• Entire Brazilian population potentially put at risk by major data

    From TechnologyDaily@1337:1/100 to All on Wed Jan 10 11:30:05 2024
    Entire Brazilian population potentially put at risk by major data leak

    Date:
    Wed, 10 Jan 2024 11:17:38 +0000

    Description:
    Yet another unprotected database was recently discovered, but this one held private info on virtually every Brazilian citizen.

    FULL STORY ======================================================================

    Researchers from Cybernews recently discovered an unprotected database that held personal information on approximately 223 million Brazilians.

    Given that by 2021 data, Brazil has 214 million people, it could be that information on the entire population of Brazil was contained in that
    database.

    The researchers said they discovered the database after running a query in Elasticsearch, a tool people can use to search, analyze, and visualize, large volumes of data. They couldnt determine who the owners of the database were, but said that the cluster held peoples full names, birth dates, sex, and Cadastro de Pessoas Fisicas (CPF) numbers. The latter is a 11-digit taxpayer identifier. Poor password hygiene

    Since making the discovery, the database was locked down. However, we dont know for how long it stayed unprotected, and if any threat actors managed to find it before the researchers. If they did, they could use the information found there in various cyberattacks and fraud campaigns, such as phishing, identity theft , or even wire fraud. This could have resulted in financial losses, unauthorized access to personal accounts, and other severe consequences for the individuals affected, Cybernews says.

    Having an unprotected cloud database means that there is no authentication process in place, and that anyone would be able to access the file, as long
    as they knew where to look. This process is made even easier with Elasticsearch, a tool that simplifies the process of finding unprotected databases.

    While definitely a lapse on the owners side, this type of leak cant be considered a system vulnerability. Still, unprotected databases are one of
    the most common causes of data leaks, with billions of data entries being available to the general public at all times.

    For example, in early November 2023, Chinese researchers found a database of 3.3 million orders made by the customers of a Chinese online store, between 2015 and 2020. In some cases, the entries contained shipping addresses and phone numbers, and in other cases even copies of government-issued identity cards. More from TechRadar Pro Microsoft employees leaked 38TB worth of private data, including Teams chats Here's a list of the best firewalls
    around today These are the best endpoint security tools right now



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/entire-brazilian-population-potentially -put-at-risk-by-major-data-leak


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)