Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Data analytics agency Polecat held to ransom after server exposed 30TB of records
#1
Quote:An unsecured server belonging to a data analytics company [color=var(--theme-link_a)]exposed an estimated 30TB of business records online, resulting in the firm being held to ransom.[/color]
 
Polecat is a UK-based agency that offers “a combination of advanced data analytics and human expertise, [to help] the world’s largest organizations achieve reputation, risk, and ESG (environmental, social, and governance) management success”.
 
On October 29, 2020, the[color=var(--theme-link_a)] Wizcase CyberResearch Team, led by Ata Hakcil, discovered that an Elasticsearch [color=var(--theme-link_a)]server[/color] owned by Polecat was exposing roughly 30TB of data on the web without any authentication required to access records, or any form of encryption in place.[/color]
 
Wizcase found records dating back to 2007, including employee usernames and hashed passwords, over 6.5 billion tweets, [color=var(--theme-link_a)]social media records, and over one billion posts gathered from different blogs and websites.[/color]
 
Chase Williams of the company's cyber research team detailed his findings in a [color=var(--theme-link_a)]blog post published today (March 1).[/color]
Meow attack
The public information gathered by Polecat is harvested on a daily basis and tends to relate to subjects such as Covid-19, firearms, politicians, racism, and healthcare.
 
Polecat was notified of the data exposure by Wizcase on October 30 and November 1. However, it can take mere moments for an open server or bucket to be detected and [color=var(--theme-link_a)]abused by threat actors – and this happened a day after the researcher’s discovery.[/color]
 
On October 30, a [color=var(--theme-link_a)]Meow attack was launched against the database. Meow attacks replace database indexes with the suffix ‘gg-meow’, leading to the destruction of swathes of data.[/color]
 
Wizcase says that approximately half of the firm’s records were wiped, and then in a second wave a further few terabytes of information were deleted.
 
At this point, roughly 4TB remained in the server. Most of these records were then destroyed and a [color=var(--theme-link_a)]ransom note was spotted by the researchers that demanded 0.04 Bitcoin (BTC) – roughly $550 at the time – in return for the files’ recovery.[/color]
 
“It’s important to note that these types of scams/ransoms are usually automated and sent to many open databases,” Wizcase noted.
 
While the information exposed was public, it could have been downloaded for sale to competitors, and could therefore directly impact Polecat’s business.
 
Polecat responded to Wizcase’s report on November 2, and secured the server on the same day.
 
The Daily Swig has reached out to Polecat and will update when we hear back.

Source
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Over 60 million wearable, fitness tracking records exposed via unsecured database mrtrout 0 718 09-15-2021 , 03:24 AM
Last Post: mrtrout
  38 million records exposed because companies used default configs in Microsoft Power mrtrout 0 740 08-23-2021 , 08:47 PM
Last Post: mrtrout
  Australian Organizations Spent $55 Million in Ransom Payments mrtrout 0 841 07-17-2021 , 06:55 AM
Last Post: mrtrout
  Android apps exposed data of millions of users through cloud authentication failure mrtrout 0 1,275 05-21-2021 , 12:58 AM
Last Post: mrtrout
  How to check if your info was exposed in the Facebook data leak tarekma7 0 1,104 04-06-2021 , 09:18 AM
Last Post: tarekma7



Users browsing this thread: 1 Guest(s)