Unprotected Database Exposes Millions of Business SMS Text Messages

Security researchers discover a massive, unsecured database belonging to TrueDialog that exposes tens of millions of two-way text messages. The leaked data contains sensitive information, including two-factor codes, password reset links, and customer login credentials.

A massive database containing tens of millions of SMS text messages sits exposed on the internet without a password. The unencrypted data belongs to TrueDialog, a business SMS provider that facilitates two-way text conversations between companies, universities, and their customers. Security researchers Noam Rotem and Ran Locar discover this security lapse during their routine internet scanning efforts.

The exposed records contain highly sensitive information, including phone numbers, message contents, and even TrueDialog customer usernames and passwords. Many of the text messages include two-factor authentication codes and password reset links for major online services like Facebook and Google, which potentially allows anyone who views the data to hijack user accounts. The database also reveals full conversation chains through unique tracking codes, showing everything from university finance details to opt-out requests from frustrated recipients.

TechCrunch contacts TrueDialog about the exposed database, prompting the company to quickly pull the data offline. Despite taking action to secure the server, TrueDialog chief executive John Wright refuses to acknowledge the breach, answer questions, or confirm if the company plans to notify affected customers or regulators about the significant security lapse.

Read More at the original source →