Millions of records containing sensitive, personally identifiable information, were sitting online in yet another unencrypted, non-password-protected database, experts have warned.
Found by security researcher Jeremiah Fowler, who discovered and reported his findings to vpnMentor, the database contained 3,637,107 records, and was 12.2TB in total size. It belongs to a company called Passion.io, a Delaware-based no-code app-building platform that allows creators, influencers, entrepreneurs, and coaches, to create websites without having any prior coding knowledge. They can also create, and sell, interactive courses.
Read more…
Source: TechRadar News
Sign up for our Newsletter
The latest news and insights delivered right to your inbox.
Related:
- Pharma giant Cencora hit by major cyberattack
February 28, 2024
Cencora has confirmed suffering a data breach earlier this month which resulted in the theft of sensitive, personal data. Cencora is a drug wholesale company and a contract research firm that was previously known as Amerisource Bergen. It was formed in 2001, after the merger of Bergen Brunswig and AmeriSource. Read more… Source: MSN News
- A first analysis of the i-Soon data leak
February 21, 2024
Data from a Chinese cybersecurity vendor that works for the Chinese government has exposed a range of hacking tools and services. Although the source is not entirely clear, it seems that a disgruntled staff member of the group leaked the information on purpose. The vendor, i-Soon (aka Anxun) is believed to be a private contractor that ...
- Sharp rise in cyber attacks at UK law firms as hackers eye sensitive data
February 21, 2024
The number of reported cyber attacks on UK law firms has increased 36 per cent over the past year. According to data by speciality reinsurance group Chaucer, there were 166 reported cyber breaches in 2021/22, this number jumped to 226 for 2022/23 (as of 30 September). Chaucer says that the large number of attacks against law ...
- India: EPFO, PMO data breach, Centre says aware of reports, Cert-In looking into details
February 21, 2024
The government is aware of reports of a data breach that claims having datasets from the Prime Minister’s Office (PMO) and the Employees’ Provident Fund Organisation, and has asked the Indian Computer Emergency Response Team (Cert-In) to look into it, senior officials told ET. “We are aware of it but need to verify if the claims ...
- Toronto Public Library uncertain whose data stolen in October cyber attack
February 20, 2024
The Toronto Public Library needs more time to investigate whether cardholder, volunteer and donor data has been compromised during a serious cyberattack four months ago. In a final report to the board on the October 2023 security breach that the library said exposed the personal data of staff and family members, it said it is “currently ...
- UK: Council worker took tens of thousands of email addresses in massive data breach
February 19, 2024
A massive data breach by a worker at Stratford-on-Avon District Council saw tens of thousands of email addresses taken. The breach, which happened in November last year, was over a database of email addresses given by residents, the authority said. The probe found that around 79,000 email addresses from the garden waste collection database were affected. ...

