One of the largest data leaks ever sees info on 1.5 billion people leaked online

Cartoon Phishing
(Image credit: Shutterstock / DRogatnev)

  • 1.5 billion exposed records have been discovered by researchers
  • Records are primarily from Chinese social media and ecommerce platforms
  • Victims are at risk of identity theft and social engineering attacks

Researchers from CyberNews have discovered an unprotected server with ‘hundreds of millions’ of records, including brands from major brands such as Weibo and DiDi, amongst many others - with the total number of comprimised records potentially numbering 1.5 billion.

The compromised data included Personally Identifiable Information (PII) such as full names, email addresses, financial information, healthcare records, and phone numbers. The largest set of information was credited to QQ messenger, and the second largest was 504 million records credited to social media giant Weibo - although it's likely these were from previous leaks.

The largest dataset with no known previous major leaks was from JD.com (Jingdong), a Chinese ecommerce firm, with the researchers discovering a staggering 142 million JD.com records in the instance.

No clear indication of ownership

Whilst some data was seemingly exposed in previous data leaks, much of the information was ‘undoubtedly’ compromised for the first time in this incident. This dataset is most likely a mix of known exposed information, and newly leaked data that was all collated into one (now closed) Elasticsearch server.

According to researchers, the server was exposed for ‘several months’ but was closed following multiple disclosure notices.

The exposed instance shows ‘no clear indication of its true ownership’, which researchers point out suggests there may be malicious intent behind the collation of such a ‘large and diverse’ dataset.

A wide dataset gives threat actors a broad scope to carry out targeted attacks like account hacking, sophisticated social engineering attacks, and identity theft.

Although the scale of the incident is enormous, it is potentially only the second data breach of this scale in recent memory, showing the need for greater protection for businesses everywhere.

You might also like

Ellen Jennings-Trace
Staff Writer

Ellen has been writing for almost four years, with a focus on post-COVID policy whilst studying for BA Politics and International Relations at the University of Cardiff, followed by an MA in Political Communication. Before joining TechRadar Pro as a Junior Writer, she worked for Future Publishing’s MVC content team, working with merchants and retailers to upload content.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
No broadband network
Massive online data breach sees 2.7 billion records leaked - here's what we know
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Data leak
Top collectibles site leaks personal data of nearly a million users
healthcare
Over a million clinical records exposed in data breach
Security padlock and circuit board to protect data
Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk
Suitcase next to a bed in a hotel
Millions of hotel users see personal info checked out in huge data leak
Latest in Security
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Oracle
Oracle denies data breach after hacker claims to hold six million records
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
Latest in News
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what's happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard