
Online store exposed millions of Chinese citizen IDs
A security researcher said he discovered millions of Chinese citizen identity numbers spilling online after an e-commerce store left its database exposed to the internet.
Viktor Markopoulos, a security researcher working for CloudDefense.ai, said he found the database belonging to Zhefengle, a China-based e-commerce store for importing goods from overseas.
The database contained more than 3.3 million orders spanning 2015 through 2020, Markopoulos said, but had not been protected with a password.
The order database contained corresponding customer shipping addresses and phone numbers, as well as the customer’s government-issued resident identity card number. Many of the orders also include uploaded copies of the customer’s identity card, TechCrunch has seen.
Customers who import goods to China must have their identity verified, and it’s not uncommon for stores to ask for customers to upload a copy of their identity card.
It’s not known how long the database was exposed. Anyone who knew the IP address of the database could access the data inside using only their web browser.
TechCrunch contacted the owners of the online store with details about the exposed database. A short time later, the database became inaccessible. In reply, the store owners responded: “The vulnerability has been addressed promptly. We are currently investigating the cause internally.”
TechCrunch’s Rita Liao contributed reporting.
More Stories
Secondaries investors tell us what’s hot heading into 2024
[ad_1] Since the market corrected in 2022, late-stage funding rounds have been few and far between. It’s been hard to...
Tumblr tests ‘Communities,’ semi-private groups with their own moderators and feeds
[ad_1] After scaling back operations and reassigning staff to other projects, Tumblr owner Automattic’s CEO Matt Mullenweg said that the...
Seattle biotech hub pursues ‘DNA typewriter’ tech with $75M from tech billionaires
[ad_1] A new Seattle biotech organization will be funded to the tune of $75 million to research “DNA typewriters,” self-monitoring...
Apple says it is not aware anyone using Lockdown Mode got hacked
[ad_1] Last year, Apple launched a special new protection for at-risk users — such as journalists and activists — called...
Can Bitcoin Spot ETFs Attract Enough Capital? Experts On What Will Lead To ATH
[ad_1] Trading firm QCP Capital has shared its thoughts on what could drive the flagship cryptocurrency, Bitcoin, to its all-time...
Opal Security, which helps companies manage access and identities, raises $22M | TechCrunch
[ad_1] VC investment trends in the cybersecurity market suggest a sector in decline — at least within the context of...