Reverb exposes 'millions' of customer records on unsecured server

Leaked records contained data including full names, email addresses, phone numbers and mailing addresses

Online musical instrument marketplace Reverb has warned customers of a data breach affecting the website and 5.6 million user records.

According to security researcher Bob Diachenko, he discovered an unsecured Elasticsearch server earlier this month containing over 5.6 million records. These records contained data about individual listings on Reverb, including full names, email addresses, phone numbers, mailing addresses, PayPal emails, and listing/order information.

“Upon closer inspection, I noticed that there are many 'test' emails coming from @reverb.com domain. I decided to verify shop slugs against real URLs on Reverb site and quickly confirmed the initial thought - it was all Reverb users’ data,” Diachenko said.

He then ran a quick check to see who the sellers were. He found the details of several high-profile sellers, including Bill Ward of Black Sabbath, Jimmy Chamberlin of Smashing Pumpkins, Alessandro Cortini of Nine Inch Nails, and more.

Reverb has started notifying customers that the breach exposed potentially sensitive information.

In an email to users, Reverb wrote: “We take our users’ privacy and security very seriously. Out of an abundance of caution, we wanted to inform you that Reverb recently became aware of an issue relating to user contact information.”

Related Resource

NETSCOUT threat intelligence report

Cyber crime: Exploiting a pandemic

Threat intelligence report - whitepaper from NETSCOUTDownload now

“At this time, we believe that contact information, including name, address, phone number, and email, was publicly accessible for a short period of time. We do not have reason to believe that any of this information has been misused, nor do we believe that password or payment information were involved.”

Paul Norris, senior systems engineer EMEA at Tripwire, told IT Pro that misconfigurations like these are becoming all too common.

“Exposing sensitive data doesn’t require a sophisticated vulnerability, and the rapid growth of cloud-based data storage has exposed weaknesses in processes that leave data available to anyone. A misconfigured database on an internal network might not be noticed, and if noticed might not go public, but the stakes are higher when your data storage is directly connected to the Internet,” he said.

“Organizations should identify processes for securely configuring all systems, including cloud-based storage, like Elasticsearch. Once a process is in place, the systems must be monitored for changes to their configurations.”

Sergio Loureiro, cloud security director at Outpost24, told IT Pro that everyone needs to be “playing from the same music sheet when it comes to security and with the countless possibilities of ‘quickly deploying a system in the cloud,’ security is -still- often overlooked by organizations.”

“As datasets grow to these sizes, the data is becoming increasingly valuable to businesses and in some cases even more valuable than money. Unfortunately, not everyone protects it like the valuable asset it is,” Loureiro said.

Featured Resources

Shining light on new 'cool' cloud technologies and their drawbacks

IONOS Cloud Up! Summit, Cloud Technology Session with Russell Barley

Watch now

Build mobile and web apps faster

Three proven tips to accelerate modern app development

Free download

Reduce the carbon footprint of IT operations up to 88%

A carbon reduction opportunity

Free Download

Comparing serverless and server-based technologies

Determining the total cost of ownership

Free download

Recommended

Pizza chain exposed 100,000 employees' Social Security numbers
data breaches

Pizza chain exposed 100,000 employees' Social Security numbers

19 Nov 2021
83% of critical infrastructure companies have experienced breaches in the last three years
cyber security

83% of critical infrastructure companies have experienced breaches in the last three years

11 Nov 2021
Identity Automation launches credential breach monitoring service
phishing

Identity Automation launches credential breach monitoring service

5 Oct 2021
Neiman Marcus data breach hits 4.6 million customers
data breaches

Neiman Marcus data breach hits 4.6 million customers

4 Oct 2021

Most Popular

What should you really be asking about your remote access software?
Sponsored

What should you really be asking about your remote access software?

17 Nov 2021
Business customers can get 30% off the Surface Laptop Go for Black Friday 2021
Laptops

Business customers can get 30% off the Surface Laptop Go for Black Friday 2021

26 Nov 2021
Nike to take customers into the metaverse with 'NIKELAND'
virtualisation

Nike to take customers into the metaverse with 'NIKELAND'

19 Nov 2021