Alibaba Group

May 11, 2023 1 min read
Alibaba Group

An Alibaba-owned project called City Brain has advanced video and processing ability for facial detection, real-time information statistics and feeds, crime and traffic offenders, and much more.

City Brain exposed its own data via elastic search engine instances that were left open without any authentication

It left all the data from its processing open for anybody to view.

It involved 56GB of data across 22 indices that appeared to be a mix of test and production naming.

Within the indices were links to a cloud system for City Brain vendors.

Links and indices revealed that the data belongs to which city.

Luzhou and Hangzhou are both well-known cities involved with the City Brain program.

Source: https://www.databreaches.net/smart-cities-with-not-so-smart-security-again/

"id": "ALI150121222",
"linkid": "alibaba-group",
"type": "Data Leak",
"date": "01/2020",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"

Join the conversation

Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.