/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researcher finds unsecured ElasticSearch server owned by a Chinese public security department that leaked databases with 90M+ records of people and businesses

Sergiu Gatlan / BleepingComputer :

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

This is the third Elasticsearch exposure BleepingComputer has reported in as many months, and the pattern is consistent: a Panama citizen database with ~3.5M records in May, then FMC Consulting's cluster leaking 20M+ resumes in June, now a server owned by a Chinese public security department itself. The difference this time is the owner — the leak comes from inside the state security apparatus, not from HR firms or private companies.

First-order effects

  • The Chinese public security department must secure or take offline the exposed server, and the personal and business records it held are now discoverable by anyone who found the open instance before the researcher's disclosure.

Second-order effects

  • Elastic faces renewed pressure to make its default configuration safe for non-expert operators, since every one of these incidents traces to clusters left public rather than to a product vulnerability; meanwhile Chinese government data holders join private firms like FMC Consulting as repeat examples in researchers' disclosure reports.

Third-order effects

The trend: Unsecured Elasticsearch clusters have become a recurring class of mega-leak spanning private HR firms and Chinese government agencies alike, with each disclosure widening scrutiny of how default configurations expose national-scale citizen databases.