VAT software supplier exposed data of millions
Summary
A MongoDB database containing the personal data of millions of UK residents was left exposed to the public internet for almost a week after its owner neglected to secure the Amazon Web Services (AWS) server that housed it. However, according to Comparitech threat researcher Bob Diachenko, who uncovered the exposed server on 3 February, the owner left the records visible to the web without any password or authentication needed to access it. “Time was of the essence here, since millions of UK shoppers personal, payment and shipment information was at risk, so I started to analyse the content of database and after several days I made the connection to the ultimate owner,” said Diachenko. To do so, it would have been required to properly secure the data on receipt, storage, usage and transfer – failure to do so could still result in suspension of termination of its access to the platform APIs. Telco provider Virgin Media confirms ‘data incident’ that left personal details of 900,000 people exposed, but denies its systems were hacked or that it suffered a data breach.