Data breach at KukuFM exposes 38 mn user personal information

KukuFM, a Mumbai-based podcast and audiobook platform, experienced a significant data breach when a Kibana instance was left publicly accessible. The breach, which exposed personal data of over 38 million users, was discovered by Cybernews researchers. The leaked information included email addresses, phone numbers, and profile pictures, posing serious privacy risks. Kibana, an open-source data visualization and exploration tool, is often used in combination with Elasticsearch, a search and analytics engine, as part of the Elastic Stack. This stack enables organizations to search, analyze, and visualize large sets of data in real time. However, in the KukuFM case, the Kibana instance was misconfigured, allowing unauthorized users to access sensitive information stored in the associated Elasticsearch database. The breach has raised concerns about KukuFM s data protection practices, especially given the platform s popularity with over 50 million app downloads. The exposed data increases the risk of phishing attacks, identity theft, and other malicious activities. Cybernews urged KukuFM to immediately secure the Kibana instance and conduct a thorough security audit to prevent future incidents. Despite these warnings, KukuFM has yet to make a public statement or demonstrate that the issue has been fully addressed. The incident highlights the broader challenges of securing sensitive information in the rapidly growing digital content industry. Baburajan Kizhakedath, the founder of KukuFM, must take immediate action to address this data breach and ensure the platform s users privacy and security.

Source: infotechlead.com
Published on 2024-09-24