Top global network service provider apparently leaks hundreds of millions of user accounts

An abstract image of a cloud raining data.
(Image credit: Pixabay)

A top global network service provider kept a database with sensitive internal and customer information unlocked on the internet, available to anyone who knew where to look. 

The breach was discovered by cybersecurity researcher Jeremiah Fowler, who reported it to its operator, who subsequently locked it down.

The company in question is Zenlayer, a global network services provider with more than 290 data centers across the world, and offices in Mumbai, Singapore, Hong Kong, and elsewhere.

Valuable data for hackers

Fowler found a non-password protected database with 380 million records, including Zenlayer internal data and customer information. The database, Fowler says, contained a “considerable number” of server, error, and monitoring logs, “that detailed internal information and customer data”.

Among the database’s files were folders with logging records labeled as “application”, “dashboard”, “vendor”, “notification”, “messaging”, “project management”, “workflow”, and “security”.

In one instance, Fowler found a name of a person that might be a dedicated salesperson within Zenlayer, assigned to specific accounts. In another, he found customer records of a company “described as a leading provider of international capacity for telecom carriers in Russia”. He also saw registration and filing documents which suggested the company was owned, in part, by a Russian state-controlled entity that was sanctioned by the West.

He also saw logs indicating VPN records and numerous IP addresses which, Fowler speculates, could be used by threat actors to map the network, identify potential targets, and plan for a future cyberattack.

While Zenlayer locked the database down as soon as Fowler reached out, the company never got back to him with any details. At press time, we didn’t know just how long the database went unprotected, or if anyone, potentially a malicious player, accessed it before. We also don’t know how many people, or organizations, could be affected by this misconfiguration. We have reached out to Zenlayer with a few questions and will update the article if we get a reply.

February 15, 2024 - Shortly after publishing the article, a Zenlayer spokesperson replied with the following statement:

"We’re aware of the data exposure, have patched the issue, and are engaged with the researcher that originally discovered the data leak. We’ll provide additional information when the investigation is complete."

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
No broadband network
Massive online data breach sees 2.7 billion records leaked - here's what we know
Data leak
Top healthcare company exposes data on millions of patients - find out if you're affected
Data leak
Popular online bill paying site leaks data of thousands of users
Data leak
AI development service Builder.ai potentially exposed over 1TB of user data
Businessman holding a magnifier and searching for a hacker within a business team.
Top Mexican fintech firm leaks details on 1.6 million customers
Latest in Security
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
BadBox malware hit after infecting over 500,000 Android devices
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
Latest in News
Fujfilm GFX 50R
First Fujifilm GFX100RF images leaked in build-up to expected reveal – here’s what they tell us about the unique premium compact camera
Samsung Galaxy Z Flip 6 in blue
The Samsung Galaxy Z Flip 7 could have a Motorola Razr-style full-sized cover screen – and I think it’s about time
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
Last-minute AMD RX 9070 XT stock rumors are making me hopeful for a much better launch than Nvidia’s RTX 5000 GPUs – with just one snag
eSIM
Global eSIM shipment volume surpasses half a billion units as demand keeps on growing
Samsung Galaxy Buds in white
Samsung may be working on new cheap wireless earbuds – will the Galaxy Buds FE 2 beat Sony's next value earbuds to the punch?
PS5 Pro feature
PlayStation Direct now lets you rent, yes rent, a PS5 from £11.99 a month