Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Unsecured Internet-facing database attracts hackers in a matter of hours

Comparitech honeypot research finds unsecured database attacked in under 9 hours of being exposed

by Beth Smith
June 10, 2020
in Editor's News, Featured, Guru's Picks, News, Research, Threat Detection
Unsecured Internet-facing database attracts hackers in a matter of hours
Share on FacebookShare on Twitter

You only have to read the news on this very website to find countless stories of instances where companies have inadvertently left a database exposed on the web – it’s every security professional’s worst nightmare.

 

Researchers at Comparitech, who will often be the source of finding these misconfigured databases to alert the unsuspecting company, decided to set up a honeypot experiment to see just how little time it would take before such a database could be found.

 

Head cybersecurity researcher, Bob Diachenko created a simulation of a database on an Elasticsearch instance complete with fake user data and left it publicly exposed to record the results over 11 days.

 

In just over 8 hours after exposure, the database had attempted unauthorised access (which Diachenko refers to as an “attack). And over the days where it was left exposed, it was attacked on average 18 times a day, 175 times in total.

 

The research should serve as a stark reminder to companies of the importance of securing databases like Elasticsearch and shows just how opportunistic hackers are. Commenting, Warren Poschman, senior solutions architect at comforte AG, said:

 

“IT departments leaving unprotected databases on the internet, data in misconfigured S3 buckets, or not patching critical systems that are internet facing is an unfortunate and increasing regular occurrence as more organisations cloudify their legacy operations or move toward new cloud-native infrastructures.

 

“With hundreds of controls and a multitude of regulations emerging to protect privacy proper and robust implementation can be a daunting task – let alone the basic security requirements that are required for basic survival,” he continued.

 

David Kennefick, product architect at Edgescan said that his team finds these instances a lot more than people might think as Edgescan monitors for exposed databases as part of its continuous profiling service; however, the cloud has improved matters. He said: “There has been a substantial improvement during the great cloud migration. Using a service such as AWS or Azure, which automatically locks down your machines and services, is a great way to reduce the likelihood of leaving something exposed. These providers, in fact, have this control enabled by default, meaning that users have to go out of their way to leave anything exposed on the internet.

 

“The issues with exposed databases are introduced when teams are managing technologies that don’t have this control enabled by default – there is an assumption of security, and this leads organisations down the path of accidental exposure,” Kennefick explained.

 

Of course, if the good guys are searching, so are the bad guys. Boris Cipot, senior security engineer at Synopsys, explained that hackers have created their own search engines to hunt out exposed databases or devices.

 

“Finding exposed databases or devices on the internet today quite easy, as further proven by Comparitech’s honeypot research. There are specially designed search engines that look for exposed devices on the internet, and even malware like Kaiji (as one example) automatically looks for exposed operating systems with root access,” Cipot said.

 

“For this reason, a timestamp of less than 9 hours before the first “attack” started is nothing surprising. It however shows that there is not much time for companies to find a mistake and repair it before there is potential for a bad actor to identify and manipulate it. Every mistake in provisioning your resources can lead to big problems. We see often that insecure steps are made when deploying instances in the cloud environment. Insecure security settings lead to exploitable systems and devices.”

 

Comforte’s Poschman noted that the findings are key indicators that going beyond the perimeter, access controls, and other traditional controls are absolutely necessary.

 

“Data security is that one catch-all that must not be left out.  By implementing a data-centric security, organisations can eliminate risk by ensuring that data is protected regardless of where it resides or who is using it – not a nice to have but a necessity given today’s attack vectors and expanding cloud usage,” he said.

 

Synopsys’ Cipot recommended that companies think about provisioning resources much like a pilot’s checklist before take-off, which will to lead to two important things, “first, the creation of security policies and procedures and secondly, a checklist that does not allow room for mistakes.”

 

The full details, including what attack methods were used and what attackers attempted to do with the data, can be found in this blog:

https://www.comparitech.com/blog/information-security/unsecured-database-honeypot/

Tags: database securityhoneypotResearch
Share4Tweet
Previous Post

One Identity Safeguard now offers free Personal Password Vault

Next Post

Trickbot Malware Spreads Through Fake Black Lives Matter Campaign

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol