Original post at https://cybernews.com/privacy/russian-e-commerce-giant-data-leak/
Founded in 1991, Elevel (previously Eleko) positions itself as the leading Russian electrical engineering company that runs both an e-commerce business and wholesale stores.
On January 24, the Cybernews research team discovered an open dataset with 1.1TB of data and attributed it to e.way – an Elevel-owned online shop with 25,000 monthly visitors.
The dataset with seven million data entries leaked two years’ worth of sensitive data, including names, surnames, phone numbers, email addresses, and delivery addresses of customers.
“If left exposed, threat actors could download and clone the cluster’s data and use it for nefarious purposes, including phishing attacks, as they possess sufficient PII and to make their scam seem legitimate,” Cybernews researchers said.
Moreover, it contained login data and passwords in URL encoding, which is considered a relatively weak protection mechanism since it can be decoded easily.
“As a number of usernames and passwords are exposed, it could enable threat actors with valid credentials to gain further sensitive data and to impersonate users to make fraudulent purchases,” Cybernews researchers noted.
The dataset is now closed. We are still waiting to receive the company’s official response.
If you want to have more info about leaky databases discovered by the Cybernews Team give a look at the original post at https://cybernews.com/privacy/russian-e-commerce-giant-data-leak/
About the author: Jurgita Lapienytė Chief Editor
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Elevel)
A new Linux botnet, SSHStalker, has infected about 7,000 systems using old 2009-era exploits, IRC…
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Office and Microsoft Windows flaws to…
Microsoft Patch Tuesday security updates for February 2026 fix six actively exploited zero-day vulnerabilities. Microsoft…
ZeroDayRAT is a commercial mobile spyware that grants full remote access to Android and iOS…
Senegal closed its national ID card office after a ransomware cyberattack disrupted ID, passport, and…
Dutch agencies confirmed attacks exploiting Ivanti EPMM flaws that exposed employee contact data at the…
This website uses cookies.