The Telegraph Exposes 10 TB Database With Subscriber Info

The Telegraph Exposes 10 TB Database With Subscriber Info

‘The Telegraph’, one of the UK’s largest newspapers and online media outlets, has leaked 10 TB of data after failing to properly secure one of its databases.

The exposed information includes internal logs, full subscriber names, email addresses, device info, URL requests, IP addresses, authentication tokens, and unique reader identifiers.

Bob Diachenko, the researcher who discovered the unprotected dataset on September 14, 2021, has confirmed that at least 1,200 unencrypted contacts were accessible without a password at the time of his review.

A sample of the exposed records. Source: cooltechzone.com

Notably, many of these cases concern registrant information of Apple News subscribers, also including passwords in plaintext form.

Also Read: Top 3 Simple Data Backup Singapore and Recovery Methods

The newspaper was contacted and warned about the exposure immediately, but it took them two days to eventually respond and secure the database.

The instance was indexed on specialized search engines on September 1, 2021, so the period of exposure is at least three weeks. That’s plenty of time for attackers and automated scanners to find the exposed database and exfiltrate the contained data.

Only affects a subset of subscribers

For those of you who might have been exposed as a result of this data leak, the main risk you’re running is getting scammed or phished via email.

The leak of the URL requests may also cause a privacy risk as someone could use them to construct the users’ browsing history on the news platform.

As for the consequences for The Telegraph, stolen access tokens could be used by non-subscribers to access content locked behind its paywall, but they could solve this with a reset. 

In response to the above, The Telegraph issued the following statement regarding Diachenko’s findings:

We became aware of this discovery on 16 September and took immediate action to secure the data. An investigation showed that only a small number of records were exposed – less than 0.1% of our users and we have contacted all the users to advise them. The investigation also concluded that whilst the data was exposed it was not breached other than the discovery posted by the researcher. We are grateful for the work of independent researchers who responsibly disclose vulnerabilities and exposures and who are vital in our continued work to protect our assets.

According to this statement, the number of the impacted individuals is 600, which is less than what Daichenko saw exposed. The Telegraph also states that none of them run any risks of exploitation since Diachenko was the first and last person to access the sensitive dataset.

Also Read: What is Pseudonymisation: 5 Techniques and Its Best Practices

Out of an abundance of caution, if you’re a subscriber to The Telegraph, we would suggest that you reset your password and remain vigilant against unsolicited emails that make bold claims or ask you to take urgent action to secure your account.

Privacy Ninja

Recent Posts

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

2 weeks ago

Prioritizing Security Measures When Launching Webpage

Prioritizing Security Measures When Launching a Webpage That Every Organisation in Singapore should take note…

2 weeks ago

The Importance of Regularly Changing Passwords for Enhanced Online Security

Importance of Regularly Changing Passwords for Enhance Online Security that every Organisation in Singapore should…

3 weeks ago

Mitigating Human Errors in Organizations: A Comprehensive Approach to Data Protection and Operational Integrity

Comprehensive Approach to Data Protection and Operational Integrity that every Organsiation in Singapore should know…

3 weeks ago

The Importance of Pre-Launch Testing in IT Systems Implementation

Here's the importance of Pre-Launch Testing in IT Systems Implementation for Organisations in Singapore. The…

4 weeks ago

Understanding Liability in IT Vendor Relationships

Understanding Liability in IT Vendor Relationships that every Organisation in Singapore should look at. Understanding…

1 month ago