Messaging app Tokee may have leaked 1.2 million user profiles — experts say exposed personal data ‘presents significant privacy, security, and regulatory risks’



  • Cybernews found Tokee’s unprotected MongoDB exposing ~1.2M users’ data
  • Leak included names, phone numbers, avatars, device tokens, IDs, activity logs, and account status; chat logs were encrypted
  • Deucetek secured the database after disclosure; no evidence of malicious access, but users warned of phishing risks

A messaging app called Tokee kept an unprotected database with plenty of sensitive information, exposing over a million customers to whoever knew where to look.

Security researchers from Cybernews discovered a non-password-protected MongoDB instance which contained user display names, phone numbers stored as numeric values, profile avatars, device tokens used for push notifications, user IDs, timestamps for account creation and update, “last seen” activity indicators, and account status flags (for example, premium or non-premium).

https://cdn.mos.cms.futurecdn.net/GcQXTy4NBXKeoop4V5WQnQ-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img