An Amazon Prime Video server packed with viewer data was exposed online

Data Breach
Image Credit: Shutterstock (Image credit: Shutterstock)

Another day, another misconfigured database leaking sensitive customer data to the wider internet. 

This time around, the perpetrator is none other than Amazon, as according to TechCrunch, cybersecurity researcher Anurag Sen recently discovered a major Amazon database, no password protection whatsoever, available to anyone who knew where to look. 

With the help of Shodan - a search engine for internet-connected things, Sen discovered the database, named Sauron, and found it full of Amazon Prime viewing habits.

Deployment error

In total, the database held some 215 million entries of pseudonymized viewing data - meaning while there’s plenty of data on specific customers to learn about their viewing habits, it’s virtually impossible to connect those accounts with actual identities. Sauron contains things such as movie/series name, the device used to stream the content, network quality, customer subscription plan, etc. 

The database was reportedly first detected to be exposed in late September 2022, after which Amazon was tipped off, and removed the system from the wider web.

“There was a deployment error with a Prime Video analytics server. This problem has been resolved and no account information (including login or payment details) were exposed. This was not an AWS issue; AWS is secure by default and performed as designed,” TechCrunch cited Amazon spokesperson Adam Montgomery.

Cloud misconfigurations are nothing new, and researchers have been warning for years that this man-made error is a major cause for data breaches. In fact, a 2021 IBM report claimed 19% of data breaches happen because IT teams fail to properly protect the assets found within their cloud infrastructure. The company polled more than 500 organizations that suffered a data breach for the report, and learned that for half (52%), securing data stored in the public cloud remained a challenge. 

Furthermore, an Accurics report from 2020 claimed “nearly all” cloud storage deployments were misconfigured.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Data leak
AWS customers hit by major cyberattack which then stored stolen credentials in plain sight
Someone checking their credit card details online.
Millions of credit card details leaked online - watch out if you're paying for Christmas
Data leak
Popular online bill paying site leaks data of thousands of users
Stress
Time tracker tool spilled details on remote workers - millions of screenshots leaked
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Latest in Software & Services
Windows 11 Start menu layout choices: Grid view
Windows 11 vs Linux for business: which operating system should you embrace?
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
Gmail vs Outlook for business: which email system is right for your organization?
Windows 11 logo
Windows 11 Pro vs Windows 11 Home: which version is right for you?
Canva HubSpot
HubSpot and Canva team up to level the creative playing field
a laptop computer
Windows 11 vs ChromeOS for business: Is one better than the other for your needs?
a laptop computer
Windows 11 vs macOS for business: which side are you on?
Latest in News
A collage of Ellie and Joel in The Last of Us season 2
The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro Pascal's Joel, but the big moment I'm waiting for is still being held back
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Gaming with AI
I asked Gemini to play a text-based adventure game with me and the AI whisked me away to a word-based fantasy
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 10 (game #1141)