Conrad Electronic SE reported a data breach in a press release: Unknown individuals gained access to 14 million customer records belonging to the Conrad Group by exploiting a security vulnerability. The group also includes Re-In Retail International GmbH, which operates under the “voelkner” brand.
The data records include mailing addresses, in some cases email addresses, fax numbers, and phone numbers, and—in just under 20% of the affected records—IBANs as well. Credit card information and customer passwords were not compromised. According to the company, it immediately filed a criminal complaint with the Bavarian State Criminal Police Office and promptly notified the Bavarian State Office for Data Protection Supervision (BayLDA). Conrad’s security experts have already identified and patched the security vulnerability in the affected Elasticsearch system.
Elasticsearch is a search engine that stores data in a NoSQL database and easily provides high availability and load balancing across a cluster of computers. Kibana provides a web-based interface for analyzing and visualizing the data. By default, the data in an Elasticsearch instance can be accessed without any authentication measures. Therefore, the most important security recommendations are to restrict network-side access to Elasticsearch and to implement upstream authentication. Network-level protection can be implemented without additional investment using simple configuration measures or firewall systems. The simplest form of authentication is Basic Authentication on the web server, which can be implemented in just a few minutes using built-in tools.
According to the press release, the vulnerability can only be detected using specialized software. This likely refers to vulnerability scanners such as leaklooker, which identify databases on the Internet and check them for insecure configurations and outdated versions. However, specialized search engines such as SHODAN, BinaryEdge, and Censys also perform this search. As of today, SHODAN returns 3,833 hits for Elasticsearch and 25,829 hits for Kibana. SHODAN locates 1,867 of these databases in Germany. Once an Elasticsearch or Kibana instance is found on the Internet, it’s easy to determine not only whether there are configuration flaws but also whether known vulnerabilities affect those instances. Known vulnerabilities that have already been identified by security researchers in other cases include CVE-2015-1427, CVE-2017-5638, and CVE-2019-7609, for which exploits (programs designed to exploit vulnerabilities) are available to anyone.
Conrad states that there is no evidence that the access was used to misuse the data. Those affected are left wondering whether the significant risk of identity theft can be ruled out through appropriate forensic analysis. Furthermore, Conrad does not specify in the press release whether the access and login attempts during the period when the data breach occurred were logged, as would be necessary for a forensic analysis. Since the perpetrators remain unknown, well-intentioned security researchers can be ruled out as the ones who discovered the security vulnerability. Another group of perpetrators consists of cybercriminals driven by financial motives. It would be unusual if cybercriminals had not used their access to extract all data records. Certainty will only emerge once the customer data is offered for sale on the dark web or phishing attacks using the compromised data begin to surface.
In addition to the data breach at Conrad, there have been numerous other high-profile cases of data leaks caused by unprotected Elasticsearch databases: