More than 3.8 billion records exposed in DarkBeam data leak

Billions of login credentials were available online after a database was left unprotected

Add bookmark
A laptop computer displaying code in teal, pink and orange

More than 3.8 billion records have been exposed after digital protection firm DarkBeam left an interface containing the exposed records unprotected. 
The leak was discovered on September 18 by CEO of cyber security news site SecurityDiscovery, Bob Diachenko, who alerted DarkBeam to the leak. The digital protection firm immediately addressed the vulnerability and closed the leak after being alerted to the fact.

DarkBeam had been collecting the data to alert its customers in the case of a data breach, meaning the data exposed was data already leaked in prior cyber attacks. Of the data leaked, there were 16 collections named ‘email 0-9' and ‘email A-F' which represented 239,635,000 pairs of login credentials.

A sample of the leaked data. Source: SecurityDiscovery.

The data leak was caused by leaving a Elasticsearch and Kibana data visualization interface unportected, allowing access to the confidential data held within it. Speaking to cyber security site Cybernews about the data leak, Dianchenko noted that data leaks like this are usually down to “human error”, for example employees forgetting to password-protect data after maintenance is done. 

DarkBeam has not yet publicly addressed the situation. 


More From Incident of the Week

IOTW: Victoria Court recordings exposed in suspected ransomware attack

Unauthorized access disrupted audio visual in-court technology network impacting video recordings, a...

 2024-01-05  by Michael Hill
IOTW: Victoria Court recordings exposed in suspected ransomware attack

IOTW: Xfinity data breach impacts 35 million customers

Exposed data includes usernames, hashed passwords and social security numbers

 2023-12-22  by Michael Hill
IOTW: Xfinity data breach impacts 35 million customers

IOTW: Russia-linked cyber attack targets Ukraine’s biggest phone operator

Powerful attack knocked out internet access and mobile communications, damaging IT infrastructure

 2023-12-15  by Michael Hill
IOTW: Russia-linked cyber attack targets Ukraine’s biggest phone operator

IOTW: HTC confirms cyber attack as BlackCat ransomware gang teases stolen data

BlackCat/ALPHV ransomware group leaked photos of what appears to be stolen passports, contact lists,...

 2023-12-08  by Michael Hill
IOTW: HTC confirms cyber attack as BlackCat ransomware gang teases stolen data

IOTW: Okta data breach affects all customer support users

Hackers stole information on all users of Okta’s customer support system

 2023-12-01  by Michael Hill
IOTW: Okta data breach affects all customer support users

Recommended