Confirmed: 2 Billion Records Exposed In Massive Smart Home Device Breach
Tuesday, July 2, 2019
A team of self-styled "hacktivist" security researchers, with an impressive track record of exposing breach after breach as part of a web-mapping project that searches for vulnerabilities within online databases, has disclosed one of the biggest to date. The researchers in question, Noam Rotem and Ran Locar from vpnMentor, found that a user database belonging to a Chinese company called Orvibo, which runs an Internet of Things (IoT) management platform, had been left exposed to the Internet without any password to protect it. So far, so appalling. But it gets even worse when you discover that the database includes more than 2 billion logs containing everything from user passwords to account reset codes and even a "smart" camera recorded conversation.
Ilia Kolochenko, founder and CEO of web security company ImmuniWeb, concludes that beyond the obvious password changing, users of Orvibo devices have little recourse "but to file a legal complaint and deactivate any remote management of their homes if it is doable." Read Full Article
SC Media: Exposed Orvibo database leaks two billion records
Computer Business Review: PCM Hacked: Cloud Services Firm Plays Down Impact