The exposed treasure trove leaked data of Decathlon Spain employees. As stated in their post:
It has everything that a malicious hacker would, in theory, need to use to take over accounts and gain access to private and even proprietary information.In brief, the exposed data on an Elasticsearch server included over 123 million records. These records included employees’ personal details such as usernames, passwords, API logs, API usernames and unencrypted passwords, detailed PII data of the employees, employment contract details, and work email addresses. Moreover, it even included unencrypted customer login information and private IP address.
Such overt details, according to the researchers, could facilitate criminals in conducting phishing attacks, corporate espionage, identity theft as well as physical threats.
They then notified the firm about the breach on February 16, 2020, who closed the database the very next day. It means, for now, the threat is over. The researchers advise users to contact Decathlon and enquire about the incident to assess their data security.
Let us know your thoughts in the comments.