Youth Non-Profit AIESEC Exposes Millions of Intern Applications in Unprotected Database
AIESEC accidentally leaves over four million internship applications unprotected on a passwordless server. The organization claims only 40 users are affected despite the massive data exposure.
AIESEC, a massive youth-run non-profit organization, exposes more than four million internship applications on an unsecured Elasticsearch database. Independent security researcher Bob Diachenko discovers this exposed server on January 11, revealing that it contains highly sensitive applicant information without any password protection.
The leaked database contains a wealth of personal details, including names, genders, dates of birth, and the applicants' reasons for applying. AIESEC global vice president Laurin Stahl admits the database is inadvertently exposed during an infrastructure improvement project around Christmas, but he claims that no more than 40 users are actually affected by this breach.
Despite AIESEC's downplaying of the incident, the organization faces potential scrutiny under GDPR rules since it hosts EU citizen data. Security researchers note that this is just the latest in a long string of similar incidents involving unprotected Elasticsearch instances left open to the public internet.