Confidential terror watchlist exposed online

Networks
(Image credit: Shutterstock)

A misconfigured Elasticsearch cluster exposed sensitive personal details of two million individuals, included in what cybersecurity researchers believe to be a highly confidential database.

Volodymyr Diachenko, Head of Security Research at Comparitech, was responsible for the discovery of the records, which appear to form the basis of a terror watch list.  The database was left exposed online, without even password protection.

“The watchlist came from the Terrorist Screening Center, a multi-agency group administered by the FBI. The TSC maintains the country's no-fly list, which is a subset of the larger watchlist,” claims Diachenko

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Diachenko reported the find to the Department of Homeland Security (DHS), which thanked him for bringing it to its attention, but did not claim ownership of the exposed records. The data was accessible for a further three weeks, before the server it resided on was taken down.

Abandoned data?

Diachenko’s team routinely scans the web for misconfigured and easily accessible databases that contain personal information. When they find one, they try to determine its ownership, and then contact the entity that owns the database to implement proper protections. 

In the case of this particular exposed Elasticsearch cluster, Diachenko claims it contained 1.9 million records with each record listing various personally identifiable information (PII) and other sensitive details, such as an individual’s name, date of birth, citizenship, passport number, no-fly indicator and more.

The exposed server was indexed by the Censys and ZoomEye search engines, and could have been accessed by anyone in the three weeks it was available online.

The FBI did not immediately return TechRadar Pro's request for comment. 

Update: 10:00 ET / 15:00 BST
The FBI has confirmed it will not comment on the story at this time.

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
Data leak
German cloud service provider exposes entire Georgian country population - millions of personal data files leaked
healthcare
Over a million clinical records exposed in data breach
Data Breach
Thousands of healthcare records exposed online, including private patient information
A person using DeepSeek on their smartphone
DeepSeek security breach - critical databases exposed, more than one million records reportedly leaked
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired