Advertisement Banner
  • Home
  • News
  • Cyber News
  • Contact
No Result
View All Result
  • Home
  • News
  • Cyber News
  • Contact
No Result
View All Result
Wellnessnewshubb
No Result
View All Result
Home Cyber News

Russian e-commerce giant Elevel exposed buyers’ delivery addressesSecurity Affairs

admin by admin
February 8, 2023
in Cyber News


A leading electrical engineering company in Russia, Elevel, has exposed its customers’ personally identifiable information (PII,) including full names and addresses.

Original post at https://cybernews.com/privacy/russian-e-commerce-giant-data-leak/

Founded in 1991, Elevel (previously Eleko) positions itself as the leading Russian electrical engineering company that runs both an e-commerce business and wholesale stores.

On January 24, the Cybernews research team discovered an open dataset with 1.1TB of data and attributed it to e.way – an Elevel-owned online shop with 25,000 monthly visitors.

The dataset with seven million data entries leaked two years’ worth of sensitive data, including names, surnames, phone numbers, email addresses, and delivery addresses of customers.

“If left exposed, threat actors could download and clone the cluster’s data and use it for nefarious purposes, including phishing attacks, as they possess sufficient PII and to make their scam seem legitimate,” Cybernews researchers said.

Moreover, it contained login data and passwords in URL encoding, which is considered a relatively weak protection mechanism since it can be decoded easily.

e.way elevel leak

“As a number of usernames and passwords are exposed, it could enable threat actors with valid credentials to gain further sensitive data and to impersonate users to make fraudulent purchases,” Cybernews researchers noted.

The dataset is now closed. We are still waiting to receive the company’s official response.

Elevel

If you want to have more info about leaky databases discovered by the Cybernews Team give a look at the original post at https://cybernews.com/privacy/russian-e-commerce-giant-data-leak/

About the author: Jurgita Lapienytė  Chief Editor 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Elevel)



Share On






Source link

Previous Post

“Unfurled Tiranga at Lal Chowk without bulletproof jacket…” Modi recalls Ekta Yatra –

Next Post

US, UK sanctions members of ‘notorious cyber gang’ TrickBot

Next Post

US, UK sanctions members of 'notorious cyber gang' TrickBot

Recommended

Ek Shaam Warriors Ke Naam Open Mic Event –

1 month ago

TSA Seeks Input to Strengthen Rail and Pipeline Cybersecurity

4 months ago

© 2022 Law Enforcement News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy and Terms & Conditions.

Navigate Site

  • Home
  • News
  • Cyber News
  • Contact

Newsletter Sign Up.

No Result
View All Result
  • Home
  • News
  • Cyber News
  • Contact

© 2022 Law Enforcement News Hubb All rights reserved.