Petabytes of data are being left exposed online

Best cloud databases
(Image credit: Pixabay)

Security researchers from CyberNews have discovered more than 29,000 unsecured databases worldwide that are exposing over 19 petabytes (19,000 TB) of data online.

To conduct its latest investigation, the news outlet used a specialized search engine capable of scanning for open Hadoop, MongoDB and Elasticsearch databases. It's worth noting though that CyberNews didn't count any databases with default credentials enabled, so the number of unprotected databases online is actually significantly higher.

Of the databases discovered in CyberNews' search, Hadoop instances exposed the most data with almost 19PB easily accessible to cybercriminals or anyone for that matter followed by Elasticsearch with 143.8TB and MongoDB with just 6.5TB. However, when it comes to the number of exposed databases, Elasticsearch took the top spot with 19,814 instances without any kind of authentication in place.

In terms of which countries have the most exposed databases, China tops the list with 12,943 instances overall while the US comes in second with 4,512 instances followed by Germany with just 1,479 unprotected instances.

Exposed databases

Last year an unknown group of cybercriminals launched a series of attacks on unsecured databases without any explanation or even a ransom demand. These so-called 'meow attacks' wiped all of the data stored on these servers and left database owners with just an empty folder filled with files named 'meow'.

Surprisingly during its recent investigation, CyberNews found 59 databases that were still not protected even after they were hit by meow attacks last year. Security researcher at the news outlet Mantas Sasnauskas provided further insight on the importance of properly securing online databases in a new report, saying:

“Anyone can look for these unprotected clusters by using IoT search engines to effortlessly identify those that don’t have authentication enabled and exploit them by stealing the data, holding them ransom, or, as was the case with the ‘Meow’ attack, simply destroy valuable information for fun, wiping billions of records and crippling both business and personal projects in the process.” 

Database owners can prevent their data from being stolen by enabling authentication, enabling encryption or using a VPN and by keeping their database software up to date. Once authentication is enabled, they should also protect their database with a complex and unique password which can be done by either using a password generator or a password manager.

Via CyberNews

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
healthcare
Over a million clinical records exposed in data breach
Data Breach
Thousands of healthcare records exposed online, including private patient information
No broadband network
Massive online data breach sees 2.7 billion records leaked - here's what we know
Data leak
Popular online bill paying site leaks data of thousands of users
Data leak
Top collectibles site leaks personal data of nearly a million users
Latest in Pro
Someone looking at a marketing graph
Why ‘boring’ tech will be 2025's biggest marketing trend
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Latest in News
Citroen 2CV
The retro EV resurgence is in full swing, as Citroen confirms the iconic 2CV will return with batteries
Hugging Snap
This AI app claims it can see what I'm looking at – which it mostly can
Apple iPhone 16 Pro Max REVIEW
The latest batch of leaked iPhone 17 dummy units appear to show where glass meets metal on the new designs
Hornet swings their weapon in mid air
Hollow Knight: Silksong could potentially launch this year and I reckon it could be a great game for an Xbox handheld
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Cassian looking at someone off-camera from a TIE fighter cockpit in Andor season 2
Star Wars: Andor creator is taking a stance against AI by canceling plans to release its scripts, and I completely get why