Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Machine Studying Practitioner’s Information to Agentic AI Methods

    October 21, 2025

    Pinterest Provides Customers the Energy to “Flip Down the AI” — However Not Fully

    October 21, 2025

    CISOs’ safety priorities reveal an augmented cyber agenda

    October 21, 2025
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»Elasticsearch Leak Exposes 6 Billion Information from Scraping, Previous and New Breaches
    AI Ethics & Regulation

    Elasticsearch Leak Exposes 6 Billion Information from Scraping, Previous and New Breaches

    Declan MurphyBy Declan MurphyOctober 21, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Elasticsearch Leak Exposes 6 Billion Information from Scraping, Previous and New Breaches
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    A misconfigured Elasticsearch server holding 1.12 terabytes of knowledge was leaking greater than 6 billion data to public entry with none safety authentication or password. The server, apparently operated from Russia or a Russian-speaking nation, contained detailed data collected via knowledge breaches, web site scraping and different sources earlier than it was taken offline.

    This was revealed solely to Hackread.com by unbiased cybersecurity researcher Anurag Sen, who initially noticed the uncovered server. It stays unclear how lengthy the information was uncovered.

    The screenshot under reveals particulars of the uncovered Elasticsearch server. The server’s index data revealed a complete dimension of 1.12 terabytes containing over 6.19 billion data, confirming the dimensions of the information publicity. Delicate server identifiers have been redacted for safety causes.

    Credit score: Hackread.com by way of Anurag Sen)

    What’s Within the Information

    Though restricted particulars can be found, one of many screenshots from the uncovered server confirmed data from a Ukrainian financial institution referred to as Accordbank, formally referred to as “Industrial Financial institution Accordbank.” Inside, the researcher discovered a trove of banking, contact, and personally identifiable data (PII) of customers saved in JSON format, together with:

    1. Full names
    2. Telephone numbers
    3. Date and homeland
    4. Nationwide ID quantity or tax code
    5. Passport numbers and issuing authority
    6. Deal with (together with metropolis and road particulars.

    (Be aware: Since different databases are concerned, there’s a probability they might include further knowledge, together with passwords.)

    Here’s a screenshot displaying the construction of the uncovered data linked to Accordbank. The unique picture is proven together with its English translation (by way of Yandex Picture Translator) for higher understanding:

    Elasticsearch Server Exposed 6 Billion Records Before Shutdown
    Screenshot immediately from the uncovered server (Credit score: Hackread.com by way of Anurag Sen)

    Moreover, the uncovered server additionally listed databases and consumer particulars gathered from each introduced and unannounced knowledge breaches, together with data extracted via web site scraping. This was confirmed by the researcher who examined the server earlier than it was taken offline, though screenshots of these particular datasets couldn’t be obtained in time.

    Cybercriminals Leaking Their Personal Server?

    This can be a case of cybercriminals by chance exposing their very own knowledge after which securing it as soon as they realised their mistake. Nevertheless, this isn’t the primary time such an incident has occurred.

    In December 2024, as reported by Hackread.com, researchers discovered a misconfigured AWS S3 bucket believed to belong to the hacker teams ShinyHunters and Nemesis, who have been allegedly working collectively on the time. The bucket contained stolen knowledge, hacking instruments, and even potential details about the hackers themselves, which was later reported to the AWS fraud crew.

    Server Might Have Been Accessed by Different Cybercriminals

    Whereas Sen couldn’t verify whether or not the misconfigured server was accessed by a 3rd celebration with malicious intent, Hackread.com’s personal analysis suggests potential indicators {that a} server owned by cybercriminals might have been accessed by different cybercriminals.

    Through the investigation, Hackread.com discovered a thread on DarkForums, the successor to the now-defunct Breach Boards, the place a consumer going by the alias “tRex_Prime” was providing knowledge data unfold throughout greater than 6,000 CSV recordsdata. The thread was titled “6k+ CSV Leak Database,” detailing 2,356 recordsdata with names. Every CSV file was labelled with both an organization identify or a tag indicating what the information belonged to.

    Among the many listed recordsdata was one named Accordbank (accordbank.com.ua.csv). Since there are not any public reviews linking Accordbank to any earlier knowledge breaches, it’s cheap to imagine that these 6,000+ CSV recordsdata have been extracted from the misconfigured Elasticsearch server containing 1.12 terabytes of knowledge.

    Elasticsearch Server Exposed 6 Billion Records Before Shutdown
    Information being bought by the menace actor (Picture credit score: Hackread.com)

    Hackread.com tried to contact “tRex_Prime,” however their Telegram account was unavailable on the time of writing, and their discussion board profile had been banned for “promoting public databases.“ The listing of two,356 recordsdata is obtainable right here (PDF).

    What Customers Ought to Do

    Sadly, Hackread.com can’t verify all the businesses or people whose knowledge might have been included among the many 6 billion data. Nevertheless, the most secure method is to observe your e mail accounts, keep away from clicking on hyperlinks or downloading attachments from unknown senders, and ignore suspicious messages despatched to your telephone.

    Within the coming days, in case you hear a couple of knowledge breach involving Accordbank, this publicity might clarify its potential origin. Accordbank customers are subsequently urged to take additional warning, contact the financial institution, and inquire about any potential breach of privateness or private knowledge.



    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    CISOs’ safety priorities reveal an augmented cyber agenda

    October 21, 2025

    5 New Exploited Bugs Land in CISA’s Catalog — Oracle and Microsoft Amongst Targets

    October 20, 2025

    131 Malicious Chrome Extensions Found Focusing on WhatsApp Customers – GBHackers Safety

    October 20, 2025
    Top Posts

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025

    Meta resumes AI coaching utilizing EU person knowledge

    April 18, 2025
    Don't Miss

    The Machine Studying Practitioner’s Information to Agentic AI Methods

    By Yasmin BhattiOctober 21, 2025

    On this article, you’ll find out how practitioners can evolve from conventional machine studying workflows…

    Pinterest Provides Customers the Energy to “Flip Down the AI” — However Not Fully

    October 21, 2025

    CISOs’ safety priorities reveal an augmented cyber agenda

    October 21, 2025

    Suppose you awoke ChatGPT’s consciousness or sentience? Right here’s what to do.

    October 21, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2025 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.