Elasticsearch Instances Expose 43M+ Records Including Credentials, Credit Cards, and Customer Data

SOCRadar researchers announced the identification of three publicly accessible and misconfigured Elasticsearch instances leaking highly sensitive data, including infostealer logs, credit card information, and millions of personal identity records.

The exposed databases contained more than 43 million records, including over 5 million valid credentials, thousands of credit cards, and large-scale PII and commercial transaction data. All three cases demonstrate how misconfigured Elasticsearch services continue to create immediate and exploitation-ready risks for organizations and individuals.

Key findings include: 

  1. Incident 1: 7.2 million infostealer logs and 24, 000 credit cards exposed
  2. Incident 2: 35 million Italian PII records publicly accessible
  3. Incident 3: 1.5 million customer records and commercial data exposed

The security team analyzed the exposed instances, notified relevant parties, and assessed the potential impact. The full details of this can be read here: https://socradar.io/blog/elasticsearch-instances-43m-records-data/

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading