Top Android real estate app leaks half a million user passwords online
MyEstatePoint app leaks sensitive data on half a million users
 
A mobile real estate app with roughly half a million users was apparently holding sensitive user data in an unprotected database, freely available for all who knew where to look.
The data held there contained enough information for hackers to mount identity theft attacks, phishing, and other social engineering fraud.
Researchers at Cybernews, who discovered the database in early November 2023, uncovering that the MyEstatePoint Property Search had a publicly accessible MongoDB app, containing users’ names and passwords in plain text. Furthermore, the database contained people’s email addresses, mobile phones, cities, business descriptors, and signup methods.
Recycling passwords
“This comprehensive dataset poses severe risks as threat actors could exploit the exposed information for unauthorized access, identity theft, fraudulent activities, and potentially compromise the privacy and security of the affected individuals,” the team said.
The app was developed by an Indian-based software developer called NJ Technologies. Upon discovery, the researchers reached out to the team, but got no feedback - although the database was subsequently locked down.
Most of the users are Indian, the researchers further added. While locking the database is a welcome step, there are still risks involved. First, we don’t know if any threat actors accessed the database beforehand, and if they did - what did they do with the information found there? It is common knowledge that many people often use the same username/password combination on multiple services, for convenience. In that case, threat actors could use the information obtained via MyEstatePoint Property Search to compromise other services, too.
By automating the process in a brute-force attack, the threat actors could test the usernames and passwords across a myriad of services quickly and efficiently. Users are generally advised not to use the same passwords for multiple services, and to make sure their login credentials are impossible to guess.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
TechRadar Pro has contacted MyEstatePoint for comment.
More from TechRadar Pro
- Major data breach exposes database of 200 million users
- Here's a list of the best firewalls today
- These are the best endpoint protection services right now
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.