# Around 2 million Edureka users’ records at risk due to database breach

URL: https://technosports.co.in/around-2-million-edureka-users-records-at-risk-due-to-database-breach/  
Published: 2020-10-02  
Updated: 2020-10-04  
Author: Anupam Modak

Edureka is one of the known online education startups based in India, and its server is based in the US. As per the report of [SafetyDetective](https://www.safetydetectives.com/blog/edureka-leak-report/), the largest antivirus review website, its security team has discovered a completely unsecured Elasticsearch server of the e-learning platform. The team, lead by Anurag Sen, found this vulnerability while routing IP-address checks on specific ports and figure out over 25GB of personal data was publicly available. Not sure about the exact number, but there were around 2 million Edureka users’ personal data, including first name, email address, phone number, country of residence, login activity records, and Miscellaneous Auth token information.

- ![Credentials with Auth Values_TechnoSports.co.in](https://technosports.co.in/wp-content/uploads/2020/10/Credentials-with-Auth-Values_TechnoSports.co_.in_-1024x122.jpg) *Credentials with Auth Values*
- ![Server logs showing login activity_TechnoSports.co.in](https://technosports.co.in/wp-content/uploads/2020/10/Server-logs-showing-login-activity_TechnoSports.co_.in_-1024x338.jpg) *Server logs showing login activity*
- ![Server logs showing user email address and user Auth values_TechnoSports.co.in](https://technosports.co.in/wp-content/uploads/2020/10/Server-logs-showing-user-email-address-and-user-Auth-values_TechnoSports.co_.in_-1024x161.jpg) *Server logs showing user email address and user Auth values*

The SafetyDetective team spotted this vulnerability on 1st August and reached the Edureka team on 6th August to notify them. In addition to vulnerability, there were also some significant security flaws. As the platform didn’t respond, SafelyDetetive reached the Indian Computer Emergency Response Team (CERT-In) on 13th August.

The login activity details in the exposed data can be used in scams or even can be handed over to the commercial third parties. 2 million users’ data is not a small amount. Apart from these, the contact details – phone number and email addresses- can also be used in various kinds of fraud.

*Do Check Out* 👇🏼

https://technosports.co.in/2020/10/01/amd-zen-3-based-ryzen-9-5900x-with-12-cores-and-24-threads-spotted/

**[TechnoSports 🔥 Stay Updated](https://technosports.co.in)**
