Experts Discover Open Server Containing SMS Messages from Banks and Online Services
According to the Telegram channel “Information Leaks,” an Elasticsearch server containing SMS messages from various online services and even banks has been publicly accessible for several days. The channel reports that the total size of the indexes is about 4.5 TB.
The server is hosted on Amazon in the United States, but experts have not been able to determine its owner. Most likely, it belongs to a service that provides SMS distribution services to different companies.
Among the senders (the “sender” field), experts found companies such as Google, Tinkoff, Aeroflot, Yula, Microsoft, and others. The server is active, and one of the indexes (send_record_202204
) is being updated with new SMS messages.
The recipients’ phone numbers are masked with asterisks, but the content of the messages—including one-time codes for two-factor authentication and password recovery—is stored in its original form.