{"id":15694,"date":"2020-09-14T10:56:27","date_gmt":"2020-09-14T08:56:27","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=15694"},"modified":"2020-09-14T10:56:27","modified_gmt":"2020-09-14T08:56:27","slug":"mailfire-datenleck-legt-daten-von-erwachsenenseiten-offen","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/09\/14\/mailfire-datenleck-legt-daten-von-erwachsenenseiten-offen\/","title":{"rendered":"Mailfire data leak reveals data from adult sites"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">[<a href=\"https:\/\/www.borncity.com\/blog\/2020\/09\/14\/mailfire-datenleck-legt-daten-von-erwachsenenseiten-offen\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]There is once again a data leak to report, but it is likely to be minor for those affected &#8211; because security researchers have discovered the data leak. The marketing company Mailfire acting on Cyprus revealed data of over 70 eCommerce and adult sides.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg06.met.vgwort.de\/na\/b4a4deb2b8c14f338a39d7f296480b23\" width=\"1\" height=\"1\">Security researchers from vpnmentor informed me about <a href=\"https:\/\/www.vpnmentor.com\/blog\/report-mailfire-leak\/\" target=\"_blank\" rel=\"noopener noreferrer\">their new discovered<\/a>. It concerns Mailfire, an email marketing platform and company used by various customers. The data leak revealed customer data from the sites in question. The provider has a larger customer base (see the following screenshot).&nbsp; <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"Mailfire affiliates\" alt=\"Mailfire affiliates\" src=\"https:\/\/www.vpnmentor.com\/wp-content\/uploads\/2020\/09\/mailfire_report_affiliates.png\" width=\"622\" height=\"241\"><\/p>\n<p><em>Screenshot Mailfire homepage \u2013 Sep 3, 2020<\/em>  <\/p>\n<p>According to Catalin Cimpanu, a cyber security expert who was provided with the vpnmentor report in advance, among the affected dating sites were Kismia, JollyRomance, Asia Charm and many others. <\/p>\n<h2>The Mailfire Data Leak<\/h2>\n<p>On an unsecured ElasticSearch server were logs of notifications sent by site owners to their users via Mailfire's user software. The primary purpose of the notifications was to inform users of the dating sites of new potential matches. At the beginning of the investigation, the data leak included 882.1 GB (approximately 320 million records) of data from the last four days, including personal user information such as full names, age, date of birth, gender, email addresses and many others, as well as private messages. These included:<\/p>\n<ul>\n<li>Full names\n<li>Age and date of birth\n<li>Gender\n<li>E-mail addresses\n<li>User locations\n<li>IP addresses\n<li>Profile pictures uploaded by users\n<li>Profile Organic Descriptions<\/li>\n<\/ul>\n<p>In addition to this personal information, the data leak also included messages exchanged between users on affected dating sites. During the investigation, vpnmentor security researchers found that some of these adult dating sites appeared to be fraudulent. The intention was probably to bait potential customers with fake profiles. Here is the timeline: <\/p>\n<ul>\n<li>Data leak discovered: August 31, 2020\n<li>Reply received from Mailfire: September 3, 2020\n<li>Server secured: September 3, 2020\n<li>Customer company informed: September 4, 2020<\/li>\n<\/ul>\n<p>If such personal data falls into the wrong hands, it potentially opens the door to phishers and fraudsters. The case is likely to be relevant to the DSGVO, as Mailfire is based in Cyprus and operates worldwide. Further details can be found in the <a href=\"https:\/\/www.vpnmentor.com\/blog\/report-mailfire-leak\/\" target=\"_blank\" rel=\"noopener noreferrer\">vpnmentor report<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]There is once again a data leak to report, but it is likely to be minor for those affected &#8211; because security researchers have discovered the data leak. The marketing company Mailfire acting on Cyprus revealed data of over 70 &hellip; <a href=\"https:\/\/borncity.com\/win\/2020\/09\/14\/mailfire-datenleck-legt-daten-von-erwachsenenseiten-offen\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[1166,69],"class_list":["post-15694","post","type-post","status-publish","format-standard","hentry","category-security","tag-data-leak","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/15694","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=15694"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/15694\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=15694"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=15694"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=15694"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}