Top Android real estate app leaks half a million user passwords online

VPN Tunnel
Image Credit: Pixabay (Image credit: voyager624 / Shutterstock)

A mobile real estate app with roughly half a million users was apparently holding sensitive user data in an unprotected database, freely available for all who knew where to look. 

The data held there contained enough information for hackers to mount identity theft attacks, phishing, and other social engineering fraud. 

Researchers at Cybernews, who discovered the database in early November 2023, uncovering that the MyEstatePoint Property Search had a publicly accessible MongoDB app, containing users’ names and passwords in plain text. Furthermore, the database contained people’s email addresses, mobile phones, cities, business descriptors, and signup methods.

Recycling passwords

“This comprehensive dataset poses severe risks as threat actors could exploit the exposed information for unauthorized access, identity theft, fraudulent activities, and potentially compromise the privacy and security of the affected individuals,” the team said. 

The app was developed by an Indian-based software developer called NJ Technologies. Upon discovery, the researchers reached out to the team, but got no feedback - although the database was subsequently locked down.

Most of the users are Indian, the researchers further added. While locking the database is a welcome step, there are still risks involved. First, we don’t know if any threat actors accessed the database beforehand, and if they did - what did they do with the information found there? It is common knowledge that many people often use the same username/password combination on multiple services, for convenience. In that case, threat actors could use the information obtained via MyEstatePoint Property Search to compromise other services, too. 

By automating the process in a brute-force attack, the threat actors could test the usernames and passwords across a myriad of services quickly and efficiently. Users are generally advised not to use the same passwords for multiple services, and to make sure their login credentials are impossible to guess.

TechRadar Pro has contacted MyEstatePoint for comment.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Data leak
Top collectibles site leaks personal data of nearly a million users
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
Stalkerware
New spyware found to be snooping on thousands of Android and iOS users
Data leak
Popular online bill paying site leaks data of thousands of users
Data Breach
Thousands of healthcare records exposed online, including private patient information
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does