Data leak

CAM4 Elasticsearch Misconfiguration (10.88 Billion Records, Sexual Orientation Data)

πŸ“… 2020-03-16 🏒 Elasticsearch
Primary Source β†—

Incident Details

On March 16, 2020, researchers at Safety Detectives discovered a production Elasticsearch logging database belonging to CAM4 (an adult live-streaming platform operated by Granity Entertainment, based in Ireland) that was publicly accessible without any authentication. The exposed database contained approximately 10.88 billion records β€” making it one of the largest data exposures ever discovered by sheer record volume, though many were duplicate log entries. Exposed data included email addresses, usernames, passwords (hashed), payment logs and partial transaction details, IP addresses, country of origin, device and browser information, private chat transcripts between users, and β€” critically β€” sexual orientation data inferred from content preferences and explicit user profile fields. The combination of sexual orientation, identity, and contact information created serious blackmail and outing risks for users. An estimated 6.6 million records belonged to US users, 5.4 million to Brazilian users, 4.9 million to Italian users. Safety Detectives responsibly disclosed the exposure to CAM4, which secured the database within hours of notification. Ireland’s Data Protection Commission was notified as CAM4 operates under EU/GDPR jurisdiction. No confirmed malicious access was identified, but given the sensitive nature of the data, the potential for harm was severe. The incident highlighted the particular risk when misconfigured databases expose sensitive behavioral and sexual orientation data.

Technical Details

Initial Attack Vector
Misconfigured Elasticsearch production logging database left publicly accessible on the internet without authentication; no malicious actor required β€” the data was fully open to anyone who found the server
Vendor / Product
Elasticsearch
Software Package
Elasticsearch

Timeline

  1. 2020-03-16 Breach occurred
  2. 2020-03-16 Publicly disclosed
  3. 2020-03-16 Customers notified