Insecure Database Exposes Millions of Private SMS Messages

Stu Sjouwerman | Dec 3, 2019

iStock-1041694856Researchers discovered an unprotected TrueDialog database hosted by Microsoft Azure with diverse and business-related data from tens of millions of users.

Tens of millions of SMS messages have been found on an unprotected database, putting the private data of hundreds of millions of people in the United States at risk for theft or exposure and leaving a communications company open for potential intrusion, security researchers discovered.

Types of data found unprotected included: full names of message recipients, TrueDialog account holders and TrueDialog users; message content; email addresses; phone numbers of both recipients and account users; dates and times that messages were sent; and message status indicators. The account details of TrueDialog account holders also were exposed in the messages, researchers said.

The scope of the leaky data has broad implications for TrueDialog, their users and the recipients of the messages, researchers said. For users and message-recipients whose data was exposed, their personal details could be sold to marketers and spammers and used for social engineering purposes that range from annoying to criminal. Employees need to be stepped through new-school security awareness training that sends them simulated TXT (SMS) messages to their smartphone. More at the Threatpost blog:

Stop Being a Target for Social Media Exploits

Social media is the new frontier for targeted spear phishing and credential theft. Use our Free Social Media Phishing Test to identify which users are likely to click malicious links or leak data on platforms like LinkedIn and X, and get your results in just 24 hours.

Get Your Free Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.