• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Vacation Web-site Uncovered 37 Million Documents In advance of Meow Attack

You are here: Home / General Cyber Security News / Vacation Web-site Uncovered 37 Million Documents In advance of Meow Attack
August 24, 2020

The company powering a person of India’s most common travel scheduling internet sites exposed 43GB of customer and company info prior to it was deleted by the notorious “Meow” attacker, according to scientists.

A crew at SafetyDetectives led by Anurag Sen found an Elasticsearch server without having password security or encryption on August 10.

It unsuccessful to get a reaction from the company in concern, govt-backed vacation market RailYatri, but the database was eventually secured right after get in touch with was produced with India’s national CERT (CERT-In).

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Having said that, that was way too late to save most of the facts saved there: the Meow bot struck on August 12 and seemingly deleted all but 1GB of the information.

The trove alone contained an believed 37 million records linked to about 700,000 distinctive customers of the well known internet site, a cellular app edition of which has been downloaded over 10 million situations on Google Play.

Uncovered in the misconfiguration have been users’ complete names, age, gender, actual physical and email addresses, cell phone quantities, booking facts, GPS location and names/initial and previous 4 digits of payment playing cards.

“Exposed person data could likely be utilised to perform identification fraud throughout unique platforms and other web pages,” argued SafetyDetectives.

“Users’ get hold of details could be harnessed to conduct a extensive variety of cons whilst personalized facts from the breach could be applied to encourage click on-throughs and malware downloads. Own facts is also applied by hackers to establish up rapport and believe in, with a check out of carrying out a larger sized magnitude intrusion in the foreseeable future.”

The company also warned that exposed details could have put consumers in bodily hazard.

“RailYatri’s server recorded and stored users’ place data when scheduling their tickets, and also allowed customers to observe their journey development with built-in GPS performance. This info could be utilized by hackers to find the nearest mobile tower to the user, and most likely, the user’s true location like existing handle,” it stated.

“Regular practice end users generate obvious and distinguishable vacation styles which destructive actors could use to commit violent criminal offense directly upon the particular person.”

The bot-driven Meow attack marketing campaign has so significantly wrecked data from thousands of victims, giving an even better urgency for IT administrators to ensure any cloud databases are properly configured.

Previous Post: «A Google Drive 'feature' Could Allow Attackers Trick You Into A Google Drive ‘Feature’ Could Allow Attackers Trick You Into Setting up Malware
Next Post: TikTok to Start Legal Motion Against Trump Administration Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • OpenAI Unveils Aardvark: GPT-5 Agent That Finds and Fixes Code Flaws Automatically
  • Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack
  • China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats
  • China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems
  • The MSP Cybersecurity Readiness Guide: Turning Security into Growth
  • CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers
  • Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery
  • CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
  • A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do
  • Google’s Built-In AI Defenses on Android Now Block 10 Billion Scam Messages a Month

Copyright © TheCyberSecurity.News, All Rights Reserved.