πŸ‡ΊπŸ‡¦ Hacken was born in Ukraine, and we stand with all Ukrainians in our fight for freedom!

πŸ‡ΊπŸ‡¦ Hacken stands with Ukraine!

Learn more
bg

Brazilian personal data exposure

Brazilian personal data exposure

Published: 21 Nov 2018 Updated: 29 Sep 2022

Brazil has always been one of those countries where cybersecurity issues are hard to report. Back in September, we have already reported a big leak by a Brazilian online booking system exposing personal data of almost 500,000 people. The company behind the exposure was really hard to identify and contact, but at the end of the day, the database was secured mainly due to our Twitter followers support.

On November 12th, when auditing the search results for open/exposed Elasticsearch databases with Binaryedge.io platform, we have found what appeared to be a collection of personal records compiled by FIESP, the Federation of Industries of the State of SΓ£o Paulo. FIESP is the largest class entity in the Brazilian industry. It represents about 130 thousand industries in various sectors, of all sizes and different production chains, distributed in 131 employers’ unions.

Records were stored in Elasticsearch with the total count of 180,104,892.

At least 3 indices (FIESP, celurares and externo) that we have analyzed contained the personal info of Brazilian citizens.

The largest collection of data (FIESP collection) had 34,817,273 personal records with exposed info like:

  • name
  • personal ID number (RG number)
  • taxpayer registry identification (CPF)
  • sex
  • date of birth
  • full address
  • email
  • phone number

We have immediately sent notifications to FIESP contacts but never received any response. The database was taken offline only after our Brazilian-based follower, Paulo Brito, managed to get in touch with a FIESP representative over the phone and inform them about the exposure.

This article will be updated if/when we hear back from FIESP as of steps taken to protect this sensitive data.

DANGER OF OPEN ELASTICSEARCH INSTANCES

We have previously reported that the lack of authentication allowed the installation of malware or ransomware on the Elasticsearch servers. The public configuration allows the possibility of cybercriminals to manage the whole system with full administrative privileges. Once the malware is in place criminals could remotely access the server resources and even launch a code execution to steal or completely destroy any saved data the server contains.

Please take note, that we regularly publish reports on data leaks. For example, we’ve recently written aboutΒ kars4kids data leak.
To learn on how you can minimize the risks of your cloud infrastructure becoming exposed – contactΒ us for a free consult

share via social

Subscribe to our research

Enter your email address to subscribe to Hacken Research and receive notifications of new posts by email

Interested in getting to know whether your systems are vulnerable to cyberattacks?

Tell us about your project

  • This field is required
  • This field is required
    • telegram icon Telegram
    • whatsapp icon WhatsApp
    • wechat icon WeChat
    • signal icon Signal
  • This field is required
  • This field is required
This field is required
departure icon

Thank you for your request

Get security score on

  • certified logo
  • coingeco logo
  • coin market cap logo

1,200+ Audited Projects

companies logos

Apply for partnership

  • This field is required
  • This field is required
  • This field is required
  • This field is required
    • Foundation
    • VC
    • Angel investments
    • IDO or IEO platform
    • Protocol
    • Blockchain
    • Legal
    • Insurance
    • Development
    • Marketing
    • Influencer
    • Other
This field is required
This field is required
departure icon

Thank you for your request

Get security score on

  • certified logo
  • coingeco logo
  • coin market cap logo

1,200+ Audited Projects

companies logos

Get in touch

  • This field is required
  • This field is required
  • This field is required
  • This field is required
This field is required
By submitting this form you agree to the Privacy Policy and information beeing used to contact you
departure icon

Thank you for your request

Get security score on

  • certified logo
  • coingeco logo
  • coin market cap logo