Unprotected Database From Adult Website CAM4 Exposed Millions Of Users To The Internet

Adult live-streaming website CAM4.com somehow failed to do protect its users, as its database was available unprotected on the internet, exposing millions of its users' personally identifiable records.

The 7TB database was found by a team of researchers from Security Detective, a site focusing on security incidents and tools. The team’s lead researcher, Anurag Sen, said that the database had more than 10.88 billion records and a production log dated back to March 16.

CAM4 belongs to Irish company Granity Entertainment. Security Detective immediately contacted the company to only receive prompt that it also needed to inform another company called Smart-X.net

Upon further investigation, the team found that both CAM4 and Smart-X are owned by a parent company called Surecom Corp.

Soon after contacting the companies, the server was secured afterwards.

But nevertheless, there is no saying who has had access to the database and whether anyone managed to steal anything from it.

CAM4 hacked
Database contained user activity and login dates for public view. (Credit: Security Detective)

The unsecured Elastic Search database included a huge amount of both user and company information with the vast majority of email data records referring to users in the U.S..

  • First and last names.
  • Email addresses.
  • Country of origin.
  • Sign-up dates.
  • Gender preference and sexual orientation.
  • Device information.
  • Miscellaneous user details such as spoken language.
  • Usernames.
  • Payments logs including credit card type, amount paid and applicable currency.
  • User conversations.
  • Transcripts of email correspondence.
  • Inter-user conversations.
  • Chat transcripts between users and CAM4.
  • Token information.
  • Password hashes.
  • IP addresses.
  • Fraud detection logs.
  • Spam detection logs.
[block:block=87]
CAM4 hacked
Purchase details with email. (Credit: Security Detective)

The information the database exposed gave a peek into CAM4's security practices.

For example, the information had some data about its fraud and spam detection methods. The research team noted that the fraud detection logs “enables hackers to better understand how cybersecurity systems have been set up and could be used as an ideal verification tool for malicious hackers, as well as enabling a greater level of server penetration.”

Cybercriminals can use this data to target emails to extort money or for spear-phishing attacks.

CAM4 is an adult website with active members. And for that reason, it has a large number of users who share sensitive data, and paying members who prefer to stay anonymous.

It should be noted that a case like this can result to a wider damage if CAM4 shares the database with others within its company group.

Like the Brazzers hacked case back in 2016, for example, the data leak originated from a separate part of the website's section, but compromised both Brazzers and Brazzersforum.

"This information could then be weaponized to compromise other individuals and groups such as family members, colleagues, employees and clients of other businesses," said Safety Detectives on its report.