Jump to content

Gearbest security lapse exposed millions of shopping orders


NelsonG

Recommended Posts

Gearbest, a Chinese online shopping giant, has exposed millions of user profiles and shopping orders, security researchers have found.

Security researcher Noam Rotem found an Elasticsearch server leaking millions of records each week, including customer data, orders, and payment records. The server wasn’t protected with a password, allowing anyone to search the data.

Gearbest ranks as one of the top 250 global websites, and serves top brands, including Asus, Huawei, Intel, and Lenovo.

TechCrunch contacted GearBest — and through its dedicated security page — to secure the database. The company neither secured the data nor responded to our request for comment.

Rotem, who shared his findings with TechCrunch and published his report at VPNMentor, said names, addresses, phone numbers, email addresses and customer orders and products purchased were among the data exposed. The database also had payment and invoice information, with amount spent and semi-masked names and email addresses.

After reviewing a portion of the data, TechCrunch found the database revealed exactly what customers bought, when, and where the items were sent.

Some of the member-specific records also included passport numbers and other national ID data. Rotem said there was little evidence of encryption, and in some cases none at all.

“The content of some people’s orders has proven very revealing,” Rotem said. Not only are the exposed orders a breach of customer privacy, the exposed data could put customers in parts of the world where freedom of speech and expression is limited in danger. Some of the listings for sex toys and other intimate purchases, for example, could lead to legal repercussions where LGBTQ+ relationships or pre-marital sex are banned.

Countries like the United Arab Emirates and Pakistan have some of the strictest laws, which can lead to punishment by death.

Rotem also found a separate exposed web-based database management system on the same IP address, allowing anyone to manipulate or disrupt the databases run by Gearbest’s parent company, Globalegrow,

It’s not known exactly for how long the server was exposed. Data from internet scanning site Binary Edge showed the database was first detected on March 7.

Shenzhen-based Gearbest has a large presence in Europe, with warehouses in Spain, Poland, and Czech Republic, and the U.K., where EU data protection and privacy laws apply. Any company violating the General Data Protection Regulation (GDPR) can be fined up to four percent of its global revenue.

This is the second security issue at Gearbest in as many years. In December 2017, the company confirmed accounts had been breached after what was described as a credential stuffing attack.

Techcrunch?d=2mJPEYqXBVI Techcrunch?d=7Q72WNTAKBA Techcrunch?d=yIl2AUoC8zA Techcrunch?i=5zKtyJkVscU:tixfblTGA68:-BT Techcrunch?d=qj6IDK7rITs
5zKtyJkVscU

View the full article

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Our picks

    • Wait, Burning Man is going online-only? What does that even look like?
      You could have been forgiven for missing the announcement that actual physical Burning Man has been canceled for this year, if not next. Firstly, the nonprofit Burning Man organization, known affectionately to insiders as the Borg, posted it after 5 p.m. PT Friday. That, even in the COVID-19 era, is the traditional time to push out news when you don't want much media attention. 
      But secondly, you may have missed its cancellation because the Borg is being careful not to use the C-word. The announcement was neutrally titled "The Burning Man Multiverse in 2020." Even as it offers refunds to early ticket buyers, considers layoffs and other belt-tightening measures, and can't even commit to a physical event in 2021, the Borg is making lemonade by focusing on an online-only version of Black Rock City this coming August.    Read more...
      More about Burning Man, Tech, Web Culture, and Live EventsView the full article
      • 0 replies
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
×
×
  • Create New...