cloud

US Military Personnel Data Leaked From Unsecured Elasticsearch Database

US Government, Military, and Department of Homeland Security (DHS) data exposed from the Elasticsearch database that belongs to the reservations management system Autoclerk.

The leak exposed thousands of users and hotel guests data across the globe, the breach also impacted military security agencies.

Autoclerk is the contractor who manages the travel arrangements of the US government and military personnel, as well as independent contractors. The Autoclerk was recently acquired by Best Western Hotel & Resorts Group the biggest hotel chain in the world.

Data Exposed in Leak

Researchers from vpnMentor discovered the unsecured Elasticsearch database hosted by Amazon Web Servers in the USA and it contains over 179GB of data.

The database contains 100,000s of booking reservations for guests and travelers. Following are the personal details of users exposed

  • Full name
  • Date of birth
  • Home address
  • Phone number
  • Dates & costs of travel
  • Masked credit card details

In some hotels, even the check-in time and room number are also visible.

The travel, hospitality, and personal data were exposed, the leak exposed the personally identifying information (PII) of personnel and their travel arrangements. Our team viewed logs for US army generals traveling to Moscow, Tel Aviv, and many more destinations.

“Before adopting software or apps to manage an area of your business, make sure they are following data security best practices. If processing external data, such as a hotel guest or members of the public, you need to ensure this data is protected from hackers.”

By having personal details, attackers can extract more information, such as financial account details or sensitive passwords. Attackers may launch targeted phishing campaigns to trick victims into providing passwords, credit card details, or embed malicious software on a device.

You can follow us on LinkedinTwitterFacebook for daily Cyber Security and hacking news updates.

Also Read

Hospitality Company OYO Exposes Millions of Customer Data

Comodo Forums Data Breach – Approximately 245,000 Users Affected

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago