Article 58351 Private data gone public: Razer leaks 100,000+ gamers’ personal info

Private data gone public: Razer leaks 100,000+ gamers’ personal info

by
Jim Salter
from Ars Technica - All content on (#58351)
razer-data-leak-800x185.jpg

Enlarge / This redacted sample record from the leaked Elasticsearch data shows someone's June 24 purchase of a $2,600 gaming laptop. (credit: Volodymyr Dianchenko)

In August, security researcher Volodymyr Diachenko discovered a misconfigured Elasticsearch cluster, owned by gaming hardware vendor Razer, exposing customers' PII (Personal Identifiable Information).

The cluster contained records of customer orders and included information such as item purchased, customer email, customer (physical) address, phone number, and so forth-basically, everything you'd expect to see from a credit card transaction, although not the credit card numbers themselves. The Elasticseach cluster was not only exposed to the public, it was indexed by public search engines.

I must say I really enjoyed my conversations with different reps of @Razer support team via email for the last couple of week, but it did not bring us closer to securing the data breach in their systems. pic.twitter.com/Z6YZ5wvejl

- Bob Diachenko (@MayhemDayOne) September 1, 2020

Diachenko reported the misconfigured cluster-which contained roughly 100,000 users' data-to Razer immediately, but the report bounced from support rep to support rep for over three weeks before being fixed.

Read 13 remaining paragraphs | Comments

index?i=3Bsb1MKNaIE:gyn5haLs8Uk:V_sGLiPB index?i=3Bsb1MKNaIE:gyn5haLs8Uk:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments