Another data breach... All data of 160 thousand people stolen
Digital data breaches continue. Our stolen data returns to us in the form of messages and calls from foreign countries.
12punto
Our digital data continues to be stolen. According to the notification published by KVKK, the data of the company named Mongo DB was breached. The data of 160 thousand people was stolen in the leak.
The Personal Data Protection Board (KVKK) publishes data breaches experienced on its website. According to the notification dated December 28 published by the Board, the data of the company named Mongo DB Limited was breached. Between 130 thousand and 160 thousand people were affected by the breach. In the breach noticed on December 13, it was determined that an unknown third party gained unauthorized access to the user accounts of a limited number of data controller employees, and findings indicated that they accessed and downloaded personal data relating to the users of some services.
The following was written in the notification regarding which data was stolen:
It was noticed on December 13, 2023, that a user account was making unusual and suspicious queries, and the investigation was deepened upon this,
Findings indicated that an unknown third party gained unauthorized access to the user accounts of a limited number of data controller employees, and accessed and downloaded personal data relating to the users of some services,
While investigations continue, it was determined on December 20, 2023, that customer contact information and metadata belonging to the relevant accounts were leaked from the CRM application and the customer support application,
The affected personal data included name, surname, address, and e-mail addresses (usually work address); however, in addition to these, other data fields were also present in the CRM application and customer support application; these data being;
The data fields in the CRM application: salutation, name, surname, title, account number, company name, address, phone number (main, mobile, fax), e-mail, sales representative (MongoDB) name, surname,
The data fields in the Customer Support application: username (e-mail address), last successful authentication time, last authentication method used, identifier for the user's preferred time zone, alphabetic code for the user's preferred time zone, user's registration date, user's name, surname, unique user ID, information that the user was invited but has not yet accepted the invitation, that the user has limited permissions, the time the page was last viewed by the user, a user's login count, information on whether the user was blocked automatically or manually and whether the user was deleted, deletion time, e-mail verification date, information that it requires e-mail verification, alternative e-mail, information that they enabled multi-factor authentication,
The data fields for users of the deprecated multi-factor authentication (MFA) system: phone number used for the deprecated MFA, phone number extension used for the deprecated MFA, alternative phone number used for the deprecated MFA, alternative phone number extension used for the deprecated MFA, whether an authenticator device was used for the deprecated MFA, information on whether the deprecated MFA user wanted to receive voice calls,
Between 130,000 and 160,000 users from Turkey may have been affected by the breach,
A public announcement regarding the breach was published on December 16, 2023, at https://www.mongodb.com/alerts#general-alert,
Relevant persons can obtain information about the breach from the e-mail address privacy@mongodb.com
information was included.