Data Security

Misconfiguration exposes millions of Companjon logs

concept of leaky software, data with a tap sticking out.3d illustration

Cybernews reports that insurance technology company Companjon has leaked a large volume of internal data due to an unsecured Kafka stream.

With more than 15 million records entering the instance within a week, Companjon may have exposed 960 million logs overall, according to Cybernews researchers. Aside from discovering a pair of exposed Kafka topics containing more than 15 million logs from travel partners such as Trainline, TripX, and Omio, researchers also observed over 15,000 logs with full names, email addresses, and other personally identifiable information. Future-dated itineraries up to 2026 were also exposed, including travel dates, exact routes, and carriers.

"The investigation confirmed the leak was active, with the latest records appearing just hours before this report. This demonstrates how a single, less visible B2B vendor can compromise the data and trust of millions of customers across multiple large-scale platforms," said researchers, who noted that Companjon only secured the misconfigured instance in late November.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds