Indian Home Salon Platform Yes Madam exposed sensitive customer and gig worker data due to a server-side misconfiguration.
Noida-based Yes Madam operates in more than 30 cities across the country, according to its website. The platform offers salon services at home, including therapy, massage, spa, and men’s grooming. Yes Madam’s mobile app has also been downloaded over his million times.
But the startup left behind a database containing the full names, mobile phone numbers, mailing addresses and email addresses of hundreds of thousands of Yes Madam customers who have gone online without a password since at least February 20. . The database also contained customer location data. User device details such as latitude and longitude values, payment links, model name and his IMEI number.
Additionally, the startup has released the profile pictures, names and mobile numbers of gig workers on the platform.
security researcher Anuragsen One of CloudDefense.ai discovered the public database and asked TechCrunch to help report it to the startup.
Anyone who knows the IP address of the database can access the misconfigured exfiltrated data using just a web browser. Sen said the database has more than 900,000 of his users.
Yes madam secured the database on Friday shortly after TechCrunch reached out with the details. Yes, Madam co-founder Mayank Arya confirmed to TechCrunch that he has made the fix.
Arya declined to comment further when asked if Yes Madam has technical means, such as logs, to determine if the published data has been accessed by someone else.
Sen also informed India’s computer emergency response team, CERT-In, of the data breach.