2026 Infutor — 676.8M records (misconfigured Elasticsearch)
Data compromised
Full names, Social Security numbers, dates of birth, complete address histories, phone numbers
Technical writeup
Infutor data platform suffered a massive exposure in March 2026 when a misconfigured Elasticsearch database was discovered publicly accessible with no authentication. SOCRadar researchers found 91.72 GB of data across nearly 677 million indexed records on port 9200. Records exceeded US population, suggesting aggregation and historical retention. Approximately 250 million entries had already circulated on hacker forums before disclosure. Infutor serves insurance, consumer finance, higher education, real estate, and other industries.
Root cause
Misconfigured Elasticsearch database; no authentication