Database Snafu Leaks 600K Records from Marketplace

According to vpnMentor, an online marketplace where users trade discount online accounts, license keys, and malware suffered a data breach exposing hundreds of thousands of sensitive records.

Security researcher Jeremiah Fowler discovered 600,000 “customer support attachments” associated with the website Z2U. This included images of individuals holding credit cards, passports and other ID documents of his.

The non-password-protected database also contained payment transactions containing IBAN numbers. User account login, email and password. An order confirmation showing the buyer’s name, email and purchase details.

In addition, Fowler had access to customer support dashboards, communications, purchase history, account credits, and screenshots of refund requests.

For more information on misconfigured databases, see Misconfigured database exposes 880 million medical records.

Fowler said the platform is in China, as is the server hosting the database in question. Z2U also has an English site, and he has a 4.5 rating on Trustpilot.

It claims to be the “world’s leading digital market trading platform” for gamers, specializing in buying and selling in-game items.

However, Fowler’s investigation appears to have uncovered a variety of questionable transactional activities outside the gaming world, including social media, streaming, and even selling Amazon accounts.

“This bypasses the verification process that many social media companies have in place to prevent malicious or fraudulent activity on their platforms. Merchant (seller) accounts also pose a risk of fraud,” he argued.

“Account sharing or selling raises a number of ethical and security concerns. Z2U users selling HBO MAX and Netflix Premium accounts for just $1 and Disney+ 3-month subscriptions for 5 For reference, Disney+ charges $109.99/year, while Z2U sellers have access for as low as $17/year.In the UK, Netflix, Amazon It is against the law for users to share passwords for services such as Prime Video and Disney+.”

Fowler also claimed that Windows license keys were being sold “for a fraction of the actual price” and that the sellers “offered viruses, malware, or other malicious applications.”

Access to the database was closed shortly after the researcher sent a note in Chinese to the site.

“We are not suggesting any fraudulent activity by Z2U or its customers and have only highlighted the details of our findings to identify real-world risks,” Fowler concluded.

Information security has reached out to Z2U for comment and will update this story if we hear back.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *