Cloud Security, Patch/Configuration Management, Privacy
Google Firebase may have exposed 125M records from misconfigurations

Misconfigured Google Firebase websites could have leaked nearly 125 million user records. (Adobe Stock)
More than 900 misconfigured Google Firebase websites could have leaked nearly 125 million user records, according to a recent post by a trio of security researchers who go by the online handles "mrbuh," "xyzeva" and "logykk."Security researcher mrbruh first reported Jan. 10 that in hacking into Chattr.ai, the AI-based hiring system, they had successfully accessed popular retail food websites such as Applebee’s, Chick-fil-A, KFC, Subway and Taco Bell.The Retail and Hospitality ISAC reported on the incident Jan. 11, the day after the first post by mrbruh, saying that attackers can use Chattr.ai’s registration feature to create new user profiles with full read/write privileges by abusing a vulnerability or a misconfiguration in their Google Firebase backend database. Companies in the retail and hospitality industry were then advised to contact Chattr.ai.After the initial press around the of pwning Chattr.ai, the trio of researchers set to work on scanning the internet for exposed PII via misconfigured Firebase instances — and that’s when they found the leaked records, including important bank details, billing information and invoices. The leaked data also included names, phone numbers, email addresses and passwords. Efforts to reach Chattr.ai and Google for comment were unsuccessful as of publication.
An In-Depth Guide to Cloud Security
Get essential knowledge and practical strategies to fortify your cloud security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds