Abstract:The leaked data also included unredacted credit cards and passports of millions of users around the world.
The team of security researchers at WizCase led by Ata Hakcil discovered a massive trove of data belonging to FBS, a prominent online trading broker with offices in Belize and Cyprus.
FBS is home to 16 million traders and 400,000 partners from over 190 countries.
According to researchers, FBS exposed almost 20 terabytes worth of data comprising over 16 billion records. As a result, millions of FBS customers had their personal and sensitive information accessible online.
It is worth noting that the data was left open to public access on an Elasticsearch server without any security authentication. This means that anyone with knowledge of unsecured databases could have downloaded the data with no password required.
The data, that was thoroughly analyzed by the WizCase team included:
Country
Addresses
Full names
IP addresses
Email addresses
Phone numbers
Passport numbers
Operating system
Mobile device models
Emails sent to FBS users
Social media IDs including Facebook and Google
Whats worse is that the company also exposed files sent by users for account verification or identity confirmation. This included the following:
Personal photos
Drivers licenses
Birth certificates
Bank statements
National ID cards
Unredacted credit cards
The fact that FBS uploaded unredacted credit cards on a web server and left them exposed for public access could have a devastating impact on unsuspecting users including empty bank account, identity theft, extortion, and blackmailing scams to name a few.
However, the list of exposed data does not end here. In their blog post, Chase Williams of WizCase wrote that FBS also exposed its users IDs, their login history, unencrypted passwords encoded in base64, links to reset the password, and other sensitive information.
Disclaimer:
The views in this article only represent the author's personal views, and do not constitute investment advice on this platform. This platform does not guarantee the accuracy, completeness and timeliness of the information in the article, and will not be liable for any loss caused by the use of or reliance on the information in the article.
The SEC cautions the public about TRADE 13.0 SERAX, an unlicensed investment platform using fake endorsements that solicits funds illegally in the Philippines.
eToro, the online brokerage platform, has unveiled its latest innovation: the Onfido Selfie Motion biometric authentication feature.
Fintech start-up Midas has achieved a significant milestone by raising $45 million in equity funding, marking the largest Series A fundraising by a Turkish fintech firm, and the second largest across sectors.
eToro collaborates with 21Shares to introduce a dynamic, data-driven crypto investment portfolio for retail investors.