• Full names
  • Addresses
  • Post codes
  • Dates of birth
  • National IDs
  • Phone numbers *Genders
  • Email addresses
  • Telco metadata
  • Breach status and social profile annotations

Good luck everyone.

  • fizzle ( fizzle@quokk.au ) 
    link
    fedilink
    English
    arrow-up
    3
    ·
    7 months ago

    Sadly I see a lot of victims of scams / identity fraud in my work.

    My advice to people generally is:

    Be vigilant, don’t click links in emails, don’t talk to people who call you, have conversations with the people you care about reminding them to also be vigilant.

    For access to government services, set up the myId app for 2fa, don’t use SMS.

    For other services, use a 2fa code generator, or SMS if that’s all thats available.

    Use a password manager, but be wary that non-technical people might find this out of reach. Their browser’s built in password management is better than nothing.

    Your State’s department of transport probably lets you lock your profile so your drivers license number can’t be used to verify your identity. Be aware that you’ll need to unlock this when you want to allow someone to confirm your id.

    Similarly you can lock your credit rating at experian or equifax:

    • sys110x ( sys110x@aussie.zone ) 
      link
      fedilink
      English
      arrow-up
      7
      ·
      7 months ago

      It’s not misleading. A database of personally identifiable information being exposed on the internet is a data leak. Personally identifiable information is legally required to be protected, while an exposed database on the internet is about as far from ‘protected’ as you can get.

      The article and title make no claim to active selling or known exploitation of the data, but to write this off as nothing would be a mistake. Are you sure that only the Cybernews team found it?

      The Cybernews team discovered the exposed MongoDB instance on November 11th, 2025 and immediately notified IDMerit. The company secured the database by November 12th.

      We don’t know how long it was exposed for prior to it being discovered on the 11th - it might’ve been that day, it might’ve been a few months.

      • It is misleading to say it was leaked because there’s no evidence that anyone saw it.

        If no ones data was stolen, was there a leak?

        It was unsecured, but it was not leaked unless someone accessed it. To try and pretend that there’s no difference is pure idiocy.

        • sys110x ( sys110x@aussie.zone ) 
          link
          fedilink
          English
          arrow-up
          1
          ·
          7 months ago

          If your house plumbing is leaking, its not a leak to you unless you see it? How do you know it hasn’t been accessed?

          Thankfully we don’t need to rely on your definition of a data leak: https://www.fortinet.com/resources/cyberglossary/data-leak

          A data leak happens when an internal party or source exposes sensitive data, usually unintentionally or by accident.

          This is sensitive data that’s accidentally been exposed on the internet. That is a leak. You are misinformed on what a data leak is.

          • FreedomAdvocate ( FreedomAdvocate@lemmy.net.au ) 
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            7 months ago

            Great analogy, but not for the point you’re trying to make.

            If your house plumbing is leaking there is water going out where it shouldn’t be. You’re saying it’s a leak just because there’s a tap out near the footpath that could be turned on by someone to use your water, even if not a single drop of water has ever come out of it.

            With an unsecured server the data isn’t going where it shouldn’t be unless someone takes it. Without evidence of someone taking it, nothing was leaked.