Security

Welcome back from the holiday, Americans! Here's who leaked data while you were away

TrueDialog, Mixcloud, Magento Marketplace expose accounts


Thanksgiving is an ideal time to either hack (IT admins need holidays too) or to drop news of hacks (because no one's reading much news) so here's your roundup of the weekend's shenanigans.

In the past few days, researchers have disclosed breaches at mobile carrier TrueDialog, music streamer MixCloud, and Adobe's Magento Marketplace service. Millions of people are thought to be affected.

TrueDialog exposes "massive" activity database

The research team at VPNmentor took credit for the discovery and disclosure of a database owned by business comms provider TrueDialog. They report that the data of millions of users, including the content of SMS messages, was left out in the open after an Azure-hosted database was mistakenly set to public availability.

"This was a huge discovery, with a massive amount of private data exposed, including tens of millions of SMS text messages," reported the VPNmentor team.

"Aside from private text messages, our team discovered millions of account usernames and passwords, PII data of TrueDialog users and their customers, and much more."

TrueDialog provides SMS services to its customers, mostly businesses and educational institutions. The Texas-based company partners with phone carriers to offer things like alerts and large-scale marketing campaigns, as well as campus alerts and student admissions.

Those are the sort of SMS communications that were exposed, along with account details (email addresses, passwords in either plaintext or base64,) and contact information. VPNmentor says that, in total, the exposed database was 604GB in size and included data on tens of millions of people.

"It’s difficult to put the size of this data leak into context. Tens of millions of people were potentially exposed in a number of ways," the report reads.

"It’s rare for one database to contain such a huge volume of information that’s also incredibly varied."

TrueDialog confirmed the incident to The Register and said that while it is still investigating, currently it is believed that VPNmentor's team were the only people to spot the database before it was pulled from the public.

"We were notified on Thursday that for a short period text message logs between our business customers and individuals were potentially accessible on one of our Azure servers," CEO John Wright told El Reg.

"The data was located at a non-published network port which is now secured. We have internally found no evidence that the data was downloaded or viewed by anyone other than the security analyst who notified our company that the data was potentially accessible."

MixCloud punter profiles put up for sale

UK music streaming service MixCloud is said to be investigating after it was reported that the details on 21 million users are being flagged for sale on the dark web.

Just what could be done with this pilfered data (usernames, email addresses, hashed passwords) isn't quite clear. The passwords are said to have been securely encoded, and no payment data is included.

Still, those who have a Mixcloud account will want to change up their password and if those credentials were re-used on other sites (don't do this) those logins should also be updated.

Adobe warns of Magento Marketplace breach

Recently, Adobe began notifying developers on its Magento Marketplace plug-in store that someone had managed to break into a system containing account details, but no payment card information.

Russian bloke charged in US with running $20 million stolen card-as-a-service online souk

READ MORE

"On November 21, we became aware of a vulnerability related to Magento Marketplace. We temporarily took down the Magento Marketplace in order to address the issue," Magento said in announcing the incident.

"The Marketplace is back online. This issue did not affect the operation of any Magento core products or services."

The exposed data included name email address, account name, billing/shipping address, and, in some cases, the percentage of plug-in sales that Magento had paid out to third-party developers. ®

Send us news
2 Comments

Adobe will fork over cash for clips to train text-to-video AI

Not touching copyrighted material with a barge pole

Microsoft squashes SmartScreen security bypass bug exploited in the wild

Plus: Adobe, SAP, Fortinet, VMware, Cisco issue pressing updates

Canva acquires Affinity, further wounding a regulator-bruised Adobe

Yet another reason to reconsider that overpriced Creative Cloud subscription

March Patch Tuesday sees Hyper-V join the guest-host escape club

Critical bugs galore among 61 Microsoft fixes, 56 from Adobe, a dozen from SAP, and a fistful from Fortinet

Adobe has 'no plans' to invest in XD despite failed Figma buy

Oh the bitter irony – now Figma can enjoy a monopoly in UX niche, say devs

Crims found and exploited these two Microsoft bugs before Redmond fixed 'em

SAP, Adobe, Intel, AMD also issue fixes as well as Google for Android

Adobe ditches $20B Figma takeover under pressure from monopoly cops

Now Photoshop giant needs to cough up that $1B break-up fee

New year, new updates for security holes in Windows, Adobe, Android and more

Nothing under exploit… The calm before the storm?

Adobe warns it may face massive fines for subscription cancellation practices

Otherwise in rude health after posting best-ever results

Former Adobe software engineering leader convicted of insider trading

Another Silicon Valley Icarus flies too close to the Sun

Europe says Adobe's $20B buy of Figma will kill competition

Software duo must respond with remedies – plus: closing deal in '23 likely a Figma of their imagination

Adobe's buy of Figma is 'likely' bad for developers, rules UK regulator

Competition Markets Authority claims merger will reduce innovation for designers and other creative types