UPDATED 21:57 EDT / JANUARY 17 2019

SECURITY

VOIPo database exposes millions of call logs and text messages online

Millions of call logs and SMS text messages have been found exposed on a misconfigured database belonging to “voice over internet protocol” provider VOIPo LLC.

Discovered by Cloudflare Inc. security researcher Justin Paine, the data was spotted via the Shodan security search engine and traced back to an unsecured Elasticsearch server owned by VOIPo.

The data included 7 million call logs, 7 million SMS/MMS message logs and plaintext internal system credentials, including unencrypted passwords.  The database is said to have been exposed since June 2018 and contained call and message logs dating back to May 2015.

The breach was confirmed by VOIPo. In a notice, the company said the data was mostly simulated data located on an isolated development server and that its production environment and the rest of its network was “not at risk.”

Ruchika Mishra, director of products and solutions at Balbix Inc., told SiliconANGLE that the millions of exposed call logs, text messages and other internal documents containing unencrypted passwords make victims easy targets for hackers.

“Although VOIPo claims there is no evidence to indicate a breach occurred, the company cannot guarantee that no unauthorized users accessed the data, especially since it was left unsecured and easily available for months,” he said. “Voipo and its customers might still be secure if the company had early visibility into vulnerabilities across its entire attack surface — including passwords and unencrypted data — and been able to correct them right away.”

Stephan Chenette, co-founder and chief technology officer of AttackIQ Inc., noted that it doesn’t take much for outsiders to find unsecured databases and access sensitive information.

“Misconfigured security controls are an all-too-common problem,” Chenette noted. “Organizations are increasingly struggling with limited and undertrained IT resources that lead to using default account passwords, unpatched systems, and poorly configured network devices.”

Data leaks of any kind can undermine customer confidence, but they’re easily preventable, he said. “Unauthorized exposure of any type of customer data, for any period, is a serious issue and organizations should always have a plan to continuously assess the viability of their security controls.”

Photo: US Air Force

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.