JusTalk has been leaking user info for months

Inside Facebook data center
(Image credit: Facebook)

A major chat log database belonging to popular messaging app JusTalk was left unprotected on the web for months, accessible to anyone who knew where to look. 

Cybersecurity researcher Anurag Sen uncovered the database, which did not have a password, storing unencrypted data including plenty of personally identifiable information, useful for cybercriminals looking to engage in identity theft, social engineering, or other forms of cybercrime. 

The data included the messages themselves, user phone numbers (both sender and receiver), call logs, all sorted out just enough to be able to identify specific people and specific conversations.

Millions of potential victims

In fact, while going through the logs, TechCrunch says it managed to find a pastor soliciting a sex worker who listed their phone number publicly. The log included the time, location, and price of the meeting. 

The database itself is “hundreds of gigabytes” large, and hosted on a Huawei server in China. In order to access it, the only thing a person would need is a browser, and its IP address. With the help of database search engine Shodan, the researcher discovered that the server was storing new data in the database as early as January this year, when it was first exposed.

It’s impossible to know exactly how many people have had their sensitive data exposed in this blunder, but we do know that JusTalk has roughly 20 million users. It also has JusTalk Kids, a separate app for minors, with more than a million downloads on Android. 

After Sen reported the problem to JusTalk, it apparently shut down the database, but also decided not to comment on the findings. 

Sen was also apparently not the first to discover this database, as it contained a ransom note, meaning someone had tried to use it to extort money from the company, but whether or not they succeeded is unknown at this time.

Via: TechCrunch

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
A person using DeepSeek on their smartphone
DeepSeek security breach - critical databases exposed, more than one million records reportedly leaked
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
A graphic showing fleet tracking locations over a city.
Disability monitoring tool leaked personal information online
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
This widely-used instant loan app leaks nearly 30 million files of user data
Data leak
Popular online bill paying site leaks data of thousands of users
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space