Data Security

Misconfiguration leaks Boryung Corporation data

concept of leaky software, data with a tap sticking out.3d illustration

Cybernews reports that major South Korean healthcare and pharmaceutical company Boryung Corporation had more than eight million internal corporate chat messages on GW Messenger exposed by an unprotected MongoDB database.

Aside from the internal chats that potentially contained business and financial communications, HR topics, internal links and documents, project management exchanges, and private employee correspondences, Boryung's misconfigured database also included almost 3,500 employee user records, which included full names, corporate email accounts, usernames, and hashed passwords, as well as device metadata, according to Cybernews researchers.

Further analysis showed the exposure of system metadata, which included message channels, timestamps, user-channel mapping, and internal routing identifiers. While the MongoDB instance has since been secured, Boryung has been urged to promptly rotate employee passwords, nullify authentication tokens, and implement forced logouts on mobile messengers.

"The company should also conduct a digital forensics investigation to determine if the exposed instance was accessed by unauthorized parties," researchers added.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds