Status DataClose notification

New Data Breach Exposes 57 Million Records

Alex Horlan
Alex Horlan
СТО HackenProof

A massive 73 GB data breach was discovered during a regular security audit of publicly available servers with the Shodan search engine. Before this publication, there were at least 3 IPs with identical Elasticsearch clusters misconfigured for public access. The first IP was indexed by Shodan on November 14th, 2018. An open Elasticsearch instance exposed personal info of 56,934,021 US citizens, with information such as first name, last name, employers, job title, email, address, state, zip, phone number, and IP address.

Another index of the same database contained more than 25 million records with more of a “Yellow Pages” details directory: name, company details, zip address, carrier route, latitude/longitude, census tract, phone number, web address, email, employee count, revenue numbers, NAICS codes, SIC codes, etc.


Possible Origin of the Data Breach

While the source of the leak was not immediately identifiable, the structure of the field ‘source’ in the data fields is similar to those used by a data management company, Data & Leads Inc. However, we weren’t able to reach their representatives.

Moreover, shortly before this publication, Data & Leads’ website went offline and is now unavailable.

As of today, the database is no longer exposed to the public; however, it is unknown how long it had been online before Shodan crawlers indexed it on November 14th, and who else might have accessed the data.


The Pattern Continues: One Major Exposure, Every Year Since

Misconfigured Elasticsearch clusters left open on the public internet have not gone away since 2018—if anything, the volume of exposed data has grown by orders of magnitude. Below is one major, independently verified incident for each of the eight years following our original report.

2019—1.2 Billion Records (People Data Labs / OxyData.io)

Researchers Bob Diachenko and Vinny Troia found an unsecured Elasticsearch server on Google Cloud Platform in October 2019, exposing roughly 4TB of data on over 1.2 billion individuals. The database contained 622 million unique email addresses, tens of millions of phone numbers, and profile data pulled from LinkedIn and Facebook. The researchers traced the data to two data-enrichment firms, People Data Labs and OxyData.io, though ownership of the exposed server itself was never conclusively established.

2020—10.88 Billion Records (CAM4)

Researchers at Safety Detectives discovered an unsecured Elasticsearch database belonging to CAM4, an adult live-streaming platform, in March 2020. The misconfiguration exposed roughly 7TB of data—some 10.88 billion records in total—including names, email addresses, payment details, chat logs, and sexual orientation data. There was no evidence the data had been exfiltrated by a third party, but the sheer scale made it one of the largest single exposures on record at the time.

2021—35 Million US Household Records

Comparitech's Bob Diachenko discovered an unprotected Elasticsearch database on June 26, 2021, containing detailed marketing profiles on roughly 35 million US residents concentrated in Chicago, San Diego, and Los Angeles. Each record held up to 268 fields—names, addresses, ethnicities, estimated income, shopping habits, and more. AWS took the server down about a month later, on July 27; the database's owner was never identified.

2022—StoreHub (Malaysia)

Safety Detectives found an exposed, password-free Elasticsearch server belonging to Malaysian point-of-sale vendor StoreHub, discovered in January 2022. The server held customer names, phone numbers, addresses, emails, device types, order histories, and partially masked payment card details, along with access tokens for StoreHub-powered sites. StoreHub said it patched the exposure within 24 hours of being notified and found no evidence of misuse.

2023—Lionsgate Play (37 Million Users)

Cybernews researchers discovered an unprotected Elasticsearch instance belonging to Lionsgate's streaming platform, reported March 22, 2023. The 20GB trove held roughly 30 million server-log entries—IP addresses, device and browser data, content titles, and search queries—plus unidentified authentication-like hashes. Lionsgate closed the exposed instance after being contacted by researchers.

2024—223 Million Brazilian Citizens

In early January 2024, Cybernews researchers running an Elasticsearch query uncovered an unprotected database holding personal records on approximately 223 million people—potentially covering nearly the entire population of Brazil. Exposed fields included full names, birth dates, sex, and CPF numbers (Brazil's national taxpayer ID). As with most of these cases, the database's owner was never identified before it was locked down.

2025—184 Million Login Records

Security researcher Jeremiah Fowler discovered an unprotected online database in May 2025 containing over 184 million records—plaintext emails, passwords, and login links tied to major platforms including Apple, Google, Facebook, and Microsoft, plus government and financial services accounts. Unusually, Fowler found no identifying trail back to an owner at all, making it one of the harder exposures to attribute.

2026—24 Billion Records

Cybernews researchers uncovered an exposed Elasticsearch cluster in mid-2026 containing more than 24 billion records and over 8.3TB of data—mostly infostealer logs (usernames, emails, passwords, login URLs) aggregated from 36 sources, including Telegram channels and prior breach compilations. The scale required the researchers to triple-check their own findings before publishing.


Importance of Responsible Disclosure

Our goal is to help protect data on the Internet by identifying data leaks and following responsible disclosure policies. Our mission is to make the cyber world safer by educating businesses and communities worldwide on ethical vulnerability disclosure policy (VDP).


Danger of Open Elasticsearch Instances

We have previously reported that the lack of authentication allowed the installation of malware or ransomware on the Elasticsearch servers. The public configuration allows the possibility of cybercriminals managing the whole system with full administrative privileges. Once the malware is in place, criminals could remotely access the server resources and even launch a code execution to steal or destroy any saved data the server contains.


Share article:
More topics:

Read more on HackenProof Blog