Breach, Data Security

Kanopy.com ElasticSearch database left unsecured

The movie streaming service Kanopy has been leaking access and API logs through an unsecured ElasticSearch database, according to a cybersecurity researcher.

Justin Paine, director of trust and safety at Cloudflare according to LinkedIn, and blogging under the name xxdesmus noted that since March 7 the site has been leaking up to 40 million log lines per day containing a laundry list of personal information including the customer names, geolocation by latitude and longtitude and the names of movies watched.

“Based on the client IP a bad actor (via the API logs or the web server logs) could have identified all videos searched for and/or watched by their client IP. In combination with the geo information, timestamp, and device type it likely would have been possible to identify the identity of a person behind that client IP (in the case of a static IP from their ISP). Depending on the videos being watched -- that potentially could be embarassing (sic) information,” he wrote.

Paine said he has attempted to contact Kanopy through messages and social media starting on March 17, but did not receive a reply. At this point he contacted the hosting provider and the database was taken offline on March 18.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds