Lionsgate streaming platform leaks data of 37 million users

Data Breach
Image Credit: Shutterstock (Image credit: Shutterstock)

Video streaming platform Lionsgate Play exposed sensitive data on millions of its users, cybersecurity researchers from Cybernews found.

The website's team found Lionsgate's platform kept an unprotected ElasticSearch instance, containing 20GB of server logs with roughly 30 million entries. Some of the data dates back to May 2022, and included user IP addresses as well as information on user devices, operating systems, and web browsers. 

While this is not exactly personally identifiable information, it can still be used by threat actors to conduct intrusions, the researchers said.

Possible authentication secrets

“It can be useful in targeted attacks, especially when combined with other leaked or publicly available information,” Cybernews’ team said in its report.

By knowing the IP addresses, the attackers can deliver custom-built malicious payloads to the targets, they added.

But this is not the only data that was leaked via ElasticSearch. Usage data, such as content titles, IDs, and search queries, were also leaked. This data is usually used by analysts to track the platform’s and content’s performance. Furthermore, researchers discovered unidentified hashes with logged HTTP GET requests, which are user-made requests for data, stored on the server.

While the researchers couldn’t say what the hashes are used for, they did say they contain more than 156 characters, meaning they were supposed to stay unchanged for long. 

“Hashes didn’t match any commonly used hashing algorithms. Since these hashes were included in the HTTP requests, we believe they could have been used as secrets for authentication, or just user IDs,” said researchers.

When reached out to by the researchers, Lionsgate responded by closing the open instance. However, an official statement is yet to be made. 

Streaming platforms are popular targets among cybercriminals. Before Lionsgate Play, hackers managed to breach Plex, START, and Carbon TV.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Security padlock and circuit board to protect data
A major US TV broadcaster leaked over a million sensitive files online
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Data leak
Popular online bill paying site leaks data of thousands of users
Data leak
This top security camera streaming app may have been putting thousands of users at risk
No broadband network
Massive online data breach sees 2.7 billion records leaked - here's what we know
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Latest in Software & Services
Windows 11 Start menu layout choices: Grid view
Windows 11 vs Linux for business: which operating system should you embrace?
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
Gmail vs Outlook for business: which email system is right for your organization?
Windows 11 logo
Windows 11 Pro vs Windows 11 Home: which version is right for you?
Canva HubSpot
HubSpot and Canva team up to level the creative playing field
a laptop computer
Windows 11 vs ChromeOS for business: Is one better than the other for your needs?
a laptop computer
Windows 11 vs macOS for business: which side are you on?
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day