Following Orders: A Day in the Life of an Iranian Telegram Bot Farm | UpGuard
Inside 24 hours of an Iranian Telegram bot farm: how a misconfigured server exposed the operation selling fake followers to financial scammers.
Inside 24 hours of an Iranian Telegram bot farm: how a misconfigured server exposed the operation selling fake followers to financial scammers.
Adult-content creators filing DMCA takedowns are inadvertently exposing thousands of compromised .gov and .edu sites used for parasite SEO scams.
An exposed DBHub instance leaked millions of records from India's largest real estate platform—the biggest MCP server breach to date.
Free World Cup streams and black-market betting sites are leaking fan data. UpGuard research reveals the hidden cyber risks of the 2026 tournament.
An exposed Azure storage bucket contained millions of documents sent through a jail messaging app, including driver's licenses used for identity verification.
A misconfigured MCP server provided complete access to a private equity firm's data lake, illustrating the unique risks of AI adoption for specialized knowledge workers.
A publicly accessible server with email logs reveals how much information such infrastructure holds–including evidence of attackers looking for it.
An exposed database of dark web threat intel reveals how China responds to the common threat of the cyber-criminal underground.
UpGuard research found a trove of sensitive information in an exposed Elastic database. Getting to the bottom of what it meant led us down an interesting path.
Tens of thousands of AI-enabled web applications using the Streamlit framework are publicly available, exposing PII and other confidential data.
Using Github event archives, UpGuard Research identifies companies with indicators of compromise of the Shai-Hulud attacks, even after the repos have been deleted.
UpGuard discovered a rapidly growing data leak of bank accounts in India– and no one to take responsibility for it.
UpGuard analyzes the universities, governments, and private companies mentioned in the access logs of hacker forum Leakzone.
UpGuard can now report that we have secured a Langflow instance leaking data for around 97,000 insurance customers in Pakistan.
Learn more about how a data exposure from within Cambridge Analytica-linked firm AggregateIQ reveals web assets built for Canadian politicians and parties.
UpGuard discovered an unauthenticated Elasticsearch database containing 22 million records of user traffic for hacking forum leakzone.net.
A sensitive S3 bucket left wide open, containing highly classified 'NOFORN' data, was discovered by the UpGuard team.
A collection of data sets detailing the purchasing habits and consumer behavior profiles of 120 million American households was exposed by Tetrad.
A company that matches individuals with clinical trials in Australia and New Zealand exposed personal information on over 37,000 people via a misconfigured MongoDB.
An AWS S3 bucket configured for public access contained a file from 2010 with six million email addresses, apparently from the Democratic Senatorial Campaign Committee.
Political data firm AggregateIQ exposed IT assets that raise questions for society about how technology is being used in recent US political history.
An internet-exposed Puppet master and secret keys left the media empire's cloud assets vulnerable to exploitation.
Thousands of files including medical, business, and legal data were exposed via a misconfigured AWS S3 storage bucket.
An AWS engineer uploaded personal information and system credentials to GitHub. UpGuard notified AWS Security to secure the data.
Learn more about how the exposed files of data firm AggregateIQ cast light on the world of British politics.
The UpGuard data breach research team discovered and secured leaks from IT services provider HCL, including new employee passwords.
Learn how 3.5 million records were exposed by Los Angeles County 211, including names, addresses, and call notes detailing reports of abuse and crisis.
Manufacturing companies rely on robotics automation to power their factories and ultimately, their businesses. See how one robotics vendor exposed confidential information for over 100 clients, including divisions of Toyota, Ford, GM, and Tesla.
111 GB of internal customer information from National Credit Federation was left exposed in a publicly downloadable data repository. This is its story.
UpGuard has identified an exposure of Chicago voters' personal information by an electronic voting machine firm.
The intersection of information technology and healthcare creates new and improved functionality for managing and delivering healthcare services, but it also entails new risks. See how one telemedicine company exposed thousands of medical records and hundreds of patient-doctor recordings online.
Learn for the first time about the secret tools developed by AggregateIQ for purposes of tracking and influencing internet users, including on Facebook.
Read how a misconfigured Amazon S3 bucket exposed strategy documents and voter call lists for the Tea Party Citizen's Fund.
Learn how over 48 million records containing personal data leaked from within the systems of a private intelligence search service.
A misconfigured Amazon S3 storage bucket leaked data from iPR Software, exposing tens of thousands of user accounts and client documents.
Data from a Huntingon, NY medical practice was left publicly exposed via a misconfigured rsync server, exposing information about staff and forty thousand patients.
UpGuard discovered and helped secure an Australian company's code repository containing SQL backups of employee information, banking data, and more.
Everyone who depends on tech assumes its risks. The justice system is no exception. See how detailed arrest records for South Carolina were exposed online.
ISPs do more than provide internet service for individual customers-- they can also act as part of US critical infrastructure. See how one ISP exposed their administrative and root passwords to the public.
While this blog post provides a description of a data exposure discovery involving Booz Allen Hamilton and the US National Geospatial-Intelligence Agency (NGA), this is no longer an active data breach.
The UpGuard Cyber Risk Team has discovered and secured a data exposure of documents appearing to describe GoDaddy infrastructure running in the Amazon AWS cloud, preventing any future exploitation of this information.
Account details for up to 14 million Verizon customers have been left totally exposed by a third-party vendor.
Thousands of resumes belonging to individuals applying to security firm TigerSwan were found publicly exposed in an AWS S3 bucket.
A shared-risk property insurance provider in Maryland left exposed data revealing the personal details of thousands of customers.
A storage server configured for public access exposed millions of files belonging to the Oklahoma Securities Commission.
Learn how the personal information of over one million individuals was exposed online, through a marketing network geared towards internet users interested in higher education.
A storage device containing 1.7 terabytes of information detailing telecommunications installations throughout the Russian Federation was exposed to the public internet.
Third-party Facebook apps gather Facebook data about the people who use them. While Facebook struggles to contain these exposures, insecure third-party data practices & misconfigured cloud systems continue to leak Facebook data to the internet. See how UpGuard discovered and secured two such cases.
UpGuard has discovered an open database containing information on what appear to be approximately 198 million American voters left misconfigured by a GOP analytics firm.
This cloud leak reveals the personal details of 123 million US households, revealing in-depth analysis of their finances sold by credit reporting agency Experian.
Sensitive data points on millions of Dow Jones publication customers were exposed in a massive cloud leak.
Multiple sensitive buckets belonging to the corporation were found publicly exposed, revealing credentials, keys, and customer information.
Backups ensure data continuity, but they're also a surface of risk. See how Fortune 100 vendor Attunity exposed nearly a terabyte of internal backups.
An unprotected backup at a Texas engineering firm exposes critical infrastructure data and information on sensitive clients serving the state.
As soon as the UpGuard Cyber Risk Team notified the Defense Department of this publicly exposed information, immediate action was taken, securing the open buckets and preventing further access.
UpGuard can now report that it has secured a Chroma database containing 341 collections of data for AI applications, including a survey of Canva Creators.
UpGuard can now report that it has secured an Elasticsearch database containing data from APIsec.ai, a security company that claims to be used by 80% of the Fortune 100.
UpGuard can now report that it has secured an Elasticsearch database for AngelSense, a GPS tracker for children and adults with special needs.
The source code for a voter contact app was left publicly accessible, exposing credentials, code, and the app's development history.
Data from TVSmiles, a German mobile application for delivering gamified advertisements, exposed a database including personally identifiable information.
On May 13th, UpGuard discovered a new set of data recently posted on a prominent dark web forum, this time allegedly belonging to the National Parent Teacher Association.
UpGuard can now report an ElasticSearch instance used as data storage for the debt collection system ENCollect has been secured. The server contained data about loans from multiple Indian and African financial services companies that had apparently been sent to ENCollect for collection. The data totalled 5.8GB in storage size and contained a total of 1,686,363 records. Those records included personal information like name, loan amount, date of birth, account number, and more.
UpGuard can now report that a public Google Cloud Storage bucket containing approximately 1.5 terabytes of data used to administer funding programs for college students has been secured. The bucket belonged to SmarterSelect, a company that provides software for managing the application process for scholarships, grants, and awards. The more than 2.8 million files included documents like transcripts, resumes, personal essays, tax returns, and invoices for approximately 1.2 million applications to funding programs.
38 million records were exposed in multiple data leaks resulting from misconfigured Microsoft Power Apps portals. Data included sensitive information such as COVID-19 contact tracing data, COVID-19 vaccination appointments, social security numbers for job applicants, employee IDs, and millions of names and email addresses.
UpGuard can now disclose that an Amazon S3 storage bucket containing publicly exposed backups of systems representing the intranet and web presence for Martin County, Florida has been secured.
A comprehensive breakdown of all the events unfolding from the Medibank data breach.
Analytical software provider Birst exposed an appliance in an S3 bucket.
UpGuard has discovered a cloud leak from Paris-based digital marketing startup Octoly exposing the personal details of thousands of social media personalities.
Based on UpGuard's data breach research, the UK Parliament’s DCMS Committee prepared and published the final report detailing their 18 month investigation into online disinformation and the privacy practices of platforms such as Facebook. Read about the report, and the AggregateIQ breach discovery.
Several large storage buckets under the control of Hortonworks were configured for public access, exposing credentials and other internal data.