• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / Gearbest; Caution! large data leak

Gearbest; Caution! large data leak

14/03/2019 20:14 by giorgos

The well-known Gearbest, a major Chinese online shopping company, revealed millions of user profiles and purchase orders, according to security researchers.

Investigator Noam Rotem has discovered that an Elasticsearch server runs millions of files each week. This includes customer data, orders, and payment records. The server is not even protected by a password, allowing anyone to access the data.

Gearbest is ranked among one of the world's leading 250 websites and is partnering with leading companies such as Asus, Huawei, Intel and Lenovo.gearbest - Gearbest; Caution! large data leak

The TechCrunch website contacted Gearbest via a dedicated security page, and made sure to inform them of the vulnerable server. Despite the report, however, the company did not lock the data or respond to the request.

Rotem, who shared them his findings with TechCrunch, said that there are names, addresses, phone numbers, e-mail addresses and customer orders from purchased products among the data being released. The database also had information on payments and invoices.

"The content of some people's orders has been very revealing," says Rotem.

Exposed orders not only violate customers' privacy but may compromise customers in many parts of the world where freedom of speech and expression is limited. Some of the listings include sex games and other markets that could for example lead to legal interference where LGBTQ relationships are forbidden by law.

Countries such as the United Arab Emirates and Pakistan have strict laws that can result in death sentences.

Shenzhen-based Gearbest has a large presence in Europe with warehouses in Spain, Poland, the Czech Republic and the UK, where EU data protection and privacy laws are in force. Thus, any company that violates the General Protection Regulation Data (GDPR) may be fined up to 4% of its total revenue.

If you have an account on the site, it makes no sense to change your password, as the server is still a wild vine. But what you can do is change the password where you use the same.

How to Enable and Disable a User in Windows 10

Gearbest; Caution! large data leak was last modified: 14 March, 2019, 8: 24 mm by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: NewsDay: GDPR, gearbest, Huawei, I'm sure, server

You May Also Like

Huawei has also filed a lawsuit against the FCC
MOSE: Post Exploitation tool for Server management
GDPR fine of 10 million for employee monitoring

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « Edge with Chromium: See the Add-ons page first
Next Post: How to Turn on Darkness in Chrome Chrome »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.