← JustDial

2019 Justdial — 100M records via unprotected API

2019 100.0M records affected Share on X

Data compromised

Names, phone numbers, emails, addresses

Technical writeup

Justdial, India's local search service, exposed 100 million user records through an unprotected API. The API allowed anyone to retrieve user names, phone numbers, emails, and other personal data without authentication.

Root cause

Unprotected API; misconfiguration

References