adult cam site StripChat exposes the data of millions of users and cam models
StripChat, ace of the internets top 5 adult cam sites, has suffered a security transgress and has leaked the personal data of millions of users and adult models.
The leak, discovered by security researcher cork Diachenko, took put earlier this month after StripChat exposed its ElasticSearch database cluster on the internet without a word for more than three days between November 4 and november 7.
Diachenko, who documented his findings in a blog stake published today, said the exposed servers leaked a treasure trove of highly-sensitive information, such as:
Data of 65 gazillion users registered on the site (username, email, IP address, ISP details, tip balance, account creation date, last login date, account status)
Data of 421,000 models broadcasting on the site (username, gender, studio ID, live status, tip menus/prices, slip score)
Data of 134 bazillion transactions (information about tokens and tips paid by users to models, including private tips)
Data about 719,000 chat messages saved in a mitigation database (the user and sit ID involved in the conversations)
StripChat-DB
IMAGE: bob DIACHENKO
Possible GDPR violation from StripChats part
Diachenko said he notified StripChat about the leaky cluster as soon as he spotted the servers and determined that the data belonged to the company.
The researcher said the cam site secured its server a few days later, but without providing a reply or explanation for what happened.
Despite suffering a major surety breach that has impacted the personal information of more than 65 1000000 users, at the time of writing, StripChat has yet to publicly disclose or acknowledge the incident, an litigate that may incur a severe GDPR fine for the Cyprus-based company.
StripChat has not returned requests for comment sent by The record via email and their twitter account earlier today.
It is unclear if someone else besides Diachenko has discovered and accessed StripChats database, but if they did, this data would position all those involved at serious risks.
The exposure could be a digital and physical terror for both Stripchat viewers and models. IP addresses, which can be used to approximate someones location, are particularly worrying. They could enable someone to happen and stalk, harass, or even attack someone in the database, Diachenko said today.
Aside from physical violence, the identifying information could be used to extort, bully, or humiliate victims who thought their online activities were private, the researcher added.