Get all your news in one place.
100’s of premium titles.
One app.
Start reading
TechRadar
TechRadar
Sead Fadilpašić

Alibaba-owned online marketplace may have breached millions of users

IT.

Chinese company Taobao, one of the world’s largest ecommerce websites, was reportedly leaking sensitive information on its users, a new report from Cybernews has claimed.

The team recently uncovered an unprotected Elasticsearch cluster of data, and say whoever built and maintained this was harvesting Taobao data illegally, “possibly through web crawling or other unauthorized means”.

The cluster, which was shut down in the meantime, held 11.1 million records, each line likely representing one Taobao user. The details found in the database included people’s names, phone numbers, and postal addresses, which is more than enough to mount identity theft and phishing attacks.

No data leak identified

Cybernews was unable to independently verify the authenticity of the information found in the database, but since it was titled “Taobao”, the information is “almost certainly related to Taobao users”. The e-commerce giant said its investigation discovered no data leaks.

“Data privacy and security is of utmost importance to Taobao. Based on our analysis of the sample data provided by Cybernews, there is no data leak identified on our platforms,” the company said.

Unprotected databases are one of the most common causes of data breaches. They are almost always the result of human error and sloppiness, when employees forget to set up a password, or other ways of locking down access to the files.

Launched in 2003, Taobao is owned by the Alibaba Group, and with almost 900 million monthly active users for September 2023, it is considered one of the largest e-commerce platforms, not just in China, but globally, as well. However, with the platform being built on Chinese, it is fairly inaccessible to the rest of the world. 

Businesses handling large data volumes should implement authentication and authorization mechanisms, and configure firewall rules to only allow traffic from trusted sources, the Cybernews team advised.

More from TechRadar Pro

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.