Articles by SafetyDetectives Cybersecurity Team

SafetyDetectives Cybersecurity Team

The SafetyDetectives research lab is a pro bono service that aims to help the online community defend itself against cyber threats while educating organizations on how to protect their users’ data. The overarching purpose of our web mapping project is to help make the internet a safer place for all users

Up to 2 million people affected by data breach at Indian e-learning platform
Up to 2 million people affected by data breach at Indian e-learning platform
A prominent Indian e-learning platform was discovered to be operating a completely unsecure Elasticsearch server based in the US. The vulnerability meant that more than 25 gigabytes of personal information belonging to around 2 mi...
Primary Indian ticket vendor suffers  crippling data breach
Primary Indian ticket vendor suffers crippling data breach
One of India’s most popular travel booking hubs was left exposed without adequate security measures, and subsequently, suffered a significant data breach that exposed all production server information and led to the loss of over 4...
Could your baby monitor be unsafe and unsecured?
Could your baby monitor be unsafe and unsecured?
The SafetyDetectives cybersecurity team has discovered a vulnerability affecting baby monitors, provoked by their misapplication/misconfiguration, which provides potentially harmful parties with unauthorized access to each camera’...
Report: Job Portal Database Exposed
Report: Job Portal Database Exposed
SafetyDetective’s research lab discovered a leak online that exposed an elastic server containing 3GB of data with over 1.6 million users affected. We informed the apparent owners of this database as soon as we were able to identi...
Cashback Sites Leak Unencrypted Passwords, Bank & Other Sensitive User Data
Cashback Sites Leak Unencrypted Passwords, Bank & Other Sensitive User Data
The security research team at Safety Detectives has uncovered yet another data leak worth 2 terabytes of data hosted on an Elastic Server. Affecting savvy shoppers in both India and the U.K., sister sites Pouringpounds.com and Cas...
French Subscribers to Famous News Site at Risk from Hacking, Fraud
French Subscribers to Famous News Site at Risk from Hacking, Fraud
The security research team at Security Detectives, led by Anurag Sen, has uncovered a significant data leak from French daily newspaper Le Figaro. Hosted on an Elasticsearch server owned by Poney Telecom in France, the leaking dat...
Cybersecurity vulnerability at major cosmetics brand leads to 7 gigabytes+ data leak
Cybersecurity vulnerability at major cosmetics brand leads to 7 gigabytes+ data leak
One of the world’s well-known cosmetic brands has been informed that a significant data breach was discovered on its web server, which was found to be publicly exposed, without password protection or encryption. Our security team,...
Brazil: Millions of Records Leaked, Including Biometric Data
Brazil: Millions of Records Leaked, Including Biometric Data
The security research team at SafetyDetectives has discovered a significant data leak in addition to other security flaws (such as lack of password protection) relating to fingerprint data on an Antheus log server in Brazil. Our t...
Australian sports fan portal leaks 132GB of private data
Australian sports fan portal leaks 132GB of private data
An active Australian sports fan site with over 100,000 members has leaked a large volume of private data. Our security team discovered multiple instances of personal private information made available to the public within the comp...
Major German shopping site leaks customer data
Major German shopping site leaks customer data
A publicly-listed multinational retailer with millions of dollars in annual revenues was discovered to be operating a completely unsecured server, thereby publicly exposing private data belonging to around 700,000 of its customers...