Research Impact

75+
Major Discoveries
3.2B
Records Protected
20
Countries
200+
Organizations Helped

Major Security Discoveries

CRITICAL
May 2019

Instagram Influencer Data Breach

Discovered massive database containing 49 million Instagram influencer records exposed online. The database included personal contact information, bios, profile pictures, follower counts, and location data for celebrities and brand accounts.

Records Exposed: 49 Million
Data Types: Email, Phone, Bio, Location
Source: Chtrbox (Mumbai-based)
Platform: Amazon Web Services
49M
Records
Influencers
Celebrities
Critical
Severity
CRITICAL
March 2024

YX International SMS Database Leak

Discovered exposed database belonging to Asian technology firm YX International that was leaking 2FA SMS messages for Google, Facebook, WhatsApp, and TikTok. The company routes 5 million SMS messages daily through unprotected infrastructure.

Daily SMS Volume: 5 Million
Affected Platforms: Google, Facebook, WhatsApp, TikTok
Exposure Duration: 8+ months
Authentication: None required
5M
SMS Daily
4+
Tech Giants
Critical
Severity
CRITICAL
February 2023

Pentagon Military Email Exposure

Uncovered 3 terabytes of unclassified US military emails from Special Operations Command exposed on Microsoft Azure cloud server without password protection for over 2 weeks, affecting approximately 20,600 individuals.

Data Volume: 3 Terabytes
Exposure Period: 2+ weeks
Military Branch: US Special Operations Command
Access Control: None (passwordless)
3TB
Data Size
20K+
Individuals
SOCOM
Military Branch
CRITICAL
January 2021

Socialarks 200M User Data Breach

Discovered 400GB of scraped data from 214 million Facebook, Instagram, and LinkedIn users exposed through unsecured ElasticSearch database hosted by Chinese startup. The data included private information not publicly available on profiles.

Total Users: 214 Million
Data Volume: 400GB
Platforms: Facebook, Instagram, LinkedIn
Data Source: Scraped/Harvested
214M
Users
400GB
Data Size
3
Platforms
HIGH
June 2023

Shell Recharge EV Data Breach

Identified exposed database containing personal information of Shell Recharge electric vehicle charging station customers across 33+ countries, including names, addresses, phone numbers, and vehicle identification numbers.

Countries Affected: 33+
Data Types: PII, VINs, Location Data
Infrastructure Type: EV Charging Network
Security Measures: Insufficient
1TB
Logging Data
33+
Countries
High
Impact
HIGH
February 2023

PokerBaazi Security Lapse

Found India's largest online poker platform exposing sensitive user information through misconfigured database for over 2 months, affecting millions of registered users across the gaming platform.

User Base: 2+ Million
Exposure Duration: 2+ Months
Platform Type: Online Poker
Data Sensitivity: High (Financial)
2M+
Users
6GB+
Data Size
2+
Months Exposed
HIGH
May 2020

Facebook Vietnam Data Scraping

Uncovered 3GB of scraped Facebook user data from 12 million Vietnamese users on Elastic server, raising concerns about data scraping vulnerabilities in social media platforms and third-party API security.

Target Region: Vietnam
Affected Users: 12 Million
Data Volume: 3GB
Operation Type: Targeted Scraping
12M
Vietnamese Users
3GB
Data Size
High
Privacy Risk
HIGH
August 2020

Natura & Co Data Breach

Discovered significant data breach at Brazilian online retailer Natura & Co exposing 192 million records including personally identifiable information through unsecured database.

Records Exposed: 192 Million
Company: Natura & Co
Region: Brazil
Data Type: PII
192M
Records
Brazil
Region
High
Severity
HIGH
June 2022

ACY Securities Trading Data Exposure

Identified Australian trading company ACY Securities unintentionally revealing 60GB of personal and financial information belonging to users across multiple countries including India, China, Spain, and Brazil.

Data Volume: 60GB
Countries: 12+
Data Type: Financial
Company: ACY Securities
60GB
Data Size
12+
Countries
Financial
Data Type
HIGH
July 2020

US Casting Site Data Leak

Discovered prominent US online casting agency MyCastingFile.com leaking personal data belonging to more than 260,000 actors and entertainment industry professionals through unsecured database.

Affected Users: 260,000+
Industry: Entertainment
Data Size: 1GB
Profession: Actors
260K+
Actors
Entertainment
Industry
High
Privacy Risk
HIGH
October 2020

Edureka E-Learning Platform Breach

Uncovered massive data breach at Indian e-learning platform Edureka affecting up to 2 million users, exposing names, email addresses, phone numbers, and login activity records on Amazon servers.

Affected Users: 2 Million
Sector: Education
Region: India
Platform: Amazon AWS
2M
Users
Education
Sector
India
Region
HIGH
August 2020

RailYatri Travel Platform Exposure

Discovered government-backed Indian travel marketplace RailYatri exposing 43GB of customer and corporate data including full names, age, gender, addresses, phone numbers, booking details, GPS location, and payment card information.

Records: 37 Million
Data Size: 43GB
Users: 700,000+
Platform: Government-backed
37M
Records
700K+
Users
43GB
Data Size
HIGH
June 2023

CrimeCheck Legal Platform Exposure

Discovered security lapse at legaltech platform CrimeCheck exposing sensitive legal and personal information, highlighting vulnerabilities in legal technology infrastructure handling confidential data.

Sector: Legal
Data Type: Confidential
Sensitivity: High
Platform: LegalTech
Legal
Sector
Confidential
Data Type
High
Sensitivity
HIGH
February 2023

Slick Social Media App Data Leak

Identified data exposure in homegrown social media app Slick that exposed users' personal information, including data belonging to children, raising concerns about youth privacy protection in social platforms.

User Group: Youth
Platform Type: Social
Focus: Privacy
Concern: Child Safety
Youth
Users
Social
Platform
Privacy
Focus

Discovery Timeline

May 2019

Instagram Influencer Data Breach

Discovered massive database containing 49 million Instagram influencer records exposed online. The database included personal contact information, bios, profile pictures, follower counts, and location data for celebrities and brand accounts.

49M
Records
Influencers
Celebrities
Critical
Severity
May 2020

Facebook Vietnam Data Scraping

Uncovered 3GB of scraped Facebook user data from 12 million Vietnamese users on Elastic server, raising concerns about data scraping vulnerabilities in social media platforms and third-party API security.

12M
Vietnamese Users
3GB
Data Size
High
Privacy Risk
July 2020

US Casting Site Data Leak

Discovered prominent US online casting agency MyCastingFile.com leaking personal data belonging to more than 260,000 actors and entertainment industry professionals through unsecured database.

260K+
Actors
Entertainment
Industry
High
Privacy Risk
August 2020

RailYatri Travel Platform Exposure

Discovered government-backed Indian travel marketplace RailYatri exposing 43GB of customer and corporate data including full names, age, gender, addresses, phone numbers, booking details, GPS location, and payment card information.

37M
Records
700K+
Users
43GB
Data Size
October 2020

Edureka E-Learning Platform Breach

Uncovered massive data breach at Indian e-learning platform Edureka affecting up to 2 million users, exposing names, email addresses, phone numbers, and login activity records on Amazon servers.

2M
Users
Education
Sector
India
Region
January 2021

Socialarks 200M User Data Breach

Discovered 400GB of scraped data from 214 million Facebook, Instagram, and LinkedIn users exposed through unsecured ElasticSearch database hosted by Chinese startup.

214M
Users
400GB
Data Size
3
Platforms
June 2022

ACY Securities Trading Data Exposure

Identified Australian trading company ACY Securities unintentionally revealing 60GB of personal and financial information belonging to users across multiple countries including India, China, Spain, and Brazil.

60GB
Data Size
12+
Countries
Financial
Data Type
February 2023

Pentagon Military Email Exposure

Uncovered 3 terabytes of unclassified US military emails from Special Operations Command exposed on Microsoft Azure cloud server without password protection for over 2 weeks.

3TB
Data Size
20K+
Individuals
SOCOM
Military Branch
February 2023

PokerBaazi Security Lapse

Found India's largest online poker platform exposing sensitive user information through misconfigured database for over 2 months, affecting millions of registered users.

2M+
Users
6GB+
Data Size
2+
Months Exposed
June 2023

Shell Recharge EV Data Breach

Identified exposed database containing personal information of Shell Recharge electric vehicle charging station customers across 33+ countries.

1TB
Logging Data
33+
Countries
High
Impact
March 2024

YX International SMS Database Leak

Discovered exposed database leaking 2FA SMS messages for Google, Facebook, WhatsApp, and TikTok. The Asian technology firm was routing 5 million SMS messages daily through an unprotected database.

5M
SMS Daily
4+
Tech Giants
Critical
Severity

Global Discovery Impact

Discovery Trends Over Time