A leaky database of SMS text messages exposed password resets and two-factor codes

General News

Summary

A security lapse has exposed a massive database containing tens of millions of text messages, including password reset links, two-factor codes, shipping notifications and more. Although Kaul found the exposed server on Shodan, a search engine for publicly available devices and databases, it was also attached to to one of Voxox’s own subdomains. Worse, the database — running on Amazon’s Elasticsearch — was configured with a Kibana front-end, making the data within easily readable, browsable and searchable for names, cell numbers and the contents of the text messages themselves. Often, app developers — like HQ Trivia and Viber — will employ technologies provided by firms like Telesign and Nexmo, either to verify a user’s phone number or to send a two-factor authentication code, for example. But it’s firms like Voxox that act as a gateway and converting those codes into text messages, to be passed on to the cell networks for delivery to the user’s phone.

Classifications

industries
Telecommunications
applications
Collaboration & Communication

AskAI Classifications

Labels
SaaS Telecommunications Marketing Software

Linked Companies

VOXOX
$5M to $10M
Telesign
$50M to $100M
Nexmo
$10M to $25M