ...
- Hackers leak passwords for 500,000 Fortinet VPN accounts
September 8, 2021
A threat actor has leaked a list of almost 500,000 Fortinet VPN login names and passwords that were allegedly scraped from exploitable devices last summer. While the threat actor states that the exploited Fortinet vulnerability has since been patched, they claim that many VPN credentials are still valid. This leak is a serious incident as the VPN ...
- Data Breaches: A Chance for Opportunistic Scammers & What You Should Watch for
September 5, 2021
Data breaches are now part of doing business, with many companies having been affected. Data is very valuable to criminals because it is often used to commit fraudulent activities as well as to enhance the credibility of scams. Data that is stolen ranges from Social Security Numbers (SSNs) to other identification documents and payment details. Scammers ...
- Names and addresses of 110,000 UK gun owners are leaked online by animal rights activists in huge security breach
September 1, 2021
Authorities are investigating a large data breach that could put thousands of Britain’s gun enthusiasts at risk. The names, home addresses and contact details of 111,295 people who own firearms in the UK have been taken and leaked online by animal rights activists. The breach, first reported by The Register website, concerns individuals have used the Guntrader ...

